initial architecture including dataflow for and between components thereof, said components comprising for example sensors or actuators, characterized in that the method includes: d) refining on said functional specification the fault tolerance requirements associated with the severity of each said undesirable event and issuing refined fault tolerance requirements of said functional specification