<?xml version="1.0" encoding="UTF-8"?><toc><section id="sec_foreword"><title>Foreword</title></section><section id="sec_intro"><title>Introduction</title></section><section id="sec_1"><label>1</label><title>Scope</title></section><section id="sec_2"><label>2</label><title>Normative references</title></section><section id="sec_3"><label>3</label><title>Terms and definitions</title></section><section id="sec_4"><label>4</label><title>Requirements for compliance</title><section id="sec_4.1"><label>4.1</label><title>Purpose</title></section><section id="sec_4.2"><label>4.2</label><title>General requirements</title></section><section id="sec_4.3"><label>4.3</label><title>Interpretations of tables</title></section><section id="sec_4.4"><label>4.4</label><title>ASIL-dependent requirements and recommendations</title></section><section id="sec_4.5"><label>4.5</label><title>Adaptation for motorcycles</title></section><section id="sec_4.6"><label>4.6</label><title>Adaptation for trucks, buses, trailers and semi-trailers</title></section></section><section id="sec_5"><label>5</label><title>General topics for the product development at the software level</title><section id="sec_5.1"><label>5.1</label><title>Objectives</title></section><section id="sec_5.2"><label>5.2</label><title>General</title></section><section id="sec_5.3"><label>5.3</label><title>Inputs to this clause</title><section id="sec_5.3.1"><label>5.3.1</label><title>Prerequisites</title></section><section id="sec_5.3.2"><label>5.3.2</label><title>Further supporting information</title></section></section><section id="sec_5.4"><label>5.4</label><title>Requirements and recommendations</title></section><section id="sec_5.5"><label>5.5</label><title>Work products</title></section></section><section id="sec_6"><label>6</label><title>Specification of software safety requirements</title><section id="sec_6.1"><label>6.1</label><title>Objectives</title></section><section id="sec_6.2"><label>6.2</label><title>General</title></section><section id="sec_6.3"><label>6.3</label><title>Inputs to this clause</title><section id="sec_6.3.1"><label>6.3.1</label><title>Prerequisites</title></section><section id="sec_6.3.2"><label>6.3.2</label><title>Further supporting information</title></section></section><section id="sec_6.4"><label>6.4</label><title>Requirements and recommendations</title></section><section id="sec_6.5"><label>6.5</label><title>Work products</title></section></section><section id="sec_7"><label>7</label><title>Software architectural design</title><section id="sec_7.1"><label>7.1</label><title>Objectives</title></section><section id="sec_7.2"><label>7.2</label><title>General</title></section><section id="sec_7.3"><label>7.3</label><title>Inputs to this clause</title><section id="sec_7.3.1"><label>7.3.1</label><title>Prerequisites</title></section><section id="sec_7.3.2"><label>7.3.2</label><title>Further supporting information</title></section></section><section id="sec_7.4"><label>7.4</label><title>Requirements and recommendations</title></section><section id="sec_7.5"><label>7.5</label><title>Work products</title></section></section><section id="sec_8"><label>8</label><title>Software unit design and implementation</title><section id="sec_8.1"><label>8.1</label><title>Objectives</title></section><section id="sec_8.2"><label>8.2</label><title>General</title></section><section id="sec_8.3"><label>8.3</label><title>Inputs to this clause</title><section id="sec_8.3.1"><label>8.3.1</label><title>Prerequisites</title></section><section id="sec_8.3.2"><label>8.3.2</label><title>Further supporting information</title></section></section><section id="sec_8.4"><label>8.4</label><title>Requirements and recommendations</title></section><section id="sec_8.5"><label>8.5</label><title>Work products</title></section></section><section id="sec_9"><label>9</label><title>Software unit verification</title><section id="sec_9.1"><label>9.1</label><title>Objectives</title></section><section id="sec_9.2"><label>9.2</label><title>General</title></section><section id="sec_9.3"><label>9.3</label><title>Inputs to this clause</title><section id="sec_9.3.1"><label>9.3.1</label><title>Prerequisites</title></section><section id="sec_9.3.2"><label>9.3.2</label><title>Further supporting information</title></section></section><section id="sec_9.4"><label>9.4</label><title>Requirements and recommendations</title></section><section id="sec_9.5"><label>9.5</label><title>Work products</title></section></section><section id="sec_10"><label>10</label><title>Software integration and verification</title><section id="sec_10.1"><label>10.1</label><title>Objectives</title></section><section id="sec_10.2"><label>10.2</label><title>General</title></section><section id="sec_10.3"><label>10.3</label><title>Inputs to this clause</title><section id="sec_10.3.1"><label>10.3.1</label><title>Prerequisites</title></section><section id="sec_10.3.2"><label>10.3.2</label><title>Further supporting information</title></section></section><section id="sec_10.4"><label>10.4</label><title>Requirements and recommendations</title></section><section id="sec_10.5"><label>10.5</label><title>Work products</title></section></section><section id="sec_11"><label>11</label><title>Testing of the embedded software</title><section id="sec_11.1"><label>11.1</label><title>Objective</title></section><section id="sec_11.2"><label>11.2</label><title>General</title></section><section id="sec_11.3"><label>11.3</label><title>Inputs to this clause</title><section id="sec_11.3.1"><label>11.3.1</label><title>Prerequisites</title></section><section id="sec_11.3.2"><label>11.3.2</label><title>Further supporting information</title></section></section><section id="sec_11.4"><label>11.4</label><title>Requirements and recommendations</title></section><section id="sec_11.5"><label>11.5</label><title>Work products</title></section></section><section id="sec_A"><label>Annex A</label><title>Overview of and workflow of management of product development at the software level (informative)</title></section><section id="sec_B"><label>Annex B</label><title>Model-based development approaches (informative)</title><section id="sec_B.1"><label>B.1</label><title>Objectives</title></section><section id="sec_B.2"><label>B.2</label><title>General</title><section id="sec_B.2.1"><label>B.2.1</label><title>Introduction</title></section><section id="sec_B.2.2"><label>B.2.2</label><title>General suitability aspects</title></section><section id="sec_B.2.3"><label>B.2.3</label><title>Potential impact of MBD on the software lifecycle</title></section></section><section id="sec_B.3"><label>B.3</label><title>Specific considerations for the example software development use cases</title><section id="sec_B.3.1"><label>B.3.1</label><title>Specification of software safety requirements (Clause 6 and ISO 26262‑8:2018, Clause 6)</title></section><section id="sec_B.3.2"><label>B.3.2</label><title>Development of the software architectural design (Clause 7)</title></section><section id="sec_B.3.3"><label>B.3.3</label><title>Design and implementation of software units (Clauses 8 and 9)</title></section><section id="sec_B.3.4"><label>B.3.4</label><title>Design, implementation and integration of software components, including automated code generation from software component models (Clauses 8, 9 and 10)</title></section><section id="sec_B.3.5"><label>B.3.5</label><title>Verification (static and/or dynamic) (Clauses 9, 10 and 11)</title></section></section></section><section id="sec_C"><label>Annex C</label><title>Software configuration (normative)</title><section id="sec_C.1"><label>C.1</label><title>Objectives</title></section><section id="sec_C.2"><label>C.2</label><title>General</title></section><section id="sec_C.3"><label>C.3</label><title>Inputs to this clause</title><section id="sec_C.3.1"><label>C.3.1</label><title>Prerequisites</title></section><section id="sec_C.3.2"><label>C.3.2</label><title>Further supporting information</title></section></section><section id="sec_C.4"><label>C.4</label><title>Requirements and recommendations</title></section><section id="sec_C.5"><label>C.5</label><title>Work products</title></section></section><section id="sec_D"><label>Annex D</label><title>Freedom from interference between software elements (informative)</title><section id="sec_D.1"><label>D.1</label><title>Objectives</title></section><section id="sec_D.2"><label>D.2</label><title>General</title><section id="sec_D.2.1"><label>D.2.1</label><title>Achievement of freedom from interference</title></section><section id="sec_D.2.2"><label>D.2.2</label><title>Timing and execution</title></section><section id="sec_D.2.3"><label>D.2.3</label><title>Memory</title></section><section id="sec_D.2.4"><label>D.2.4</label><title>Exchange of information</title></section></section></section><section id="sec_E"><label>Annex E</label><title>Application of safety analyses and analyses of dependent failures at the software architectural level (informative)</title><section id="sec_E.1"><label>E.1</label><title>Objectives</title></section><section id="sec_E.2"><label>E.2</label><title>General</title><section id="sec_E.2.1"><label>E.2.1</label><title>Scope and purpose of the analyses</title></section><section id="sec_E.2.2"><label>E.2.2</label><title>Relationship between safety analyses and dependent failure analyses at the system, hardware and software level</title></section><section id="sec_E.2.3"><label>E.2.3</label><title>Safety analyses in a distributed software development (including SEooC development of software elements)</title></section></section><section id="sec_E.3"><label>E.3</label><title>Topics for performing analyses</title><section id="sec_E.3.1"><label>E.3.1</label><title>Determination of the goals for the analyses</title></section><section id="sec_E.3.2"><label>E.3.2</label><title>Determination of the scope and boundaries regarding the specific architectural design to be analysed</title></section><section id="sec_E.3.3"><label>E.3.3</label><title>Determination of the method applied to conduct the analyses</title></section><section id="sec_E.3.4"><label>E.3.4</label><title>Aspects to support the meaningfulness, objectivity and rigour of the analyses</title><section id="sec_E.3.4.1"><label>E.3.4.1</label><title>Coupling factor classes for DFA in accordance with ISO 26262‑9:2018</title></section><section id="sec_E.3.4.2"><label>E.3.4.2</label><title>Use content of Annex D</title></section><section id="sec_E.3.4.3"><label>E.3.4.3</label><title>Analyses supported by using guide words</title></section></section></section><section id="sec_E.4"><label>E.4</label><title>Mitigation strategy for weaknesses identified during safety and dependent failure analyses</title></section></section><section id="sec_bibl"><title>Bibliography</title></section></toc>