Skip to main content

The title is Best Practices for Airborne Software Development Assurance Using EUROCAE ED-12( ) and RTCA DO-178( )

AC 00-69 · FAA

Public domain · FAAAdvisory Circulars

Overview

The The title is Best Practices for Airborne Software Development Assurance Using EUROCAE ED-12( ) and RTCA DO-178( ) (AC 00-69) is a public-domain FAA advisory circular, republished here as a free chaptered HTML edition with a linked table of contents and the official PDF.

Publisher
FAA
Document
AC 00-69
Pages
6
Chapters
5

Key points

  • This advisory circular (AC) provides best practices for airborne software development assurance using EUROCAE ED-12 and RTCA DO-178.
  • The AC is intended to assist applicants, design approval holders, and developers of airborne systems and equipment containing software for type certificated aircraft.
  • Software Change Impact Analyses (CIA) are recommended to identify changes and their impacts on the software baseline.
  • The AC emphasizes the importance of error handling at the design level to mitigate foreseeable software errors.
  • Related publications include various FAA Advisory Circulars and RTCA documents that support the guidance provided in this AC.
Frequently asked questions
What is the purpose of AC 00-69?

The purpose of AC 00-69 is to provide best practices for airborne software development assurance, complementing existing standards ED-12C/DO-178C and AC 20-115D.

Who is the intended audience for this advisory circular?

The intended audience includes applicants, design approval holders, and developers of airborne systems and equipment containing software for type certificated aircraft.

What is a Software Change Impact Analysis (CIA)?

A Software Change Impact Analysis (CIA) identifies the released software baseline for proposed changes, summarizing the changes, impacts, and problem reports to be corrected.

What does the AC say about error handling?

The AC recommends handling foreseeable sources of software errors at the design level to reduce unintended software behavior, including specifying protection mechanisms in software requirements.

Where can I find this advisory circular?

AC 00-69 can be found at the FAA's official website under the advisory circulars section.

1 Purpose.

2 Audience.

3 Best practices.

Advisory

U.S. Department of Transportation Federal Aviation

Circular

Administration Subject : Best Practices for Airborne Date: 0 7/21 / 2017 AC No: 00 - 69 Software Development Assurance Using Initiated by: AIR - 134 Change: EUROCAE ED - 12( ) and RTCA DO - 178( ) 1 PURPOSE . This advisory circular (AC) provides information in the form of “best practices ” and, as such, is not intended as guidance but rather as comple mentary information to ED - 12C/DO - 178C (and related documents) and AC 20 - 115D.

2 AUDIENCE . We wrote this AC as a means of assisting applicants, design approval holders and developers of airborn e systems and equipment containing software intended to be installed on type certificated aircraft, engines, and propellers , or to be used in TSO articles .

3 BEST PRACTICES .

3.1 S oftware Change Impact Analyses (CIA ) .

3.1.1 These practices provide complement ary information to ED - 12C /DO - 178C and ED - 12B /DO - 178B , section 12.1.1, 12.1.2, and 12.1.3 ; and AC 20 - 115D section 9.b.(4) .

You may consider using these best practices when you need to conduct a software CIA .

3.1.2 The CIA identif ies the released software baseline up on which the proposed sof tware is to be built, providing: 3.1.2.1 A summary of the changes and impact of the changes; 3.1.2.2 A listing and descriptions of the problem reports to be corrected as part of the intended change and/or change requests related to those changes; and 3.1.2.3 A listing of new functions to be activated and/or implemented.

3.1.3 The CIA address es changes in the following items , where applicable : 3.1.3.1 S oftware level; 3.1.3.2 D evelopment or verification environment; 3.1.3.3 Software processes ; 7 /21 / 17 AC 00 - 69 3.1.3.4 T ool s (e.g. when a new tool version is introduced or a tool’s use is modified) ; 3.1.3.5 P rocessor or other hardware components and interfaces; 3.1.3.6 C onfiguration data, especially when activating or deactivating functions; 3.1.3.7 S oftware interface characteristics and input/output requirements; and 3.1.3.8 S oftware requirements, design, architecture, and code components , where such changes are not limited to the modified life - cycle data , but should also consider the ones affected by the change.

3.1.4 For each applicable item in subparagraph 3.1.3 ( above ) , the CIA describes the resulting impact and identifies the activities to be performed to satisfy ED - 12C/DO - 178C and ED - 12B/DO - 178B and continue to satisfy requirements for safe operation.

3.2 Clarification on Data Coupling and Control Coupling . Thes e practices provide complementary information to ED - 94C/DO - 248C , FAQ #67 for satisfying objective A - 7 (8) of ED - 12C /DO - 178C and ED - 12B /DO - 178B : 3.2.1 D ata coupling analysis is of different type and purpose than control coupling analys i s .

Both analyses are necessary to satisfy this objective .

3.2.2 Although they support a verification objective, d ata coupling and control coupling analyses rely on good practices in the software design phase ; for example, through the specification of interface s (I/O) and of dependen cies between components .

3.3 Error Handling at Design Level .

3.3.1 Th ese practices provide complement ary information to ED - 12C/DO - 178C and ED - 12B/DO - 178B , sections 6.3.2, 6.3.3, and 6.3.4 . Section 6.3.4.f. identifies potential sources of errors that require specific activity focused at the source code review level .

However , in order to protect against foreseeable unintended software behavior , it is beneficial and recommended to handle these sources of error at the design level .

3.3.2 T o reduce the possibility of unintended software behavior , co nsider the following activities : 3.3.2.1 Identif ication of foreseeable sources of software errors , which include: 3.3.2.1.1 Runtime exceptions or errors like fixed/floating point arithmetic overflow, stack/heap overflow, division by zero, or c ounter an d timer overrun/wrap - around .

3.3.2.1.2 Data/memory corruption or timing issues like those due to lack of partitioning or to improper interrupt management or cache management.

5 Where to Find this AC.

7 /21 / 17 AC 00 - 69  EUROCAE ED - 217, Object - Oriented Technology an d Related Techniques Supplement to ED - 12C and ED - 109A , dated January 2012  EUROCAE ED - 218, Model - Based Development and Verification Supplement to ED - 12C and ED - 109A , dated January 2012 .

5 WHERE TO FIND THIS A C.

5.1 You may find this AC at http://www.faa.gov/regulations_policies/advisory_circulars/ .

5.2 If you have suggestions for improvement or changes, you may use the template in appendix A at the end of this AC.

Sus an J. M. Cabler Manager, Design, Manufacturing, & Airworthiness Division Aircraft Certification Service 7 /21 / 17 AC 00 - 69 Appendix A Appendix A. Advisory Circular Feedback Information If you find an error in this AC, have recommendations for improving it, or have suggestions for new items/subjects to be added, you may let us know by (1) complete the form online at https://ksn2 .faa.gov/avs/dfs/Pages/Home.aspx or (2) emailing this form to 9 - AWA - AVS - AIR - DMO@faa.gov Subject: AC 00 - SW Date: ___________ Please check all appropriate line items: An error (procedural or typographical) has been noted in paragraph _______ on page _______ .

Recommend p aragraph _______ on page _______ be changed as follows: In a future change to this AC, please cover the following subject: (Briefly describe what you want added.)

Other comments: I would like to discuss the above. Please contact me.

Submitted by : _________________________________ Date : __________________ A - 1

Source & rights

Source: faa.gov. Public-domain U.S. Government work (17 USC §105) — freely reproducible.

Permanent URL — we don’t break links.

Report a problem or request removal

Document details

Doc number
AC 00-69
Publisher
FAA
Pages
6
File size
220 KB
Chapters
5