29.1.1 A failure analysis, at INS functional level,
should be performed and documented for the INS. The failure analysis
should verify that the INS is designed on “fail-to-safe”
principle and that failure of one part of the integrated system should
not affect the functionality of other parts, except for those functions
directly dependent on the defective part.