Review of Potential Assurance Case Tool Options for DoD

Abstract

The assurance case framework has the potential to improve the safety certification process for complex systems; however, effective implementation of it relies on tools to help one build a complex assurance case. We previously conducted a survey to identify available assurance case tools. We now build on this work by attempting to directly access assurance case tools and evaluate their ease of installation and use hands-on. Our work uncovered a litany of possible cybersecurity issues with assurance case tools, which make 16 of 17 open access tools studied in this work unsuitable for DoD use. We also contacted 6 commercial assurance case tool developers; though full trial versions of tools were not always available, we identified multiple commercial assurance case tools lacking obvious cybersecurity issues that may be suitable for DoD use. However, given the range of issues identified (and possibility of further unnoticed issues), it may be worthwhile for DoD to invest in assurance case tool development in-house, if DoD intends to push the assurance case approach. We also investigated linkages between assurance case tools and tools for model-based systems engineering (MBSE), and found that very few tools mentioned MBSE or linked to MBSE tools.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Jan 01, 2024
Accession Number
AD1211550

Entities

People

  • Kevin P. Roback

Organizations

  • Institute for Defense Analyses
  • Office Of The Under Secretary Of Defense

Tags

Fields of Study

  • Computer science
  • Engineering

Readers

  • Cybersecurity.
  • Database Systems and Applications
  • Educational Psychology

Technology Areas

  • Cyber