PREFACE |
|
xvii | |
ACKNOWLEDGMENTS |
|
xix | |
|
|
1 | (12) |
|
|
1 | (1) |
|
1.2 System Safety Background |
|
|
2 | (1) |
|
1.3 System Safety Characterization |
|
|
3 | (1) |
|
1.4 System Safety Process |
|
|
4 | (1) |
|
|
5 | (7) |
|
1.5.1 General System Model |
|
|
5 | (2) |
|
|
7 | (1) |
|
|
8 | (1) |
|
|
9 | (1) |
|
|
10 | (2) |
|
|
12 | (1) |
|
2. Hazards, Mishap, and Risk |
|
|
13 | (18) |
|
|
13 | (1) |
|
2.2 Hazard-Related Definitions |
|
|
14 | (1) |
|
|
15 | (4) |
|
|
19 | (2) |
|
2.5 Hazard Causal-Factors |
|
|
21 | (2) |
|
2.6 Hazard-Mishap Probability |
|
|
23 | (1) |
|
|
23 | (4) |
|
|
27 | (1) |
|
|
27 | (4) |
|
3. Hazard Analysis Types and Techniques |
|
|
31 | (24) |
|
|
31 | (3) |
|
3.2 Description of Hazard Analysis Types |
|
|
34 | (10) |
|
3.2.1 Conceptual Design Hazard Analysis Type (CD-HAT) |
|
|
34 | (1) |
|
3.2.2 Preliminary Design Hazard Analysis Type (PD-HAT) |
|
|
35 | (2) |
|
3.2.3 Detailed Design Hazard Analysis Type (DD-HAT) |
|
|
37 | (1) |
|
3.2.4 System Design Hazard Analysis Type (SD-HAT) |
|
|
38 | (2) |
|
3.2.5 Operations Design Hazard Analysis Type (OD-HAT) |
|
|
40 | (1) |
|
3.2.6 Human Design Hazard Analysis Type (HD-HAT) |
|
|
41 | (1) |
|
3.2.7 Requirements Design Hazard Analysis Type (RD-HAT) |
|
|
42 | (2) |
|
3.3 Timing of Hazard Analysis Types |
|
|
44 | (1) |
|
3.4 Interrelationship of Hazard Analysis Types |
|
|
44 | (1) |
|
3.5 Hazard Analysis Techniques |
|
|
45 | (3) |
|
3.5.1 Technique Attributes |
|
|
45 | (1) |
|
3.5.2 Primary Hazard Analysis Techniques |
|
|
46 | (2) |
|
3.6 Inductive and Deductive Techniques |
|
|
48 | (3) |
|
3.7 Qualitative and Quantitative Techniques |
|
|
51 | (2) |
|
|
53 | (2) |
|
4. Preliminary Hazard List |
|
|
55 | (18) |
|
|
55 | (1) |
|
|
55 | (1) |
|
|
56 | (1) |
|
|
56 | (1) |
|
|
57 | (3) |
|
|
60 | (2) |
|
|
62 | (2) |
|
|
64 | (1) |
|
4.9 Example: Ace Missile System |
|
|
65 | (5) |
|
4.10 Advantages and Disadvantages |
|
|
70 | (1) |
|
4.11 Common Mistakes to Avoid |
|
|
71 | (1) |
|
|
71 | (2) |
|
5. Preliminary Hazard Analysis |
|
|
73 | (22) |
|
|
73 | (1) |
|
|
73 | (1) |
|
|
74 | (1) |
|
|
75 | (1) |
|
|
76 | (2) |
|
|
78 | (3) |
|
|
81 | (1) |
|
5.8 Example: Ace Missile System |
|
|
82 | (3) |
|
5.9 Advantages and Disadvantages |
|
|
85 | (1) |
|
5.10 Common Mistakes to Avoid |
|
|
85 | (8) |
|
|
93 | (2) |
|
6. Subsystem Hazard Analysis |
|
|
95 | (20) |
|
|
95 | (1) |
|
|
95 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
97 | (1) |
|
|
98 | (4) |
|
|
102 | (1) |
|
6.8 Example: Ace Missile System |
|
|
103 | (4) |
|
6.9 Advantages and Disadvantages |
|
|
107 | (1) |
|
6.10 Common Mistakes to Avoid |
|
|
107 | (6) |
|
|
113 | (2) |
|
7. System Hazard Analysis |
|
|
115 | (16) |
|
|
115 | (1) |
|
|
116 | (1) |
|
|
117 | (1) |
|
|
117 | (1) |
|
|
118 | (2) |
|
|
120 | (2) |
|
|
122 | (1) |
|
|
123 | (5) |
|
7.9 Advantages and Disadvantages |
|
|
128 | (1) |
|
7.10 Common Mistakes to Avoid |
|
|
129 | (1) |
|
|
129 | (2) |
|
8. Operating and Support Hazard Analysis |
|
|
131 | (24) |
|
|
131 | (1) |
|
|
131 | (2) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
134 | (1) |
|
|
135 | (3) |
|
|
138 | (2) |
|
|
140 | (1) |
|
|
140 | (2) |
|
|
142 | (1) |
|
|
143 | (9) |
|
|
143 | (1) |
|
|
143 | (9) |
|
8.12 Advantages and Disadvantages |
|
|
152 | (1) |
|
8.13 Common Mistakes to Avoid |
|
|
152 | (1) |
|
|
152 | (3) |
|
9. Health Hazard Assessment |
|
|
155 | (14) |
|
|
155 | (1) |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
|
157 | (3) |
|
|
160 | (2) |
|
|
162 | (2) |
|
|
164 | (1) |
|
9.9 Advantages and Disadvantages |
|
|
164 | (4) |
|
9.10 Common Mistakes to Avoid |
|
|
168 | (1) |
|
|
168 | (1) |
10. Safety Requirements/Criteria Analysis |
|
169 | (14) |
|
|
169 | (1) |
|
|
169 | (1) |
|
|
170 | (1) |
|
|
170 | (1) |
|
|
171 | (1) |
|
|
172 | (3) |
|
|
175 | (1) |
|
10.8 Advantages and Disadvantages |
|
|
175 | (5) |
|
10.9 Common Mistakes to Avoid |
|
|
180 | (1) |
|
|
180 | (3) |
11. Fault Tree Analysis |
|
183 | (40) |
|
|
183 | (2) |
|
|
185 | (1) |
|
|
186 | (1) |
|
|
187 | (1) |
|
|
188 | (9) |
|
|
188 | (3) |
|
|
191 | (2) |
|
11.5.3 Construction-Basics |
|
|
193 | (2) |
|
11.5.4 Construction-Advanced |
|
|
195 | (1) |
|
11.5.5 Construction Rules |
|
|
196 | (1) |
|
11.6 Functional Block Diagrams |
|
|
197 | (1) |
|
|
198 | (1) |
|
|
199 | (1) |
|
|
199 | (2) |
|
|
201 | (1) |
|
|
202 | (2) |
|
11.12 Importance Measures |
|
|
204 | (2) |
|
|
206 | (1) |
|
|
207 | (3) |
|
|
210 | (5) |
|
11.16 Phase- and Time-Dependent FTA |
|
|
215 | (3) |
|
|
218 | (1) |
|
11.18 Advantages and Disadvantages |
|
|
219 | (1) |
|
11.19 Common Mistakes to Avoid |
|
|
220 | (1) |
|
|
220 | (3) |
12. Event Tree Analysis |
|
223 | (12) |
|
|
223 | (1) |
|
|
223 | (1) |
|
|
224 | (1) |
|
|
225 | (1) |
|
|
225 | (3) |
|
|
228 | (2) |
|
|
230 | (1) |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
231 | (2) |
|
12.12 Advantages and Disadvantages |
|
|
233 | (1) |
|
12.13 Common Mistakes to Avoid |
|
|
233 | (1) |
|
|
233 | (2) |
13. Failure Mode and Effects Analysis |
|
235 | (26) |
|
|
235 | (1) |
|
|
236 | (1) |
|
|
237 | (1) |
|
|
237 | (1) |
|
|
238 | (6) |
|
13.5.1 Structural and Functional Models |
|
|
241 | (1) |
|
13.5.2 Product and Process FMEA |
|
|
242 | (1) |
|
13.5.3 Functional Failure Modes |
|
|
242 | (1) |
|
13.5.4 Hardware Failure Modes |
|
|
242 | (1) |
|
13.5.5 Software Failure Modes |
|
|
243 | (1) |
|
13.5.6 Quantitative Data Sources |
|
|
244 | (1) |
|
|
244 | (3) |
|
|
247 | (4) |
|
13.8 Example 1: Hardware Product FMEA |
|
|
251 | (1) |
|
13.9 Example 2: Functional FMEA |
|
|
252 | (1) |
|
|
252 | (3) |
|
13.11 Advantages and Disadvantages |
|
|
255 | (3) |
|
13.12 Common Mistakes to Avoid |
|
|
258 | (1) |
|
|
258 | (3) |
14. Fault Hazard Analysis |
|
261 | (10) |
|
|
261 | (1) |
|
|
261 | (1) |
|
|
262 | (1) |
|
|
262 | (1) |
|
|
263 | (2) |
|
|
265 | (1) |
|
|
266 | (1) |
|
14.8 Advantages and Disadvantages |
|
|
267 | (2) |
|
14.9 Common Mistakes to Avoid |
|
|
269 | (1) |
|
|
269 | (2) |
15. Functional Hazard Analysis |
|
271 | (20) |
|
|
271 | (1) |
|
|
271 | (1) |
|
|
272 | (1) |
|
|
272 | (1) |
|
|
273 | (2) |
|
|
275 | (2) |
|
15.7 Example 1: Aircraft Flight Functions |
|
|
277 | (1) |
|
15.8 Example 2: Aircraft Landing Gear Software |
|
|
278 | (1) |
|
15.9 Example 3: Ace Missile System |
|
|
278 | (1) |
|
15.10 Advantages and Disadvantages |
|
|
278 | (3) |
|
15.11 Common Mistakes to Avoid |
|
|
281 | (3) |
|
|
284 | (7) |
16. Sneak Circuit Analysis |
|
291 | (16) |
|
|
291 | (1) |
|
|
292 | (1) |
|
|
293 | (1) |
|
|
293 | (1) |
|
|
294 | (1) |
|
|
295 | (5) |
|
16.6.1 Step 1: Acquire Data |
|
|
296 | (1) |
|
|
296 | (1) |
|
16.6.3 Step 3: Process Data |
|
|
297 | (1) |
|
16.6.4 Step 4: Produce Network Trees |
|
|
297 | (1) |
|
16.6.5 Step 5: Identify Topographs |
|
|
298 | (1) |
|
16.6.6 Step 6: Perform Analysis |
|
|
298 | (1) |
|
16.6.7 Step 7: Generate Report |
|
|
299 | (1) |
|
16.7 Example 1: Sneak Path |
|
|
300 | (1) |
|
16.8 Example 2: Sneak Label |
|
|
301 | (1) |
|
16.9 Example 3: Sneak Indicator |
|
|
301 | (1) |
|
16.10 Example Sneak Clues |
|
|
301 | (2) |
|
16.11 Software Sneak Circuit Analysis |
|
|
303 | (1) |
|
16.12 Advantages and Disadvantages |
|
|
304 | (1) |
|
16.13 Common Mistakes to Avoid |
|
|
305 | (1) |
|
|
305 | (2) |
17. Petri Net Analysis (PNA) |
|
307 | (10) |
|
|
307 | (1) |
|
|
307 | (1) |
|
|
308 | (1) |
|
|
308 | (1) |
|
|
309 | (1) |
|
|
309 | (4) |
|
|
313 | (2) |
|
17.8 Advantages and Disadvantages |
|
|
315 | (1) |
|
17.9 Common Mistakes to Avoid |
|
|
315 | (1) |
|
|
315 | (2) |
18. Markov Analysis |
|
317 | (18) |
|
|
317 | (1) |
|
|
318 | (1) |
|
|
318 | (1) |
|
|
319 | (1) |
|
|
320 | (1) |
|
|
320 | (5) |
|
18.6.1 State Transition Diagram Construction |
|
|
320 | (3) |
|
18.6.2 State Equation Construction |
|
|
323 | (2) |
|
|
325 | (3) |
|
|
325 | (1) |
|
18.7.2 Markov Model of Two-Component Series System with No Repair |
|
|
325 | (1) |
|
18.7.3 Markov Model of Two-Component Parallel System with No Repair |
|
|
326 | (1) |
|
18.7.4 Markov Model of Two-Component Parallel System with-Component Repair |
|
|
326 | (1) |
|
18.7.5 Markov Model of Two-Component Parallel System with ComponentSystem Repair |
|
|
327 | (1) |
|
18.7.6 Markov Model of Two-Component Parallel System with Sequencing |
|
|
328 | (1) |
|
18.8 Markov Analysis and FTA Comparisons |
|
|
328 | (3) |
|
18.9 Advantages and Disadvantages |
|
|
331 | (1) |
|
18.10 Common Mistakes to Avoid |
|
|
332 | (1) |
|
|
332 | (3) |
19. Barrier Analysis |
|
335 | (18) |
|
|
335 | (1) |
|
|
335 | (1) |
|
|
336 | (1) |
|
|
337 | (1) |
|
|
337 | (1) |
|
|
338 | (6) |
|
19.6.1 Example Checklist of Energy Sources |
|
|
338 | (1) |
|
|
338 | (6) |
|
|
344 | (3) |
|
|
347 | (1) |
|
19.9 Advantages and Disadvantages |
|
|
347 | (2) |
|
19.10 Common Mistakes to Avoid |
|
|
349 | (1) |
|
|
350 | (3) |
20. Bent Pin Analysis |
|
353 | (12) |
|
|
353 | (1) |
|
|
353 | (1) |
|
|
354 | (1) |
|
|
354 | (2) |
|
|
356 | (1) |
|
|
356 | (2) |
|
|
358 | (2) |
|
20.8 Advantages and Disadvantages |
|
|
360 | (4) |
|
20.9 Common Mistakes to Avoid |
|
|
364 | (1) |
|
|
364 | (1) |
21. Hazard and Operability Analysis |
|
365 | (18) |
|
|
365 | (1) |
|
|
366 | (1) |
|
|
366 | (1) |
|
|
367 | (1) |
|
|
368 | (5) |
|
21.5.1 Design Representations |
|
|
370 | (1) |
|
|
371 | (1) |
|
|
372 | (1) |
|
21.5.4 Deviation from Design Intent |
|
|
372 | (1) |
|
|
373 | (2) |
|
|
375 | (1) |
|
|
376 | (1) |
|
21.9 Advantages and Disadvantages |
|
|
376 | (3) |
|
21.10 Common Mistakes to Avoid |
|
|
379 | (1) |
|
|
379 | (4) |
22. Cause-Consequence Analysis |
|
383 | (14) |
|
|
383 | (1) |
|
|
383 | (1) |
|
|
384 | (1) |
|
|
385 | (1) |
|
|
385 | (1) |
|
|
386 | (2) |
|
|
388 | (1) |
|
|
388 | (1) |
|
22.9 Example 1: Three-Component Parallel System |
|
|
389 | (1) |
|
22.10 Example 2: Gas Pipeline System |
|
|
389 | (5) |
|
22.10.1 Reducing Repeated Events |
|
|
390 | (4) |
|
22.11 Advantages and Disadvantages |
|
|
394 | (1) |
|
22.12 Common Mistakes to Avoid |
|
|
395 | (1) |
|
|
395 | (2) |
23. Common Cause Failure Analysis |
|
397 | (26) |
|
|
397 | (1) |
|
|
398 | (1) |
|
|
399 | (1) |
|
|
399 | (2) |
|
|
401 | (3) |
|
|
404 | (9) |
|
|
413 | (1) |
|
|
414 | (5) |
|
|
419 | (1) |
|
23.10 Advantages and Disadvantages |
|
|
420 | (1) |
|
23.11 Common Mistakes to Avoid |
|
|
420 | (1) |
|
|
420 | (3) |
24. Management Oversight Risk Tree Analysis |
|
423 | (8) |
|
|
423 | (1) |
|
|
423 | (1) |
|
|
424 | (1) |
|
|
424 | (1) |
|
|
425 | (1) |
|
|
425 | (2) |
|
24.7 Advantages and Disadvantages |
|
|
427 | (2) |
|
24.8 Common Mistakes to Avoid |
|
|
429 | (1) |
|
|
430 | (1) |
25. Software Safety Assessment |
|
431 | (20) |
|
|
431 | (1) |
|
|
431 | (1) |
|
|
432 | (1) |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
434 | (2) |
|
|
436 | (1) |
|
|
437 | (11) |
|
25.9 Advantages and Disadvantages |
|
|
448 | (1) |
|
25.10 Common Mistakes to Avoid |
|
|
448 | (1) |
|
|
448 | (3) |
26. Summary |
|
451 | (10) |
|
26.1 Principle 1: Hazards, Mishaps, and Risk are Not Chance Events |
|
|
451 | (1) |
|
26.2 Principle 2: Hazards are Created During Design |
|
|
452 | (1) |
|
26.3 Principle 3: Hazards are Comprised of Three Components |
|
|
453 | (1) |
|
26.4 Principle 4: Hazard and Mishap Risk Management Is the Core Safety Process |
|
|
454 | (1) |
|
26.5 Principle 5: Hazard Analysis Is a Key Element of Hazard and Mishap Risk Management |
|
|
455 | (1) |
|
26.6 Principle 6: Hazard Management Involves Seven Key Hazard Analysis Types |
|
|
455 | (1) |
|
26.7 Principle 7: Hazard Analysis Primarily Encompasses Seven Hazard Analysis Techniques |
|
|
456 | (1) |
|
|
457 | (4) |
Appendix A List of Acronyms |
|
461 | (6) |
Appendix B Glossary |
|
467 | (16) |
Appendix C Hazard Checklists |
|
483 | (14) |
Index |
|
497 | |