Untitled Document

DO-278/ED-109 Software Standard for Non-Airborne Systems

 

Overview


Background


The RTCA DO-278 / EUROCAE ED-109 "Guidelines for Communication, Navigation, Surveillance and Air Traffic Management (CNS/ATM) Systems Software Integrity Assurance" is a complementary standard to the airborne DO-178B standard. RTCA DO-278 / EUROCAE ED-109 provides guidelines for the assurance of software contained in non-airborne CNS/ATM systems.


The RTCA DO-278 / EUROCAE ED-109 guidelines are intended as a guide for the application of DO-178B guidance to non-airborne CNS/ATM systems. The two standards are therefore complementary and interrelated.


DO-178B defines the five levels as:


ldraimages/cozumler/do-178b-table-3.jpg


DO-278 provides guidelines for the production of software for ground based avionics systems and equipment that performs its intended function with a level of confidence in safety. The guidelines are in the form of:

 

- Objectives of software lifecycle processes

- Description of activities and design considerations for achieving these objectives

- Description of the evidence that indicate that the objectives have been satisfied

 

The document discusses those aspects of certification that apply to the production of software for ground based avionics systems and are used in CNS or ATM equipment.

 

DO-278 Software Level Definitions are:

 

- (AL1) Assurance Level 1 - Software that could cause or contribute to the failure of the ground-based system resulting in a catastrophic failure condition.

- (AL2) Assurance Level 2 - Software that could cause or contribute to the failure of the ground-based system resulting in a hazardous or severe failure condition.

- (AL3) Assurance Level 3 - Software that could cause or contribute to the failure of the ground-based system resulting in a major failure condition.

- (AL4) Assurance Level 4 - This level accounts for certain CNS/ATM systems where AL3 is too stringent and AL5 is too lenient.

- (AL5) Assurance Level 5 - Software that could cause or contribute to the failure of the ground-based system resulting in a minor failure condition.

- (AL6) Assurance Level 6 - Software that could cause or contribute to the failure of the ground-based system resulting in no effect on the system.

 

DO-278 Software Level Definitions