Systematic Techniques for Inspecting Critical Software
David Lorge Parnas · Technology of Object-Oriented Languages and Systems · 1999
Software is devilishly hard to inspect. Serious errors can hide for years. Consequently, many are hesitant to employ software in safety-critical applications and all companies are finding the cost of correcting and improving software to be an increasing burden.This talk describes a procedure for inspecting software that consistently finds subtle errors in software that was believed to be correct. The procedure is based on four key ideas: All software reviewers actively use the code Reviewers exploit the hierarchical structure of the code rather than proceeding sequentially through the code Reviewers focus on small sections of code, producing precise summaries that are used when inspecting other such sections Reviewers proceed systematically so that no case, and no section of the program, gets overlookedDuring the procedure, the inspectors produce and review precise documentation. They are able to check for complete coverage; tabular notation allows the work to proceed in small systematic steps. The procedure was originally developed and used to inspect safety-critical software in a nuclear power plant, and then improved based on that experience.