Viewing a single comment thread. View all comments

skucera t1_j1uovax wrote

You perform a Failure Mode and Effects Analysis (FMEA). Once you know the failure modes that you can’t design out of the system, you design mitigation for the rest. You then add redundancy for those modes you can’t mitigate. Finally, you take the probability of an individual critical failure happening and calculate the duration before there is X% chance that a critical failure has occurred, and that’s your planned mission length. If it’s too short, you put in more mitigation or redundancy.

2