Originally Posted by
ST Dog
Hazard criticality is determined first. Then based on that you design at the appropriate assurance level.
But DALs don't have failure rates.
And the criticality probabilities are per flight hour, not per year. And that's per flight hour of the entire fleet/type, not a single aircraft.
How the individual probabilities for parts of a system/subsystem add up depends on the relationships, determined in the FTA (fault tree).
And FWIW, in a FTA software failures have a probability of 1. There's really no way to calculate the probability of a defect in software, just as there is no defect free software (of any reasonable complexity).
Thanks, yes per hour. I was thinking primarily of the vane mechanics. Will have to do a sum to see what that means per year. A 1 in 10 million chance it will go wrong in any given hour still seems a stretch.