The combination of faults is analysed where a single fault could remain undetected long enough for a second to occur: the analysis identifies the fault combinations that would be hazardous, shows that the detection and negation times keep their probability within the TFFR, treats common-cause failures explicitly and, where m-out-of-n redundancy is used, demonstrates that the required number of items remain independent.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.