| SWE Title | Requirement |
|---|
| SWE-801 - Single Failure Tolerance | 4.3.1 The space system shall provide at least single failure tolerance to catastrophic events, with specific levels of failure tolerance and implementation (similar or dissimilar redundancy) derived via an integration of the design and safety analysis (required by NPR 8705.2). |
| SWE-802 - Inadvertent Operator Action | 4.3.3 The space system shall be designed to tolerate inadvertent operator action (minimum of one inadvertent action), as verified by a human error analysis, without causing a catastrophic event. |
| SWE-803 - Operator Action With Single System Failure | 4.3.4 The space system shall tolerate inadvertent operator action, as described in Section 4.3.3, in the presence of any single system failure. |
| SWE-804 - Mitigate Hazardous Behavior Of Critical Software | 4.3.5 The space system shall provide the capability to mitigate the hazardous behavior of critical software where the hazardous behavior would result in a catastrophic event. |
| SWE-805 - Detect And Annunciate Faults | 4.3.6 The space system shall provide the capability to detect and annunciate faults that affect critical systems, subsystems, or crew health. |
| SWE-806 - Fault Recovery | 4.3.7 The space system shall provide the capability to isolate and recover from faults identified during system development or mission operations that would result in a catastrophic event. |
| SWE-807 - Data Analysis | 4.3.8 The space system shall provide the capability to utilize health and status data (including system performance data) of critical systems and subsystems to facilitate anomaly resolution during and after the mission. |
| SWE-808 - Autonomous Operation | 4.3.9 The crewed space system shall provide the capability for autonomous operation of system and subsystem functions which, if lost, would result in a catastrophic event. |
| SWE-809 - Crew Operations | 4.4.1 The crewed space system shall provide the capability for the crew to monitor, operate, and control the crewed space system and subsystems, where: - The capability is necessary to execute the mission; or
- The capability would prevent a catastrophic event; or
- The capability would prevent an abort.
|
| SWE-810 - Crew Override | 4.4.2 The crewed space system shall provide the capability for the crew to manually override higher level software control and automation (such as automated abort initiation, configuration change, and mode change) when the transition to manual control of the system will not cause a catastrophic event. |
| SWE-811 - Crew Control | 4.4.3 The space system shall provide the capability for humans to remotely monitor, operate, and control the crewed system elements and subsystems, where: - The remote capability is necessary to execute the mission; or
- The remote capability would prevent a catastrophic event; or
- The remote capability would prevent an abort.
|
| SWE-812 - Crew Flight Control | 4.5.1 The crewed space system shall provide the capability for the crew to manually control the flight path and attitude of their spacecraft, with the following exception: during the atmospheric portion of Earth ascent when structural and thermal margins have been determined to negate the benefits of manual control. |
| SWE-813 - Crew Control Of Uncrewed Spacecraft | 4.6.1 The space system shall provide the capability for the crew to monitor, operate, and control an uncrewed spacecraft during proximity operations, where: - The capability is necessary to execute the mission; or
- The capability would prevent a catastrophic event; or
- The capability would prevent an abort.
|
| SWE-814 - Interface with Launch Vehicle | 4.7.1.3 The crewed space system shall monitor the Earth ascent launch vehicle performance and automatically initiate an abort when an impending catastrophic failure is detected. |
| SWE-815 - Crew Initiate Ascent Abort Sequence | 4.7.1.4.1 The space system shall provide the capability for the crew to initiate the Earth ascent abort sequence. |
| SWE-816 - Ground Initiate Ascent Abort Sequence | 4.7.1.4.2 The space system shall provide the capability for the ground control to initiate the Earth ascent abort sequence. |
| SWE-817 - Interface With Range Safety Destruct System | 4.7.1.5 If a range safety destruct system is incorporated into the design, the space system shall automatically initiate the Earth ascent abort sequence when range safety destruct commands are received onboard, with an adequate time delay prior to destruction of the launch vehicle to allow a successful abort. |
| SWE-818 - Autonomous Mission Abort | 4.7.2 Earth Orbit Systems. The crewed space system shall provide the capability to autonomously abort the mission from Earth orbit by targeting and performing a deorbit to a safe landing on Earth. |