initial architecture including dataflow for and between components thereof, said components comprising for example sensors or actuators, the procedure being characterized in that it includes; d) refining on said functional specification the fault tolerance requirements associated with the severity of each said undesirable event and issuing refined fault tolerance requirements of said functional s