Impact Analysis Template#
Impact Analysis Template
|
status: valid
|
||||
Type of Change Request#
[New Feature/Component, Modification of an existing Feature/Component]
Dependencies on other Change Requests#
[List all dependencies on other Change Requests]
Estimates for Realization#
[List all work products and elements affected by the Change Request]
Note
For the identification of the affected work products use the Traceability Analysis approach. Traceability analysis uses the existing links between different elements (requirements, architecture, implementation, etc.) for the identification of the affected work products and elements.
[Describe here which work products to be modified by the Change Request]
[Describe here the verification methods used for the changed work products or elements]
[Estimate the effort, resources, risk for the realization]
[Describe here which stakeholder and which roles of the stakeholder are involved to execute the Change Request]
Note
Typically the Project Leads are involved for planning and approval activities. As well as Safety Manager or Security Manager are responsible for Change Request which has impact on functional safety or security.
[Describe here which Milestones are considered to realize the Change Request]
Note
A draft realization plan may support the realization proposal.
Potential Impact on the platform#
[How could the platform be impacted by the new/modified feature?]
[Describe potential impact and severity on pre-existing platform/project elements.]
Potential Impact on Security#
[How could a malicious user take advantage of this new/modified feature?]
Note
If there are security concerns in relation to the CR, those concerns should be explicitly written out to make sure reviewers of the CR are aware of them.
Which security requirements are affected or has to be changed? Could the new/modified feature enable new threat scenarios? Could the new/modified feature enable new attack paths? Could the new/modified feature impact functional safety? If applicable, which additional security measures must be implemented to mitigate the risk?
Note
Use Trust Boundary, Defense in Depth Analysis and/or Security Software Critically Analysis, Vulnerability Analysis. [Methods will be defined later in Process area Security Analysis] These analyses may not be available at the time of creation of the feature (request) but content will be improved iteratively.
Potential Impact on Safety#
[How could the safety be impacted by the new/modified feature?]
Note
If there are safety concerns in relation to the CR, those concerns should be explicitly written out to make sure reviewers of the CR are aware of them. Link here to the filled out Impact Analysis Template or copy the template in this chapter.
Which safety requirements are affected or has to be changed? Could the new/modified feature be a potential common cause or cascading failure initiator? If applicable, which additional safety measures must be implemented to mitigate the risk?
Note
Use Dependency Failure Analysis and/or Safety Software Critically Analysis. [Methods will be defined later in Process area Safety Analysis] These analyses may not be available at the time of creation of the feature (request) but content will be improved iteratively.
For new feature contributions:
[What is the expected ASIL level?]
License Impact#
[How could the copyright impacted by the license of the new contribution?]