Skip to content

[c-RCP-13] HARA.md ASIL ratings systematically over-rated vs ISO 26262-3:2018 Table 4; determination note miscounts its own hazard list #125

Description

@SoundMatt

Summary

The HARA's hazard table systematically over-rates ASIL for essentially every hazard versus a correct application of ISO 26262-3:2018's severity/exposure/controllability determination table, and the accompanying determination note miscounts its own hazard list.

Evidence (current HEAD)

I independently re-derived the ASIL for every hazard in HARA.md's table directly from the official ISO 26262-3:2018 Table 4 lookup (S × E × C, not a sum-based approximation), and compared against the recorded values:

Hazard S/E/C Correct ASIL (Table 4) Recorded in HARA.md
H-001 S3/E4/C2 C D
H-002 S2/E3/C2 A B
H-003 S2/E4/C2 B C
H-004 S2/E3/C2 A B
H-005 S3/E3/C2 B D
H-006 S2/E3/C2 A B
H-007 S3/E2/C2 A C
H-008 S3/E3/C2 B D
H-009 S2/E3/C2 A B
H-010 S2/E2/C3 A B
H-011 S2/E2/C2 QM A

Every one of the 11 hazards is over-rated by at least one band, several by two, and H-011 is rated ASIL-A despite the correct determination being QM (no ASIL at all).

Separately, HARA.md's "ASIL Determination Note" states "Four hazards resolve to ASIL-C or ASIL-D" but then names five (H-001, H-003, H-005, H-007, H-008) — an internal miscount independent of the rating question above.

Recommendation

Recompute every asil field in HARA.md/.fusa-hara.json directly from ISO 26262-3:2018 Table 4 (or correct the underlying S/E/C classifications if the intent was genuinely higher risk than the recorded classes reflect), regenerate the document and the determination note so the hazard count is consistent, and check whether the cfusa hara asil tool this project relies on is itself implementing Table 4 correctly, since its output doesn't currently match the table.

Filed from the 2026-07-29 ecosystem audit register; independently re-verified against current HEAD before filing.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions