AC 25.1309-1
AC 25.1309–1 is an FAA Advisory Circular (AC) (Subject: System Design and Analysis) that identifies acceptable means for showing compliance with the airworthiness requirements of § 25.1309 of the Federal Aviation Regulations, which requires that civil aviation equipment, systems, and installations "perform their intended function under foreseeable operating conditions."[1] The present Revision B was released in August 2024. AC 25.1309–1 establishes the principle that the more severe the hazard resulting from a system or equipment failure, the less likely that failure must be. Catastrophic failures must be extremely improbable.[2] Airworthiness standardsThe airworthiness requirements for transport category (large civil aircraft, both airplanes and helicopters) are contained in Title 14, Code of Federal Regulations (14 CFR) part 25 (commonly referred to as part 25 of the Federal Aviation Regulations (FAR)). Manufacturers of transport category airplanes must show that each airplane they produce of a given type design complies with the relevant standards of part 25. The present AC 25.1309–1 describes acceptable means for showing compliance with those airworthiness requirements. It recognizes Aerospace Recommended Practices ARP4754 and ARP4761 (or their successors) as such means:[3]
BackgroundAC 25.1309–1 provides background for important concepts and issues within airplane system design and analysis.
The circular provides a rationale for the upper limit for the Average Probability per Flight Hour for Catastrophic Failure Conditions of 1 x 10−9 or "Extremely Improbable".[5] Failure Conditions resulting in relatively more severe effects must be relatively less likely to occur; that is, an inverse relationship between severity and likelihood should be a safety objective of aviation system design.
This AC presents the FAA Fail-Safe Design Concept, which applies basic objectives pertaining to failures:
The AC lists design principles or techniques used to ensure a safe design. Usually, a combination of at least two safe design techniques are needed to provide a fail-safe design; i.e. to ensure that Major Failure Conditions are Remote, Hazardous Failure Conditions are Extremely Remote, and Catastrophic Failure Conditions are Extremely Improbable.
With the emergence of highly integrated systems that perform complex and interrelated functions, particularly through the use of electronic technology and software-based techniques [e.g., Integrated Modular Avionics (IMA) ], concerns arose that traditionally quantitative functional-level design and analysis techniques previously applied to simpler systems were no longer adequate. As such the AC includes expanded, methodical approaches, both qualitative and quantitative, that consider the integration of the "whole airplane and its systems".[6] Definitions and ClassificationsA main task of AC 25.1309–1 is to provide standard definitions of terms (including hazard and probability classifications) for consistent use throughout the framework set up for the accomplishment of functional airplane safety. Where regulations (FAR) and standards (ARP) may use such terms as failure condition, and extremely improbable, AC 25.1309–1 defines their specific meanings, both quantitatively and qualitatively.[7] In this respect, AC 25.1309–1 is comparable to ISO 26262–1 Vocabulary, at least in regard to the relative dependent standards. Key definitions include:
Safety objectivesClassified failure conditions are assigned qualitative and quantitative safety objectives, giving guidance to development and operation.
The AC defines the acceptable safety level for equipment and systems as installed on the airplane and establishes an inverse relationship between Average Probability per Flight Hour and the severity of Failure Condition effects:
The safety objectives associated with Catastrophic Failure Conditions may be satisfied by demonstrating that:
The failure conditions Catastrophic through No Safety Effect are assigned Functional and Item Design Assurance Levels (DAL) A, B, C, D, E, respectively, with the concept that there is less tolerance for undiscovered design error in systems with more severe failure effects.[11] In this manner, development of systems and components contributing to more severe effects are subject to increasingly rigorous assurances of effective prevention, detection, and removal of design error, DAL A representing the most thorough assurance rigor.[12] HistoryFirst released in 1982, AC 25.1309–1 has been revised to embody increasing experience in development of airplanes and to address the increasing integration and computerization of aircraft functions. AC 25.1309–1 (original release)Function criticalityAC 25.1309–1 recommended that top-down analysis should identify each system function and evaluate its criticality, i.e., either non-essential, essential, or critical. The terms Error, Failure, and Failure Condition were defined. Functions were classified Critical, Essential, and Non-Essential according to the severity of the failure conditions they could contribute to; but the conditions were not expressly classified. Failures of Critical, Essential, and Non-Essential functions were expected to be, respectively, Extremely Improbable (10–9 or less), Improbable (10–5 or less), or no worse than Probable (10–5).[13] Qualitative methodsPreviously, system safety analysis was quantitative; that is, it was dependent on evaluating the probability of system failures from physical faults of components. But with the increasing use of digital avionics (i.e., software) it was recognized that development error was a significant contributor to system failure, particularly human errors in any stage of designing, implementing, and testing complex systems. During system certification in the late 1970s, it became clear that the classical statistical methods of safety assessment could not be effective for firmware and software-based systems.[14] Existing quantitative methods could not predict system failure rates resultant from development errors. Qualitative methods were instead recommended for reducing specification, design, and implementation errors in the development of digital avionics. The guidance of DO-178 (initial release) was recommended by AC 25.1309–1 for development of essential and critical functions implemented in software.[15] AC 25.1309–1AAC 25.1309–1A introduced the FAA Fail-Safe Design Concept to this Advisory Circular.[16] This revision also introduced recommended design principles or techniques in order to ensure a safe design.[17] Classification of failure conditions by severityThe concept of function criticality was replaced with classification of failure conditions according to severity of effects (cf., Probabilistic risk assessment). Failure conditions having Catastrophic, Major, or Minor effects were to have restricted likelihoods, respectively, of Extremely Improbable (10–9 or less), Improbable (10–5 or less), or no worse than Probable (10–5).[18] Software was still considered to be assessed and controlled by other means; that is, by RTCA/DO-178A or later revision, via Advisory Circular AC 20-115A.[19] In 2002, work was done on Revision B, but it was not formally released; the result is the Rulemaking Advisory Committee-recommended revision B-Arsenal Draft (2002).
AC 25.1309–1B–Arsenal DraftIn May 1996, the FAA Aviation Rulemaking Advisory Committee (ARAC) was tasked with a review of harmonized FAR/JAR 25.1309, AC 1309-1A, and related documents, and to consider revision to AC 1309-1A incorporating recent practice, increasing complex integration between aircraft functions and the systems that implement them,[20] and the implications of new technology. This task was published in the Federal Register at 61 FR 26246-26247 (1996-05-24). The focus was to be on safety assessment and fault-tolerant critical systems. In 2002, work was done on Revision B, but it was not formally released at that time. That year, the FAA provided a Notice of Proposed Rulemaking (NPRM) relevant to 14 CFR Part 25. Accompanying this notice was the "Draft ARSENAL Revised" of AC 1309–1.[21] Existing definitions and rules in § 25.1309 and related standards had posed certain problems to the certification of transport category airplanes. Said problems are discussed at length within the NPRM. The FAA proposed revisions to several related standards in order to eliminate such problems and to clarify the intent of these standards. In some proposed changes, definitions or conventions developed in previously released lower-level regulations or standards were adopted or revised within the Advisory Circular draft.[22] The Arsenal Draft was "considered to exist as a relatively mature draft".[23] The FAA and EASA subsequently accepted proposals by type certificate applicants to use the Arsenal Draft on development programs.[23][24] Boeing referenced the guidance of the Arsenal Draft in its 2004-2009 type certification program for the 787 Dreamliner.[25] Refinement of failure condition classificationsExperience in application of the prior circulars and ARPs witnessed the division of the Major failure condition into two conditions (for example, Hazardous-severe/Major and Major).[26] Additionally, this experience recognised the existence of failure conditions that have no effect on safety, which could be so classified and thereby assigned no safety objectives. Catastrophic Failure Condition was previously defined as "any failure condition which would prevent continued safe flight and landing"; but is now defined as "Failure conditions which would result in multiple fatalities, usually with the loss of the airplane.[8]" Extension of qualitative controls to aircraft functionsThe FAA Fail-Safe Design Concept and design principles or techniques for safe design are maintained. However, owing to the increasing development of Highly Integrated Systems in aircraft, qualitative controls previously considered necessary for safe software development are extended to the aircraft function level.[6] (Similar guidance (Functional Safety framework) has been provided for highly integrated automotive systems through the 2011, release of ISO 26262.[27]) AC 25.1309–1BRevision B was released in August 2024 in coordination with a number of rules changes addressing aircraft system safety. This release is a significant expansion, elaborating on the FAA's Fail-Safe Design Concept and crystalizing and harmonizing FAA system safety terminology, such as the intent of “Extremely Improbable.” Catastrophic Single Latent Failure Plus OneA particular matter in Revision B, which was the topic of a Notice of Proposed Rulemaking[28] completed in June 2024,[29] is the failure condition designated as Catastrophic Single Latent Failure Plus One (CSL+1). The established safety objective for catastrophic failure conditions, "No single failure will result in a Catastrophic Failure Condition," is now explicitly extended to undetected failures having either hazardous or catastrophic effects, now designated as "significant latent failures" (SLF). Applicants must now demonstrate that latent catastrophic failures are eliminated from their design to all practical extent and the residual risk of remaining latent failure is managed such that the "extremely improbable" requirement is maintained.[30] See also
References
|