Schedule a Software Walkthrough
NATO AOP-52 — Guidance on SW Safety Design & Assessment of Munition-Related Computing Systems Edition B, Nov 2016 (orig. 2009) Section 4 — Generic SW Safety Design Reqs Public — STANAG 4452
4
NATO AOP-52 · Section 4

Generic Software Safety Design Requirements

NATO's own catalog of baseline software safety design requirements — and the direct ancestor of JSSSEH Appendix E. The two documents share most of the same requirement statements, organized around the same topic areas, under different section numbers and slightly different wording.

Requs AI Edge Case and Requs AI Software FMEA consider these design criteria.

1Lineage

The older of the two documents

NATO AOP-52 (2009, 205 pages) predates the JSSSEH (August 2010, 334 pages). Independent analysis comparing the two, published in the Journal of System Safety, found that JSSSEH Appendix E heavily borrows from — and is based on — AOP-52 Section 4, with many statements carried over essentially unchanged aside from grammatical corrections.

Where JSSSEH diverges, it's usually to clarify and expand the original NATO AOP-52 wording, not to change its intent.

2Wording

Same requirements, shifted vocabulary

Nearly every NATO AOP-52 requirement carries into JSSSEH, but with two consistent word swaps applied along the way:

NATO AOP-52

Requirements are written with "must" and describe the broader category of "safety-related" functions.

JSSSEH

The same statements are restated with "shall", and narrowed to "safety-critical" functions specifically.

Per the Ozarin (2020) comparison: nearly all "must"/"shall" requirements carry over between the two documents; a handful of "should" statements do not.

3Delta

What Section 4 has that Appendix E doesn't

The one notable structural difference: NATO AOP-52 §4.4, "Safety-Related Events and Safety-Related Functions," isn't a requirements list at all — it's roughly a 600-word essay on how to identify safety-related hazards. JSSSEH omits it entirely from Appendix E, keeping only the checkable requirement statements.

4Topics

The same generic requirement areas

Stripped of numbering, Section 4 and Appendix E cover the same ground — the requirement areas below appear in both documents, under AOP-52's own section numbers on one side and JSSSEH's E.1–E.13 on the other:

Safety-critical functions
Design & dev process
System design & safe states
Power-up initialization
Computing environment
Self-check design
Function protection
Interface design
Human interface
Timing & interrupts
Coding requirements
Software maintenance
Analysis & testing

Topic areas common to both documents' generic requirements sections — see JSSSEH Appendix E for the full worked breakdown of each area.

Requs AI Edge Case and Requs AI Software FMEA include these design criteria.

5Xref

Confirmed section-to-section cross-references

Most of AOP-52's own subsection numbering isn't publicly indexed outside the paywalled document, but a handful of exact correspondences have been published in the independent comparison referenced above:

AOP-52 JSSSEH Ozarin, 2020
4.2.2
Failure in the Computing Environment
→ JSSSEH E.5.1.1, same title
4.2.3
CPU Selection
→ JSSSEH E.5.2, same title
4.4
Safety-Related Events and Safety-Related Functions
→ no JSSSEH equivalent — essay, not requirements
4.7.2
Computer/Human Interface Issues
→ JSSSEH E.9.1.1, "CHI Issues"
4.12.1
General Testing Guidelines
→ JSSSEH E.13.1, same title
4.12.2
Trajectory Testing for Embedded Systems
→ JSSSEH E.13.2, same title