Certify66
← Back to Digital Techniques / Electronic Instrument Systems
Section 5.13

Software Management Control

Awareness of the restrictions on changing airborne software, and of the possible catastrophic effects of an unapproved change.

Notes

Software management control, summary notes

Main ideas
  • Airborne software is part of the type design. It carries a part number and issue, is recorded in the aircraft's configuration, and may only be changed by an approved process, an uncontrolled change is an airworthiness issue, not an IT matter.
  • DO-178 (EUROCAE ED-12) sets the design assurance levels by the severity of the failure condition the software could cause: A = catastrophic, B = hazardous/severe-major, C = major, D = minor, E = no safety effect. The lower the letter, the more rigorous the objectives, verification and independence required.
  • Verification asks "was the software built right?" (reviews, analysis and testing against requirements); validation asks "was the right software built?" (the requirements themselves are correct). Requirements traceability links every requirement to design, code and test.
  • Configuration control covers loadable software aircraft parts (LSAP): approved media, controlled data loading, verification of the part number after loading, and an entry in the aircraft technical log and configuration record.
  • After a data load the technician must confirm the loaded part number and issue against the approved configuration and carry out the specified post-load test before release to service.
  • ⚠ Exam trap: level A is the MOST severe (catastrophic) and level E the least, the letters run from worst to harmless, which is the reverse of most grading schemes.
Key formulas
DO-178 levels
A catastrophic · B hazardous · C major · D minor · E no effect
Solved examples
  1. A software load fails part-way through. What must the technician not do, and what must be recorded?

    The LRU must not be released to service in its part-loaded state, the load must be repeated or the unit rejected per the maintenance data. The failed attempt, the resulting configuration and the corrective action are recorded so the aircraft's software configuration remains traceable.

  2. Why does a flight-control computer's software attract more rigorous objectives than a cabin lighting controller's?

    Because the design assurance level follows the worst credible failure condition. Loss or malfunction of flight-control software is potentially catastrophic (level A), whereas cabin lighting has no safety effect (level D or E), so far fewer objectives and less independence are required.

Mind map

Software control concept map

Software Management Control

Quiz

Software management control quiz

Software Management Control, quiz (Level 1)

Ref 5.13Pass 75%
  1. 1. Aircraft software may be changed:

    Only by an approved procedure
    By any licensed engineer
    At the operator's discretion
  2. 2. An unapproved change to aircraft software is:

    An airworthiness issue
    A minor administrative matter
    Acceptable if it works
  3. 3. Aircraft software is identified by:

    A part number and issue
    The date it was written
    The size of the file
  4. 4. After loading software onto an LRU, the technician must:

    Verify the loaded part number and record the change
    Simply switch the system off and on
    Take no further action
  5. 5. The possible effect of a fault in critical aircraft software is:

    Potentially catastrophic
    Always minor
    Limited to cabin systems
  6. 6. If a software load fails part-way through, the unit:

    Must not be released to service until correctly loaded
    May be used if it powers up
    Should be returned to stores as serviceable
  7. 7. Software used on an aircraft must come from:

    Approved media and an approved source
    Any copy that matches the part number
    The maintenance organisation's own archive
  8. 8. The record of which software is loaded on an aircraft is kept in the:

    Aircraft configuration record and technical log
    Pilot's operating handbook
    Manufacturer's sales file