The AFHA and SFHA identify failure conditions early; the PASA and PSSA then assess the functions, their failure conditions and classes, and the proposed architectures, to assign levels so the right validation and verification processes are applied. A level does not imply any random hardware failure probability, so probability analysis is still done where needed. Interactions of system functions forming an aircraft function are assessed at the aircraft function's FDAL, and interactions of items forming a system function at the higher of the aircraft and system FDALs. Assignment begins by giving each top-level function the FDAL that matches the worst of its top-level failure conditions, per Table 2: level A for a catastrophic condition, B for hazardous, C for major, D for minor and E where there is no safety effect. Without architectural credit, that level applies to every supporting function and item (5.2.3.1); where a single FDAL A process is the mitigation for a catastrophic condition, the applicant may need to show it has enough independent validation and verification, techniques and completion criteria to remove such errors within the process. ARP4761A/ED-135 gives the detailed considerations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.