1. Ainsworth , M . 2008 . Prototyping versus formal development . In Redmill , F . & Anderson , T . Improvements in Systems Safety .Proccedings of the Sixteenth Safety-critical Symposium, Bristol , UK , 5–7 February 2008 . Springer 195 207 .
2. Archinoff , G.H. , Hohendorf , R.J. , Wassyng , A. , Quigley , B Borsch , M.R . 1990 . Verification of the shutdown system software at the Darlington nuclear generating station . International Conference on Control and Instrumentation in Nuclear Installations, Glasgow, UK Glasgow , The Institution of Nuclear Engineers .
3. Bartussek , W Parnas , D.L . 1978 . Using assertions about traces to write abstract specifications for software modules . In: Proceedings of the 2nd Conference of European Cooperation in Informatics, Venice, 1978. Lecture Notes in Computer Science 65 : 211 236 . Berlin , Springer ; reprinted in Gehani, N. & McGettrick, A.D. (Eds), Software Specification Techniques 1985: 111–130.
4. Bharadwaj , R Heitmeyer , C.L . 2000 . Developing high assurance avionics systems with the SCR requirements method . Proceedings of the 19th Digital Avionics Systems Conference, Philadelphia 1 8 .
5. Darimont , R. , Delor , E. , Massonet , P Van Lamsweerde , A . 1977 . GRAIL/KAOS: An environment for goal-driven requirements engineering .Proceedings of the 19th International Conference on Software Engineering612 613 .