{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T11:09:02Z","timestamp":1785841742138,"version":"3.56.0"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2017,12,4]],"date-time":"2017-12-04T00:00:00Z","timestamp":1512345600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100009527","name":"Myndigheten f\u00f6r Samh\u00e4llsskydd och Beredskap","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100009527","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004955","name":"\u00d6sterreichische Forschungsf\u00f6rderungsgesellschaft","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004955","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Software Qual J"],"published-print":{"date-parts":[[2019,3]]},"DOI":"10.1007\/s11219-017-9396-0","type":"journal-article","created":{"date-parts":[[2017,12,4]],"date-time":"2017-12-04T01:50:10Z","timestamp":1512352210000},"page":"349-387","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":90,"title":["Comparison of the FMEA and STPA safety analysis methods\u2013a case study"],"prefix":"10.1007","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8635-7462","authenticated-orcid":false,"given":"Sardar Muhammad","family":"Sulaman","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Armin","family":"Beer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Felderer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"H\u00f6st","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,12,4]]},"reference":[{"key":"9396_CR1","doi-asserted-by":"crossref","unstructured":"Becker, J.C., & Flick, G. (1996). A practical approach to failure mode, effects and criticality analysis (FMECA) for computing systems. In Proceedings of the IEEE High-Assurance Systems Engineering Workshop (pp. 228\u2013236).","DOI":"10.1002\/j.2334-5837.1996.tb01996.x"},{"key":"9396_CR2","unstructured":"Bond, & et al. (2003). Collision mitigation by braking system. US Patent 6607255B2."},{"key":"9396_CR3","doi-asserted-by":"crossref","unstructured":"Coelingh, E., Eidehall, A., Bengtsson, M. (2010). Collision warning with full auto brake and pedestrian detection-a practical example of automatic emergency braking. In Proceedings of the 13th International IEEE Conference on Intelligent Transportation Systems (ITSC\u201910) (pp. 155\u2013160).","DOI":"10.1109\/ITSC.2010.5625077"},{"issue":"3","key":"9396_CR4","doi-asserted-by":"publisher","first-page":"319","DOI":"10.2307\/249008","volume":"13","author":"FD Davis","year":"1989","unstructured":"Davis, F.D. (1989). Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS Quarterly, 13(3), 319\u2013340.","journal-title":"MIS Quarterly"},{"issue":"8","key":"9396_CR5","doi-asserted-by":"publisher","first-page":"982","DOI":"10.1287\/mnsc.35.8.982","volume":"35","author":"FD Davis","year":"1989","unstructured":"Davis, F.D., Bagozzi, R.P., Warshaw, P.R. (1989). User acceptance of computer technology: a comparison of two theoretical models. Management Science, 35 (8), 982\u20131003.","journal-title":"Management Science"},{"issue":"5","key":"9396_CR6","doi-asserted-by":"publisher","first-page":"627","DOI":"10.1007\/s10009-014-0330-5","volume":"16","author":"G Erdogan","year":"2014","unstructured":"Erdogan, G., Li, Y., Runde, R.K., Seehusen, F., St\u00f8len, K. (2014). Approaches for the combined use of risk analysis and testing: a systematic literature review. International Journal on Software Tools for Technology Transfer, 16(5), 627\u2013642.","journal-title":"International Journal on Software Tools for Technology Transfer"},{"key":"9396_CR7","unstructured":"Ericson, C.A. (1999). Fault tree analysis-a history. In Proceedings of The 17th International System Safety Conference."},{"key":"9396_CR8","doi-asserted-by":"crossref","unstructured":"Eubanks, C.F., Kmenta, S., Ishii, K. (1997). Advanced failure modes and effects analysis using behavior modeling. In Proceedings of DETC\u201997 ASME Design Engineering Technical Conferences and Design Theory and Methodology Conference Sacramento, California, USA.","DOI":"10.1115\/DETC97\/DTM-3872"},{"issue":"5","key":"9396_CR9","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1007\/s10009-014-0332-3","volume":"16","author":"M Felderer","year":"2014","unstructured":"Felderer, M., & Schieferdecker, I. (2014). A taxonomy of risk-based testing. International Journal on Software Tools for Technology Transfer, 16(5), 559\u2013568.","journal-title":"International Journal on Software Tools for Technology Transfer"},{"key":"9396_CR10","unstructured":"Fleming, C.H., Spencer, M., Leveson, N.G., Wilkinson, C. (2012). Safety assurance in NextGen. Tech. rep., NASA Technical report NASA\/CR-2012-217553."},{"key":"9396_CR11","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1016\/j.ssci.2012.12.005","volume":"55","author":"CH Fleming","year":"2013","unstructured":"Fleming, C.H., Spencer, M., Thomas, J., Leveson, N., Wilkinson, C. (2013). Safety assurance in NextGen and complex transportation systems. Safety Science, 55, 173\u2013187.","journal-title":"Safety Science"},{"key":"9396_CR12","doi-asserted-by":"crossref","unstructured":"Grunske, L., Colvin, R., Winter, K. (2007). Probabilistic model-checking support for FMEA. In Proceedings of the 4:th International Conference on the Quantitative Evaluation of Systems (QEST\u201907) (pp. 119\u2013128).","DOI":"10.1109\/QEST.2007.18"},{"key":"9396_CR13","unstructured":"Haissig, C.M., & Brandao, R. (2012). Using TCAS surveillance to enable legacy ADS-B transponder use for in-trail procedures. In Proceedings of the 31st IEEE\/AIAA Digital Avionics Systems Conference (DASC), Williamsburg, Virginia, USA (pp. 5D5:1\u20135D5:114)."},{"key":"9396_CR14","unstructured":"I.E.C. 60812:2006. (2006). Analysis techniques for system reliability-procedure for failure mode and effects analysis (FMEA). http:\/\/www.iec.chAugust2014 ."},{"key":"9396_CR15","unstructured":"Ishimatsu, T., Leveson, N.G., Thomas, J., Katahira, M., Miyamoto, Y., Nakao, H. (2010). Modeling and hazard analysis using STPA. In NASA 2010 IV&V Annual Workshop, NASA."},{"issue":"2","key":"9396_CR16","doi-asserted-by":"publisher","first-page":"509","DOI":"10.2514\/1.A32449","volume":"51","author":"T Ishimatsu","year":"2014","unstructured":"Ishimatsu, T., Leveson, N.G., Thomas, J.P., Fleming, C.H., Katahira, M., Miyamoto, Y., Ujiie, R., Nakao, H., Hoshino, N. (2014). Hazard analysis of complex spacecraft using systems-theoretic process analysis. Journal of Spacecraft and Rockets, 51(2), 509\u2013522.","journal-title":"Journal of Spacecraft and Rockets"},{"issue":"3","key":"9396_CR17","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1007\/s10664-005-1290-x","volume":"10","author":"TC Lethbridge","year":"2005","unstructured":"Lethbridge, T.C., Sim, S.E., Singer, J. (2005). Studying software engineers: data collection techniques for software field studies. Empirical Software Engineering, 10(3), 311\u2013341. https:\/\/doi.org\/https:\/\/doi.org\/10.1007\/s10664-005-1290-x .","journal-title":"Empirical Software Engineering"},{"key":"9396_CR18","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/8179.001.0001","volume-title":"Engineering a safer world: systems thinking applied to safety","author":"NG Leveson","year":"2012","unstructured":"Leveson, N.G. (2012). Engineering a safer world: systems thinking applied to safety. Cambridge: The MIT Press."},{"key":"9396_CR19","doi-asserted-by":"crossref","unstructured":"Leveson, N.G., Fleming, C.H., Spencer, M., Thomas, J., Wilkinson, C. (2012). Safety assessment of complex, software-intensive systems. SAE International Journal of Aerospace, 5(1), 233\u2013244.","DOI":"10.4271\/2012-01-2134"},{"issue":"46","key":"9396_CR20","first-page":"65","volume":"1","author":"MO M\u00e4ckel","year":"2001","unstructured":"M\u00e4ckel, M.O. (2001). Mit blick auf\u2019s risiko. software-fmea im entwicklungsprozess softwareintensiver technischer systeme. Qualit\u00e4t und Zuverl\u00e4ssigkeit, 1(46), 65\u201368.","journal-title":"Qualit\u00e4t und Zuverl\u00e4ssigkeit"},{"key":"9396_CR21","doi-asserted-by":"crossref","unstructured":"McDermid, J.A., Nicholson, M., Pumfrey, D.J., Fenelon, P. (1995). Experience with the application of HAZOP to computer-based systems. In Proceedings of the 10th Annual Conference on Computer Assurance (COMPASS\u201995), Systems Integrity, Software Safety and Process Security (pp. 37\u201348).","DOI":"10.1109\/CMPASS.1995.521885"},{"key":"9396_CR22","unstructured":"McDermott, R.E., Mikulak, R.J., Beauregard, M.R. (2008). The basics of FMEA. Productivity Press, paper back."},{"key":"9396_CR23","volume-title":"The practical guide to defect prevention","author":"M McDonald","year":"2008","unstructured":"McDonald, M., Musson, R., Smith, R. (2008). The practical guide to defect prevention. USA: Microsoft Press."},{"key":"9396_CR24","unstructured":"Menkhaus, G., & Andrich, B. (2005). Metric suite directing the failure mode analysis of embedded software systems. In ICEIS (3) (pp. 266\u2013273)."},{"key":"9396_CR25","unstructured":"MIL-STD-1629A. (1980). Procedures for performing a failure mode, effects and criticality analysis, U.S. Department of Defense."},{"key":"9396_CR26","unstructured":"Nakao, H., Katahira, M., Miyamoto, Y., Leveson, G.N. (2011). Safety guided design of crew return vehicle in concept design phase using STAMP\/STPA. In Proceedings of the 5th International Association for the Advancement of Space Safety (IAASS) Conference - A Safer Space for a Safer World (pp. 497\u2013501). Netherlands: Noordwijk."},{"key":"9396_CR27","doi-asserted-by":"crossref","unstructured":"Peischl, B., Felderer, M., Beer, A. (2016). Testing security requirements with non-experts: approaches and empirical investigations. In 2016 IEEE International Conference on Software quality, reliability and security (QRS) (pp. 254\u2013261): IEEE.","DOI":"10.1109\/QRS.2016.37"},{"key":"9396_CR28","unstructured":"Pereira, S.J., Lee, G., Howard, J. (2006). A system-theoretic hazard analysis methodology for a non-advocate safety assessment of the ballistic missile defense system. In Proceedings of the AIAA Missile Sciences Conference, Monterey, California."},{"key":"9396_CR29","doi-asserted-by":"crossref","unstructured":"Pries, K.H. (1998). Failure mode & effects analysis in software development. Tech. rep., SAE Technical Paper.","DOI":"10.4271\/982816"},{"key":"9396_CR30","doi-asserted-by":"crossref","unstructured":"Ramler, R., & Felderer, M. (2015). A process for risk-based test strategy development and its industrial evaluation. In International Conference on Product-Focused Software Process Improvement (pp. 355\u2013371): Springer.","DOI":"10.1007\/978-3-319-26844-6_26"},{"issue":"4","key":"9396_CR31","doi-asserted-by":"publisher","first-page":"1124","DOI":"10.1016\/j.jss.2012.12.002","volume":"86","author":"C Raspotnig","year":"2013","unstructured":"Raspotnig, C., & Opdahl, A. (2013). Comparing risk identification techniques for safety and security requirements. Journal of Systems and Software, 86(4), 1124\u20131151.","journal-title":"Journal of Systems and Software"},{"issue":"2","key":"9396_CR32","first-page":"91","volume":"12","author":"F Redmill","year":"2002","unstructured":"Redmill, F. (2002). Risk analysis-a subjective process. Engineering Management Journal, 12(2), 91\u201396.","journal-title":"Engineering Management Journal"},{"key":"9396_CR33","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4471-0883-2","volume-title":"System safety: HAZOP and software HAZOP","author":"F Redmill","year":"1999","unstructured":"Redmill, F., Chudleigh, M., Catmur, J. (1999). System safety: HAZOP and software HAZOP. Hoboken: Wiley."},{"key":"9396_CR34","unstructured":"RTCA\/DO-312. (2008). Safety, performance, and interoperability requirements document for the in-trail procedure in oceanic airspace (ATSA-ITP) application. Tech. rep., RTCA Incorporate, Washington DC."},{"key":"9396_CR35","doi-asserted-by":"publisher","DOI":"10.1002\/9781118181034","volume-title":"Case study research in software engineering: guidelines and examples","author":"P Runeson","year":"2012","unstructured":"Runeson, P., H\u00f6st, M, Rainer, A., Regnell, B. (2012). Case study research in software engineering: guidelines and examples, 1st edn. Hoboken: Wiley.","edition":"1st edn"},{"key":"9396_CR36","unstructured":"Schmittner, C., Gruber, T., Puschner, P., Schoitsch, E. (2014). Security application of failure mode and effect analysis (FMEA). In Computer safety, reliability, and security (pp. 310\u2013325): Springer."},{"issue":"1","key":"9396_CR37","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00766-004-0194-4","volume":"10","author":"G Sindre","year":"2005","unstructured":"Sindre, G., & Opdahl, A.L. (2005). Eliciting security requirements with misuse cases. Requirements Engineering, 10(1), 34\u201344.","journal-title":"Requirements Engineering"},{"key":"9396_CR38","doi-asserted-by":"crossref","unstructured":"Stadler, J.J., & Seidl, N.J. (2013). Software failure modes and effects analysis. In Reliability and Maintainability Symposium (RAMS), 2013 Proceedings-Annual (pp. 1\u20135): IEEE.","DOI":"10.1109\/RAMS.2013.6517710"},{"key":"9396_CR39","doi-asserted-by":"crossref","unstructured":"Sta\u0307lhane, T., & Sindre, G. (2007). A comparison of two approaches to safety analysis based on use cases. In Conceptual Modeling - ER 2007, Springer Berlin Heidelberg, Lecture Notes in Computer Science, (Vol. 4801 pp. 423\u2013437).","DOI":"10.1007\/978-3-540-75563-0_29"},{"key":"9396_CR40","doi-asserted-by":"crossref","unstructured":"Sulaman, S.M., Weyns, K., H\u00f6st, M. (2013). A review of research on risk analysis methods for IT systems. In Proceedings of the 17th International Conference on Evaluation and Assessment in Software Engineering (pp. 86\u201396): ACM.","DOI":"10.1145\/2460999.2461013"},{"key":"9396_CR41","unstructured":"Sulaman, S.M., Abbas, T., Wnuk, K., H\u00f6st, M. (2014). Hazard analysis of collision avoidance system using STPA. In International Conference on Information Systems for Crisis Response and Management (ISCRAM) (pp. 424\u2013428)."},{"key":"9396_CR42","unstructured":"Thomas, J., & Leveson, N.G. (2011). Performing hazard analysis on complex, software and human-intensive systems. In Proceedings of the 29th ISSC Conference about System Safety, Las Vegas, Nevada."},{"key":"9396_CR43","volume-title":"Case study research: design and methods","author":"RK Yin","year":"2003","unstructured":"Yin, R.K. (2003). Case study research: design and methods. Thousand Oaks: SAGE Publications Ltd."},{"key":"9396_CR44","doi-asserted-by":"crossref","unstructured":"Yu, S., Yang, Q., Liu, J., Pan, M. (2011). A comparison of FMEA, AFMEA and FTA. In Proceedings of the 9th International Conference on Reliability, Maintainability and Safety (ICRMS\u201911) (pp. 954\u2013960).","DOI":"10.1109\/ICRMS.2011.5979423"}],"container-title":["Software Quality Journal"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-017-9396-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11219-017-9396-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-017-9396-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,29]],"date-time":"2024-06-29T10:30:09Z","timestamp":1719657009000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11219-017-9396-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,12,4]]},"references-count":44,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,3]]}},"alternative-id":["9396"],"URL":"https:\/\/doi.org\/10.1007\/s11219-017-9396-0","relation":{},"ISSN":["0963-9314","1573-1367"],"issn-type":[{"value":"0963-9314","type":"print"},{"value":"1573-1367","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,12,4]]},"assertion":[{"value":"4 December 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}