{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T12:42:58Z","timestamp":1740141778472,"version":"3.37.3"},"reference-count":80,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,6,3]],"date-time":"2020-06-03T00:00:00Z","timestamp":1591142400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,6,3]],"date-time":"2020-06-03T00:00:00Z","timestamp":1591142400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["01IS12005c"],"award-info":[{"award-number":["01IS12005c"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Softw Syst Model"],"published-print":{"date-parts":[[2021,2]]},"DOI":"10.1007\/s10270-020-00799-1","type":"journal-article","created":{"date-parts":[[2020,6,3]],"date-time":"2020-06-03T16:23:15Z","timestamp":1591201395000},"page":"175-210","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Generation of hazard relation diagrams: formalization and tool support"],"prefix":"10.1007","volume":"20","author":[{"given":"Bastian","family":"Tenbergen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thorsten","family":"Weyer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,6,3]]},"reference":[{"key":"799_CR1","unstructured":"Allenby, K., Kelly, T.: Deriving safety requirements using scenarios. In: Proceedings of the 5th IEEE International Symposium on Requirements Engineering, pp. 228\u2013235 (2001)"},{"key":"799_CR2","doi-asserted-by":"publisher","first-page":"465","DOI":"10.1007\/s00766-014-0213-z","volume":"20","author":"L Ammar","year":"2015","unstructured":"Ammar, L., Trabelski, A., Mahfoudhi, A.: Incorporating usability requirements into model transformation technologies. Requir. Eng. 20, 465\u2013479 (2015)","journal-title":"Requir. Eng."},{"issue":"3","key":"799_CR3","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1002\/stvr.243","volume":"12","author":"A Aurum","year":"2002","unstructured":"Aurum, A., Petersson, H., Wohlin, C.: State-of-the-art: software inspections after 25 years. Softw. Test. Verif. Reliab. 12(3), 133\u2013154 (2002)","journal-title":"Softw. Test. Verif. Reliab."},{"key":"799_CR4","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1007\/978-94-007-0431-2_5","volume-title":"Foundational Theories of Classical and Constructive Mathematics","author":"S Awodey","year":"2011","unstructured":"Awodey, S.: From sets to types, to categories, to sets. In: Sommaruga, G. (ed.) Foundational Theories of Classical and Constructive Mathematics, pp. 113\u2013125. Springer, Heidelberg (2011)"},{"key":"799_CR5","doi-asserted-by":"crossref","unstructured":"Basir, N., Denney, E., Fischer, B.: Deriving safety cases for hierarchical structure in model-based development. In: Proceedings of the 29th International Conference on Computer Safety, Reliability, and Security, pp. 68\u201381 (2010)","DOI":"10.1007\/978-3-642-15651-9_6"},{"key":"799_CR6","doi-asserted-by":"crossref","unstructured":"Belli, F., Hollmann, A., Nissanke, N.: Modeling, analysis and testing of safety issues\u2014an event-based approach and case study. In: Proceedings of the 26th International Conference Computer Safety, Reliability and Security, pp. 276\u2013282 (2007)","DOI":"10.1007\/978-3-540-75101-4_27"},{"key":"799_CR7","unstructured":"Berry, D.: The safety requirements engineering dilemma. In: Proceedings of the 9th International Workshop on Software Specification and Design, pp. 147\u2013149 (1998)"},{"issue":"1","key":"799_CR8","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1023\/A:1008697817793","volume":"6","author":"R Bharadwaj","year":"1999","unstructured":"Bharadwaj, R., Heitmeyer, C.: Model checking complete requirements specifications using abstraction. Autom. Softw. Eng. 6(1), 37\u201368 (1999)","journal-title":"Autom. Softw. Eng."},{"key":"799_CR9","unstructured":"Bishop, P., Bloomfield, R., Guerra, S.: The future of goal-based assurance cases. In: Proceedings of the Workshop on Assurance Cases. Supplemental Volume of the 2004 International Conference on Dependable Systems and Networks, pp. 390\u2013395 (2004)"},{"key":"799_CR10","doi-asserted-by":"crossref","unstructured":"Bitsch, F.: Safety patterns\u2014the key to formal specification of safety requirements. In: Proceedings of the 20th International Conference on Computer Safety, Reliability and Security, pp. 176\u2013189 (2001)","DOI":"10.1007\/3-540-45416-0_18"},{"key":"799_CR11","doi-asserted-by":"crossref","unstructured":"Boehm, B.: Verifying and validating software requirements and design specifications. IEEE Softw. 75\u201388 (1984)","DOI":"10.1109\/MS.1984.233702"},{"key":"799_CR12","unstructured":"Carver, J., Jaccheri, L., Morasca, S., Shull, F.: Issues in using students in empirical studies in software engineering education. In: Proceedings of the 9th International Software Metrics Symposium, pp. 239\u2013249 (2003)"},{"issue":"6","key":"799_CR13","doi-asserted-by":"publisher","first-page":"800","DOI":"10.1109\/TSE.2008.49","volume":"34","author":"J Carver","year":"2008","unstructured":"Carver, J., Nagappan, N., Page, A.: The impact of educational background on the effectiveness of requirements inspections: an empirical study. IEEE Trans. Softw. Eng. 34(6), 800\u2013812 (2008)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"799_CR14","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1145\/295558.295570","volume":"8","author":"S Cheung","year":"1999","unstructured":"Cheung, S., Kramer, J.: Checking Safety properties using compositional reachability analysis. ACM Trans. Softw. Eng. Methodol. 8, 49\u201378 (1999)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"799_CR15","doi-asserted-by":"crossref","unstructured":"Cleland-Huang, J., Heimdahl, M., Huffman Hayes, J., Lutz, R., Maeder, P.: Trace queries for safety requirements in high assurance systems. In: Proceedings of the 18th International Working Conference on Requirements Engineering: Foundation for Software Quality, pp. 179\u2013193 (2012)","DOI":"10.1007\/978-3-642-28714-5_16"},{"key":"799_CR16","doi-asserted-by":"crossref","unstructured":"Cleland-Huang, J., Settimi, R., BenKhadra, O., Berezhanskaya, E., Christina, S.: Goal-centric traceability for managing non-functional requirements. In: Proceedings of the 27th International Conference on Software Engineering, pp. 362\u2013371 (2005)","DOI":"10.1145\/1062455.1062525"},{"key":"799_CR17","unstructured":"Cooper, K., DePrenger, M., Mattern, S., McKinley, A., Pajouhesh, A., Shampine, D.: Joint Software Systems Safety Engineering Handbook. United States Department of Defense, Version 1.0, 2010. http:\/\/www.acqnotes.com\/Attachments\/Joint-SW-Systems-Safety-Engineering-Handbook.pdf. Accessed 9 Apr 2020"},{"key":"799_CR18","doi-asserted-by":"publisher","DOI":"10.4135\/9781452230153","volume-title":"Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory","author":"J Corbin","year":"2008","unstructured":"Corbin, J., Strauss, A.: Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory, 3rd edn. Sage Publications, Los Angeles (2008)","edition":"3"},{"key":"799_CR19","doi-asserted-by":"crossref","unstructured":"Despotou, G., Kelly, T., White, S., Ryan, M.: Introducing safety cases for health IT. In: Proceedings of the 4th International Workshop on Software Engineering in Health Care, pp. 44\u201350 (2012)","DOI":"10.1109\/SEHC.2012.6227010"},{"key":"799_CR20","unstructured":"Dezfuli, H., Benjamin, A., Everett, M., Smith, C., Stamatelatos, M., Youngblood, R.: NASA System Safety Handbook. Volume 1, System Safety Framework and Concepts for Implementation. US National Aeronautics and Space Administration, Document No. NASA\/SP-2010-580 (2011). https:\/\/ntrs.nasa.gov\/search.jsp?R=20120003291. Accessed 25 Oct 2018"},{"key":"799_CR21","doi-asserted-by":"crossref","unstructured":"Dittel, T., Aryus, H.: How to \u201csurvive\u201d a safety case according to ISO 26262. In: Proceedings of the 29th International Conference on Computer Safety, Reliability and Security, pp. 97\u2013111 (2010)","DOI":"10.1007\/978-3-642-15651-9_8"},{"key":"799_CR22","unstructured":"Eclipse UML2 Tools: Luna Package Distribution. https:\/\/goo.gl\/6EfDUi. Accessed 25 Oct 2018"},{"key":"799_CR23","unstructured":"Eclipse UML2 Tools: Luna Package Distribution. https:\/\/goo.gl\/fXLxfe. Accessed 25 Oct 2018"},{"key":"799_CR24","unstructured":"Eclipse Modeling Tools: Luna Package Distribution. https:\/\/goo.gl\/qo9Sf5. Accessed 25 Oct 2018"},{"key":"799_CR25","doi-asserted-by":"publisher","DOI":"10.1002\/0471739421","volume-title":"Hazard Analysis Techniques for System Safety","author":"C Ericson III","year":"2005","unstructured":"Ericson III, C.: Hazard Analysis Techniques for System Safety. Wiley, Hoboken (2005)"},{"key":"799_CR26","doi-asserted-by":"crossref","unstructured":"Eshuis, R., Wieringa, R.: A formal semantics for UML activity diagrams\u2014formalizing workflow models. Technical report, University of Twente (2001)","DOI":"10.1007\/3-540-45314-8_7"},{"issue":"3","key":"799_CR27","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1147\/sj.153.0182","volume":"15","author":"M Fagan","year":"1976","unstructured":"Fagan, M.: Design and code inspections to reduce errors in program development. IBM Syst. J. 15(3), 182\u2013211 (1976)","journal-title":"IBM Syst. J."},{"issue":"7","key":"799_CR28","doi-asserted-by":"publisher","first-page":"744","DOI":"10.1109\/TSE.1986.6312976","volume":"12","author":"M Fagan","year":"1986","unstructured":"Fagan, M.: Advances in software inspections. IEEE Trans. Softw. Eng. 12(7), 744\u2013751 (1986)","journal-title":"IEEE Trans. Softw. Eng."},{"issue":"3","key":"799_CR29","doi-asserted-by":"publisher","first-page":"27","DOI":"10.5381\/jot.2004.3.3.c3","volume":"3","author":"D Firesmith","year":"2004","unstructured":"Firesmith, D.: Engineering safety requirements, safety constraints, and safety-critical requirements. J. Object Technol. 3(3), 27\u201342 (2004)","journal-title":"J. Object Technol."},{"issue":"3","key":"799_CR30","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1111\/j.1365-2575.1994.tb00051.x","volume":"4","author":"D Flynn","year":"1994","unstructured":"Flynn, D., Warhurst, R.: An empirical study of the validation process within requirements determination. Inf. Syst. J. 4(3), 185\u2013212 (1994)","journal-title":"Inf. Syst. J."},{"issue":"2","key":"799_CR31","first-page":"6","volume":"5","author":"L Fuentes-Fernand\u00e9s","year":"2004","unstructured":"Fuentes-Fernand\u00e9s, L., Vallecillo-Moreno, A.: An introduction to UML profiles. Upgrade 5(2), 6\u201313 (2004)","journal-title":"Upgrade"},{"issue":"3\u20134","key":"799_CR32","doi-asserted-by":"publisher","first-page":"363","DOI":"10.1007\/s00450-014-0256-x","volume":"30","author":"M Glinz","year":"2015","unstructured":"Glinz, M., Fricker, S.: On shared understanding in software engineering: an essay. Comput. Sci. Res. Dev. 30(3\u20134), 363\u2013376 (2015)","journal-title":"Comput. Sci. Res. Dev."},{"key":"799_CR33","unstructured":"Glinz, M.: Improving the quality of requirements with scenarios. In: Proceedings of the 2nd World Congress on Software Quality, pp. 55\u201360 (2000)"},{"issue":"1","key":"799_CR34","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1111\/j.1540-5915.1998.tb01346.x","volume":"29","author":"D Goodhue","year":"1998","unstructured":"Goodhue, D.: Development and measurement validity of a task-technology fit instrument for user evaluations of information system. Decis. Sci. 29(1), 105\u2013138 (1998)","journal-title":"Decis. Sci."},{"key":"799_CR35","doi-asserted-by":"crossref","unstructured":"Guillerm, R., Sadou, N., Demmou, H.: Combining FMECA and fault trees for declining safety requirements of complex systems. In: Proceedings of the Annual European Safety and Reliability Conference, pp. 1287\u20131293 (2011)","DOI":"10.1201\/b11433-182"},{"issue":"7","key":"799_CR36","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1109\/32.708570","volume":"24","author":"K Hansen","year":"1998","unstructured":"Hansen, K., Ravn, A., Stavridou, V.: From safety analysis to software requirements. IEEE Trans. Softw. Eng. 24(7), 573\u2013584 (1998)","journal-title":"IEEE Trans. Softw. Eng."},{"issue":"7","key":"799_CR37","doi-asserted-by":"publisher","first-page":"655","DOI":"10.1002\/1098-2736(200009)37:7<655::AID-TEA3>3.0.CO;2-E","volume":"37","author":"C Hart","year":"2000","unstructured":"Hart, C., Mulhall, P., Berry, A., Loughran, J., Gunstone, R.: What is the purpose of this experiment? Or can students learn something from doing experiments? J. Res. Sci. Teach. 37(7), 655\u2013675 (2000)","journal-title":"J. Res. Sci. Teach."},{"key":"799_CR38","doi-asserted-by":"crossref","unstructured":"Hatcliff, J., Wassyng, A., Kelly, T., Comar, C., Jones, P.: Certifiably safe software-dependent systems: challenges and directions. In: Proceedings on the Future Software Engineering, pp. 182\u2013200 (2014)","DOI":"10.1145\/2593882.2593895"},{"key":"799_CR39","doi-asserted-by":"crossref","unstructured":"Hawkins, R., Kelly, T., Knight, J., Graydon, P.: A new approach to creating clear safety arguments. In: Advances in Systems Safety, pp. 3\u201323. Springer, London (2011)","DOI":"10.1007\/978-0-85729-133-2_1"},{"issue":"11","key":"799_CR40","doi-asserted-by":"publisher","first-page":"927","DOI":"10.1109\/32.730543","volume":"24","author":"C Heitmeyer","year":"1998","unstructured":"Heitmeyer, C., Kirby, J., Labaw, B., Archer, M., Bharadwaj, R.: Using abstraction and model checking to detect safety violations in requirements specifications. IEEE Trans. Softw. Eng. 24(11), 927\u2013948 (1998)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"799_CR41","doi-asserted-by":"crossref","unstructured":"High, K., Kelly, T., Mcdermid, J.: Safety Case Construction and Reuse using Patterns, pp. 55\u201369 (1997)","DOI":"10.1007\/978-1-4471-0997-6_5"},{"key":"799_CR42","unstructured":"International Organization for Standardization: ISO26262: Road Vehicles\u2014Functional Safety (2011)"},{"key":"799_CR43","unstructured":"International Requirements Engineering Board: IREB Glossary, version 1.6. https:\/\/goo.gl\/NOh7NX. Accessed 25 Oct 2018"},{"key":"799_CR44","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/978-1-84800-044-5_8","volume-title":"Guide to Advanced Empirical Software Engineering","author":"A Jedlitschka","year":"2008","unstructured":"Jedlitschka, A., Ciolkowski, M., Pfahl, D.: Reporting experiments in software engineering. In: Shull, F., Singer, J., Sj\u00f8berg, D.I.K. (eds.) Guide to Advanced Empirical Software Engineering, pp. 201\u2013228. Springer, London (2008)"},{"key":"799_CR45","unstructured":"Kelly, T., Weaver, R.: The goal structuring notation\u2014a safety argument notation. In: Proceedings of the Workshop on Assurance Cases of Dependable Systems and Networks (2004)"},{"key":"799_CR46","unstructured":"Kelly, T.: Reviewing assurance arguments\u2014a step-by-step approach. In: Proceedings of the Workshop Assurance Cases for Security (2007)"},{"key":"799_CR47","doi-asserted-by":"publisher","DOI":"10.1002\/9780470249260","volume-title":"Domain-Specific Modeling\u2014Enabling Full Code Generation","author":"S Kelly","year":"2008","unstructured":"Kelly, S., Tolvanen, J.-P.: Domain-Specific Modeling\u2014Enabling Full Code Generation. Wiley, New York (2008)"},{"key":"799_CR48","unstructured":"Kotonya, G., Sommerville, I.: Integrating safety analysis and requirements engineering. In: Proceedings of the Joint 4th International Computer Science Conference and the 4th Asia-Pacific Software Engineering Conference, pp. 259\u2013271 (1997)"},{"key":"799_CR49","doi-asserted-by":"crossref","unstructured":"Lagarde, F., Espinoza, H., Terrier, F., Andr\u00e9, C., G\u00e9rard, S.: Leveraging patterns on domain models to improve UML profile definition. In: Proceedings of 11th International Conference on Fundamental Approaches to Software Engineering, pp. 116\u2013130 (2008)","DOI":"10.1007\/978-3-540-78743-3_10"},{"key":"799_CR50","doi-asserted-by":"crossref","unstructured":"Lagarde, F., Espinoza, H., Terrier, F., G\u00e9rard, S.: Improving UML profile design practices by leveraging conceptual domain models. In: Proceedings of the 22nd IEEE\/ACM International Conference on Automated Software Engineering, pp. 445\u2013448 (2007)","DOI":"10.1145\/1321631.1321705"},{"key":"799_CR51","doi-asserted-by":"publisher","first-page":"1612","DOI":"10.1016\/j.jss.2009.08.022","volume":"83","author":"J Lee","year":"2010","unstructured":"Lee, J., Katta, V., Jee, E., Raspotnig, C.: Means-ends and whole-part traceability analysis of safety requirements. J Syst. Softw. 83, 1612\u20131621 (2010)","journal-title":"J Syst. Softw."},{"key":"799_CR52","unstructured":"Lehmann, E., Leighton, F., Meyer, A.: Mathematics for Computer Science. (2017). https:\/\/courses.csail.mit.edu\/6.042\/spring17\/mcs.pdf. Accessed 6 Nov 2018"},{"key":"799_CR53","volume-title":"Safeware: System Safety and Computers","author":"N Leveson","year":"1995","unstructured":"Leveson, N.: Safeware: System Safety and Computers. Addison-Wesley, Reading (1995)"},{"key":"799_CR54","volume-title":"Engineering a Safer World: Systems Thinking Applied to Safety","author":"N Leveson","year":"2011","unstructured":"Leveson, N.: Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Cambridge (2011)"},{"key":"799_CR55","unstructured":"Leveson, N.: The use of safety cases in certification and regulation. J. Syst. Saf. 47(6) (2011). https:\/\/dspace.mit.edu\/handle\/1721.1\/102833. Accessed 9 Apr 2020"},{"key":"799_CR56","volume-title":"Driver Assistance Systems Technical Manual","author":"M Maurer","year":"2009","unstructured":"Maurer, M.: Design and test of driver assistance systems. In: Winner, H., Hakuli, S., Wolf, G. (eds.) Driver Assistance Systems Technical Manual. Vieweg + Teubner, Berlin (2009). (in German)"},{"issue":"6","key":"799_CR57","doi-asserted-by":"publisher","first-page":"756","DOI":"10.1109\/TSE.2009.67","volume":"35","author":"D Moody","year":"2009","unstructured":"Moody, D.: The \u201cphysics\u201d of notation: toward a scientific basis for constructing visual notations in software engineering. IEEE Trans. Softw. Eng. 35(6), 756\u2013779 (2009)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"799_CR58","unstructured":"Object Management Group: Meta Object Facility (MOF) 2.0 Query\/View\/Transformation Specification, Version 1.3. OMG Document Number formal\/2016-06-03. http:\/\/goo.gl\/RGUr44. Accessed 25 Oct 2018"},{"key":"799_CR59","unstructured":"Object Management Group: OMG Meta Object Facility (MOF) Core, Version 2.5. OMG Document Number formal\/2015-06-05. http:\/\/goo.gl\/phs4kA. Accessed 25 Oct 2018"},{"key":"799_CR60","unstructured":"Object Management Group: OMG Unified Modeling Language (OMG UML), Version 2.5. OMG Document Number formal\/2015-03-01. http:\/\/goo.gl\/7cQyPv. Accessed 25 Oct 2018"},{"key":"799_CR61","doi-asserted-by":"crossref","unstructured":"Palin, R., Habli, I.: Assurance of Automotive Safety\u2014A Safety Case Approach, vol. 6351, pp. 82\u201396 (2010)","DOI":"10.1007\/978-3-642-15651-9_7"},{"key":"799_CR62","doi-asserted-by":"crossref","unstructured":"Panach, J.I., Espa\u00f1a, S., Moreno, A.M., Pastor, \u00d3.: Dealing with usability in model transformation technologies. In: Proceedings of Conceptual Modeling, pp. 498\u2013511 (2008)","DOI":"10.1007\/978-3-540-87877-3_36"},{"key":"799_CR63","unstructured":"QVT Operational Eclipse Plugin, v3.5.0. https:\/\/goo.gl\/SglK1F. Accessed 25 Oct 2018"},{"key":"799_CR64","doi-asserted-by":"crossref","unstructured":"Saeed, A., de Lemos, R., Anderson, T.: Robust requirements specifications for safety-critical systems. In: Proceedings of the 12th International Conference on Computer Safety, Reliability and Security (1993)","DOI":"10.1007\/978-1-4471-2061-2_23"},{"key":"799_CR65","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1145\/1178625.1178628","volume":"15","author":"G Snelting","year":"2006","unstructured":"Snelting, G., Robschink, T., Krinke, J.: Efficient path conditions in dependence graphs for software safety analysis. ACM Trans. Softw. Eng. Methodol. 15, 410\u2013457 (2006)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"799_CR66","unstructured":"SparxSystems Enterprise Architect, Version 14. https:\/\/goo.gl\/V7z4Ms. Accessed 25 Oct 2018"},{"key":"799_CR67","unstructured":"SparxSystems: Enterprise Architect User Guide (2014). https:\/\/goo.gl\/w2Enek. Accessed 25 Oct 2018"},{"key":"799_CR68","doi-asserted-by":"crossref","unstructured":"Stamm, B., Baumann, R., K\u00fcndig-Herzog, M.: A safety critical computer system in a railway application. In: Proceedings of the 12th International Conference on Computer Safety, Reliability and Security (1993)","DOI":"10.1007\/978-1-4471-2061-2_20"},{"key":"799_CR69","doi-asserted-by":"crossref","unstructured":"Str\u00fcber, D., Born, K., Gill, R. Groner, K.D., Kehrer, T., Ohrndorf, M., Tichy, M.: Henshin: a usability-focused framework for EMF model transformation development. In: Proceedings of the International Conference on Graph Transformations, pp. 196\u2013208 (2017)","DOI":"10.1007\/978-3-319-61470-0_12"},{"key":"799_CR70","unstructured":"Sun, L.: Establishing Confidence in Safety Assessment Evidence. Dissertation, University of York (2012)"},{"key":"799_CR71","doi-asserted-by":"crossref","unstructured":"Tenbergen, B., Weyer, T., Pohl, K.: Supporting the validation of adequacy in requirements-based hazard mitigations. In: Proceedings of the 21st International Working Conference on Requirements Engineering: Foundation for Software Quality, pp. 17\u201332 (2015)","DOI":"10.1007\/978-3-319-16101-3_2"},{"issue":"2","key":"799_CR72","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1007\/s00766-017-0267-9","volume":"23","author":"B Tenbergen","year":"2018","unstructured":"Tenbergen, B., Weyer, T., Pohl, K.: Hazard relation diagrams: a diagrammatic representation to increase validation objectivity of requirements-based hazard mitigations. Requir Eng J 23(2), 291\u2013329 (2018). https:\/\/doi.org\/10.1007\/s00766-017-0267-9","journal-title":"Requir Eng J"},{"key":"799_CR73","doi-asserted-by":"crossref","unstructured":"Troubitsyna, E.: Elicitation and Specification of Safety Requirements. In: Proceedings of the 3rd International Conference on Systems, pp. 202\u2013207 (2008)","DOI":"10.1109\/ICONS.2008.56"},{"key":"799_CR74","unstructured":"Tsuchiya, T., Terada, H., Kusumoto, S., Kikuno, T., Kim, E.: Derivation of safety requirements for safety analysis of object-oriented design documents. In: Proceedings of the 21st Annual International Computer Software and Applications Conference, pp. 252-255 (1997)"},{"issue":"2","key":"799_CR75","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1111\/j.1540-5915.2008.00192.x","volume":"39","author":"V Venkatesh","year":"2008","unstructured":"Venkatesh, V., Bala, H.: Technology acceptance model 3 and a research agenda on interventions. Decis. Sci. 39(2), 273\u2013315 (2008)","journal-title":"Decis. Sci."},{"key":"799_CR76","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1142\/S0218539301000335","volume":"8","author":"J Wang","year":"2001","unstructured":"Wang, J., Yang, J.: A subjective safety and cost based decision model for assessing safety requirements specifications. Int. J. Reliab. Qual. Saf. Eng. 8, 35\u201357 (2001)","journal-title":"Int. J. Reliab. Qual. Saf. Eng."},{"key":"799_CR77","volume-title":"Peer Reviews in Software: A Practical Guide","author":"K Wiegers","year":"2002","unstructured":"Wiegers, K.: Peer Reviews in Software: A Practical Guide. Addison-Wesley, Boston (2002)"},{"key":"799_CR78","doi-asserted-by":"crossref","unstructured":"Wilson, S., Kelly, T., McDermid, J.: Safety case development: current practice, future prospects. In: Proceedings of the 12th Annual CSR WS on Safety and Reliability of Software Based Systems, pp. 135\u2013156 (1997)","DOI":"10.1007\/978-1-4471-0921-1_6"},{"key":"799_CR79","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-29044-2","volume-title":"Experimentation in Software Engineering","author":"C Wohlin","year":"2012","unstructured":"Wohlin, C., Runeson, P., H\u00f6st, M., Ohlsson, M., Regnell, B., Weel\u00e9n, A.: Experimentation in Software Engineering. Springer, Heidelberg (2012)"},{"key":"799_CR80","doi-asserted-by":"crossref","unstructured":"Xu, X., Bao, X., Lu, M., Chang, W.: A study and application on airborne software safety requirements elicitation. In: Proceedings of the 9th International Conference on Reliability, Maintainability and Safety, pp. 710\u2013716 (2011)","DOI":"10.1109\/ICRMS.2011.5979357"}],"container-title":["Software and Systems Modeling"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-020-00799-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10270-020-00799-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-020-00799-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T23:24:06Z","timestamp":1622676246000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10270-020-00799-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,3]]},"references-count":80,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,2]]}},"alternative-id":["799"],"URL":"https:\/\/doi.org\/10.1007\/s10270-020-00799-1","relation":{},"ISSN":["1619-1366","1619-1374"],"issn-type":[{"type":"print","value":"1619-1366"},{"type":"electronic","value":"1619-1374"}],"subject":[],"published":{"date-parts":[[2020,6,3]]},"assertion":[{"value":"7 November 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 March 2020","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 April 2020","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 June 2020","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}