2 research outputs found

    Service Dependability with Continuously Revised Assurance Cases by Multiple Stakeholders: A Case Study

    Full text link
    Recently, assurance cases have received much attentions in the field of software-based computer systems and IT services. However, software very often changes and there are no strong regulations for software. These facts are main two challenges to be addressed in software assurance cases. We propose a development method of assurance cases by means of continuous revision at every stage of the system lifecycle, including in-operation and service recovery in failure cases. The quality of dependability arguments are improved by multiple stakeholders who check with each other. This paper reported our experience of the proposed method in a case of the ASPEN education service. The case study demonstrate that the continuos updates create a significant amount of active risk communications between stakeholders. This gives us a promising perspective for the long-term improvement of service dependability with the lifecycle assurance cases.Comment: Submitted to Journal of Information Processin

    Assurance via workflow+ modelling and conformance

    Full text link
    We propose considering assurance as a model management enterprise: saying that a system is safe amounts to specifying three workflows modelling how the safety engineering process is defined and executed, and checking their conformance. These workflows are based on precise data modelling as in functional block diagrams, but their distinctive feature is the presence of relationships between the output data of a process and its input data; hence, the name ``WorkflowPlus'', WF+ . A typical WP^+ model comprises three layers: (i) process and control flow, (ii) dataflow (with input-output relationships), and (iii) argument flow or constraint derivation. Precise dataflow modelling signifies a crucial distinction of (WP+)-based and GSN-based assurance, in which the data layer is mainly implicit. We provide a detailed comparative analysis of the two formalisms and conclude that GSN does not fulfil its promises
    corecore