Measures addressing SOTIF-related risks are specified and applied, and the input information to the specification and design is updated. They are considered when a hazardous scenario needs further analysis and the response to a triggering condition is unacceptable, and the system is refined iteratively through measures, updating the specification and design, and re-evaluating risk; further iterations occur if V&V or the release evaluation shows unacceptable residual risk. A suitable mix of avoidance measures (inherently safe design, aiming for no harm or full controllability) and mitigation measures (reducing risk where avoidance is hard) is chosen, checking for adverse effects on other elements and interactions with other hazardous scenarios, and monitoring in operation confirms the measures stay effective.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.