Preface |
|
xxi | |
Acknowledgments |
|
xxiii | |
1 System Safety and Hazard Analysis |
|
1 | (9) |
|
|
1 | (1) |
|
1.2 The Need for Hazard Analysis |
|
|
2 | (1) |
|
1.3 System Safety Background |
|
|
3 | (1) |
|
1.4 System Safety Overview |
|
|
4 | (2) |
|
1.5 System Safety Process |
|
|
6 | (1) |
|
1.6 System Safety Standards |
|
|
7 | (1) |
|
1.7 System Safety Principles |
|
|
7 | (1) |
|
|
8 | (1) |
|
|
9 | (1) |
2 Systems |
|
10 | (18) |
|
|
10 | (2) |
|
|
12 | (1) |
|
|
13 | (1) |
|
|
13 | (2) |
|
|
15 | (1) |
|
2.6 System Development Process |
|
|
16 | (1) |
|
|
16 | (2) |
|
|
18 | (1) |
|
2.9 System Development Artifacts |
|
|
19 | (1) |
|
2.10 Systems Complexity and Safety |
|
|
20 | (1) |
|
|
21 | (5) |
|
|
26 | (1) |
|
|
26 | (2) |
3 Hazards, Mishap, and Risk |
|
28 | (17) |
|
|
28 | (1) |
|
3.2 Hazard, Mishap, and Risk Definitions |
|
|
29 | (1) |
|
3.3 Accident (Mishap) Theory |
|
|
30 | (1) |
|
3.4 The Hazard-Mishap Relationship |
|
|
31 | (2) |
|
|
33 | (1) |
|
3.6 The Components of a Hazard |
|
|
33 | (2) |
|
|
35 | (1) |
|
|
35 | (2) |
|
3.9 Hazard Causal Factors |
|
|
37 | (2) |
|
3.10 Hazard-Mishap Probability Example |
|
|
39 | (1) |
|
|
40 | (3) |
|
|
43 | (1) |
|
3.13 Hazard Theory Summary |
|
|
43 | (2) |
4 Hazard Analysis Features |
|
45 | (24) |
|
|
45 | (1) |
|
4.2 Types Versus Technique |
|
|
46 | (2) |
|
4.3 Description of Hazard Analysis Types |
|
|
48 | (9) |
|
4.3.1 Conceptual Design Hazard Analysis Type |
|
|
48 | (1) |
|
4.3.2 Preliminary Design Hazard Analysis Type |
|
|
49 | (2) |
|
4.3.3 Detailed Design Hazard Analysis Type |
|
|
51 | (1) |
|
4.3.4 System Design Hazard Analysis Type |
|
|
52 | (1) |
|
4.3.5 Operations Design Hazard Analysis Type |
|
|
53 | (1) |
|
4.3.6 Human Health Design Hazard Analysis Type (HD-HAT) |
|
|
54 | (1) |
|
4.3.7 Requirements Design Hazard Analysis Type (RD-HAT) |
|
|
55 | (2) |
|
4.4 The Timing of Hazard Analysis Types |
|
|
57 | (1) |
|
4.5 The Interrelationship of Hazard Analysis Types |
|
|
57 | (2) |
|
4.6 Hazard Analysis Techniques |
|
|
59 | (1) |
|
4.7 Hazard Analysis Technique Attributes |
|
|
59 | (1) |
|
4.8 Primary and Secondary Techniques |
|
|
59 | (4) |
|
4.9 Inductive and Deductive Techniques |
|
|
63 | (2) |
|
4.10 Qualitative and Quantitative Techniques |
|
|
65 | (2) |
|
|
67 | (2) |
5 Hazard Recognition and Management |
|
69 | (24) |
|
|
69 | (1) |
|
5.2 Hazard Analysis Tasks |
|
|
69 | (5) |
|
5.2.1 Plan the Hazard Analysis |
|
|
70 | (1) |
|
5.2.2 Understand the System Design |
|
|
71 | (1) |
|
5.2.3 Acquire Hazard Analysis Tools |
|
|
71 | (1) |
|
|
72 | (1) |
|
|
72 | (1) |
|
|
72 | (1) |
|
|
72 | (1) |
|
|
73 | (1) |
|
|
73 | (1) |
|
|
73 | (1) |
|
|
74 | (5) |
|
5.3.1 Hazard Recognition Introduction |
|
|
74 | (1) |
|
5.3.2 Hazard Recognition: System Perspectives |
|
|
74 | (1) |
|
5.3.3 Hazard Recognition: Failure Perspectives |
|
|
75 | (1) |
|
5.3.4 Key Hazard Recognition Factors |
|
|
76 | (3) |
|
5.3.5 Hazard Recognition Basics |
|
|
79 | (1) |
|
5.3.6 Hazard Recognition Sources |
|
|
79 | (1) |
|
5.4 Describing the Identified Hazard |
|
|
79 | (2) |
|
5.5 Hazard Types by General Circumstances |
|
|
81 | (1) |
|
5.6 Hazard Types by Analysis Category |
|
|
82 | (1) |
|
5.7 Modelling Hazard Space |
|
|
83 | (9) |
|
5.7.1 System Mishap Model |
|
|
84 | (3) |
|
5.7.2 System Mishap Model Examples |
|
|
87 | (5) |
|
|
92 | (1) |
6 Functional Hazard Analysis |
|
93 | (16) |
|
|
93 | (1) |
|
|
93 | (1) |
|
|
94 | (1) |
|
|
94 | (1) |
|
|
95 | (1) |
|
|
96 | (3) |
|
6.7 FHA Example 1: Aircraft Flight Functions |
|
|
99 | (1) |
|
6.8 FHA Example 2: Aircraft Landing Gear Software |
|
|
99 | (3) |
|
6.9 FHA Example 3: Ace Missile System |
|
|
102 | (3) |
|
6.10 FHA Advantages and Disadvantages |
|
|
105 | (1) |
|
6.11 Common FHA Mistakes to Avoid |
|
|
105 | (3) |
|
|
108 | (1) |
7 Preliminary Hazard List Analysis |
|
109 | (16) |
|
|
109 | (1) |
|
|
109 | (1) |
|
|
110 | (1) |
|
|
110 | (1) |
|
|
111 | (3) |
|
|
114 | (1) |
|
|
115 | (2) |
|
|
117 | (1) |
|
7.9 PHL Example: Ace Missile System |
|
|
118 | (3) |
|
7.10 PHL Advantages and Disadvantages |
|
|
121 | (1) |
|
7.11 Common PHL Mistakes to Avoid |
|
|
122 | (2) |
|
|
124 | (1) |
8 Preliminary Hazard Analysis |
|
125 | (20) |
|
|
125 | (1) |
|
|
125 | (1) |
|
|
126 | (1) |
|
|
126 | (1) |
|
|
127 | (3) |
|
|
130 | (2) |
|
|
132 | (1) |
|
8.8 PHA Example: Ace Missile System |
|
|
133 | (3) |
|
8.9 PHA Advantages and Disadvantages |
|
|
136 | (1) |
|
8.10 Common PHA Mistakes to Avoid |
|
|
136 | (7) |
|
|
143 | (2) |
9 Subsystem Hazard Analysis |
|
145 | (19) |
|
|
145 | (1) |
|
|
145 | (1) |
|
|
146 | (1) |
|
|
146 | (1) |
|
|
147 | (2) |
|
|
149 | (2) |
|
|
151 | (1) |
|
9.8 SSHA Example: Ace Missile System |
|
|
152 | (4) |
|
9.9 SSHA Advantages and Disadvantages |
|
|
156 | (1) |
|
9.10 Common SSHA Mistakes to Avoid |
|
|
156 | (6) |
|
|
162 | (2) |
10 System Hazard Analysis |
|
164 | (13) |
|
|
164 | (1) |
|
|
165 | (1) |
|
|
166 | (1) |
|
|
166 | (1) |
|
|
167 | (1) |
|
|
167 | (3) |
|
|
170 | (2) |
|
|
172 | (3) |
|
10.9 SHA Advantages and Disadvantages |
|
|
175 | (1) |
|
10.10 Common SHA Mistakes to Avoid |
|
|
175 | (1) |
|
|
176 | (1) |
11 Operating and Support Hazard Analysis |
|
177 | (22) |
|
|
177 | (1) |
|
|
177 | (1) |
|
|
178 | (1) |
|
|
179 | (1) |
|
|
179 | (1) |
|
|
179 | (1) |
|
|
179 | (1) |
|
|
180 | (1) |
|
|
181 | (2) |
|
|
183 | (2) |
|
11.8 O&SHA Hazard Checklists |
|
|
185 | (1) |
|
|
186 | (1) |
|
|
187 | (1) |
|
|
188 | (10) |
|
|
188 | (1) |
|
|
188 | (10) |
|
11.12 O&SHA Advantages and Disadvantages |
|
|
198 | (1) |
|
11.13 Common O&SHA Mistakes to Avoid |
|
|
198 | (1) |
|
|
198 | (1) |
12 Health Hazard Analysis |
|
199 | (13) |
|
|
199 | (1) |
|
|
199 | (1) |
|
|
200 | (1) |
|
|
200 | (1) |
|
|
201 | (3) |
|
|
204 | (2) |
|
12.7 Human Health Hazard Checklist |
|
|
206 | (1) |
|
|
207 | (1) |
|
12.9 HHA Advantages and Disadvantages |
|
|
207 | (1) |
|
12.10 Common HHA Mistakes to Avoid |
|
|
207 | (4) |
|
|
211 | (1) |
13 Requirements Hazard Analysis |
|
212 | (12) |
|
|
212 | (1) |
|
|
212 | (1) |
|
|
213 | (1) |
|
|
213 | (1) |
|
|
214 | (1) |
|
|
214 | (3) |
|
|
217 | (5) |
|
13.8 RHA Advantages and Disadvantages |
|
|
222 | (1) |
|
13.9 Common RHA Mistakes to Avoid |
|
|
222 | (1) |
|
|
222 | (2) |
14 Environmental Hazard Analysis (EHA) |
|
224 | (16) |
|
|
224 | (1) |
|
|
225 | (1) |
|
|
226 | (1) |
|
|
226 | (1) |
|
|
227 | (3) |
|
|
230 | (2) |
|
|
232 | (1) |
|
|
233 | (1) |
|
14.9 EHA Advantages and Disadvantages |
|
|
233 | (4) |
|
14.10 Common EHA Mistakes to Avoid |
|
|
237 | (1) |
|
|
237 | (1) |
|
|
237 | (1) |
|
14.13 National Environmental Policy Act |
|
|
237 | (1) |
|
14.14 Environmental Protection Agency |
|
|
238 | (2) |
15 Fault Tree Analysis |
|
240 | (38) |
|
|
240 | (2) |
|
|
242 | (1) |
|
|
243 | (1) |
|
|
243 | (1) |
|
|
244 | (9) |
|
15.5.1 FT Building Blocks |
|
|
245 | (2) |
|
|
247 | (1) |
|
15.5.3 FT Construction: Basics |
|
|
248 | (3) |
|
15.5.4 FT Construction: Advanced |
|
|
251 | (1) |
|
15.5.5 FT Construction Rules |
|
|
252 | (1) |
|
15.6 Functional Block Diagrams |
|
|
253 | (1) |
|
|
254 | (1) |
|
|
254 | (2) |
|
|
256 | (1) |
|
|
256 | (2) |
|
15.10.1 Probability of Success |
|
|
256 | (1) |
|
15.10.2 Probability of Failure |
|
|
256 | (1) |
|
15.10.3 Boolean Rules for FTA |
|
|
256 | (1) |
|
15.10.4 AND Gate Probability Expansion |
|
|
257 | (1) |
|
15.10.5 OR Gate Probability Expansion |
|
|
257 | (1) |
|
15.10.6 FT Probability Expansion |
|
|
257 | (1) |
|
15.10.7 Inclusion—Exclusion Approximation |
|
|
257 | (1) |
|
|
258 | (1) |
|
15.12 Importance Measures |
|
|
259 | (3) |
|
15.12.1 Cut Set Importance |
|
|
260 | (1) |
|
15.12.2 Fussell—Vesely Importance |
|
|
260 | (1) |
|
15.12.3 Risk Reduction Worth |
|
|
261 | (1) |
|
15.12.4 Risk Achievement Worth |
|
|
261 | (1) |
|
15.12.5 Birnbaum's Importance Measure |
|
|
261 | (1) |
|
|
262 | (1) |
|
|
262 | (9) |
|
|
271 | (1) |
|
15.16 Phase- and Time-Dependent FTA |
|
|
271 | (3) |
|
|
274 | (1) |
|
15.18 FTA Advantages and Disadvantages |
|
|
275 | (1) |
|
15.19 Common FTA Mistakes to Avoid |
|
|
276 | (1) |
|
|
276 | (2) |
16 Failure Mode and Effects Analysis |
|
278 | (22) |
|
|
278 | (1) |
|
|
278 | (1) |
|
|
279 | (1) |
|
|
280 | (1) |
|
|
281 | (5) |
|
16.5.1 FMEA Structural and Functional Models |
|
|
283 | (1) |
|
16.5.2 FMEA Product and Process FMEA |
|
|
283 | (1) |
|
16.5.3 FMEA Functional Failure Modes |
|
|
283 | (1) |
|
16.5.4 FMEA Hardware Failure Modes |
|
|
284 | (1) |
|
16.5.5 FMEA Software Failure Modes |
|
|
285 | (1) |
|
16.5.6 Quantitative Data Sources |
|
|
286 | (1) |
|
|
286 | (3) |
|
|
289 | (3) |
|
16.8 FMEA Example 1: Hardware Product FMEA |
|
|
292 | (1) |
|
16.9 FMEA Example 3: Functional FMEA |
|
|
292 | (3) |
|
16.10 FMEA Level of Detail |
|
|
295 | (3) |
|
16.11 FMEA Advantages and Disadvantages |
|
|
298 | (1) |
|
16.12 Common FMEA Mistakes to Avoid |
|
|
298 | (1) |
|
|
298 | (2) |
17 Hazard and Operability (HAZOP) Analysis |
|
300 | (16) |
|
|
300 | (1) |
|
17.2 HAZOP Analysis Background |
|
|
301 | (1) |
|
|
301 | (1) |
|
|
302 | (1) |
|
|
303 | (6) |
|
17.5.1 Design Representations |
|
|
305 | (1) |
|
|
305 | (1) |
|
|
306 | (1) |
|
17.5.4 Deviation from Design Intent |
|
|
307 | (2) |
|
|
309 | (1) |
|
|
310 | (1) |
|
|
311 | (1) |
|
17.9 HAZOP Advantages and Disadvantages |
|
|
311 | (2) |
|
17.10 Common HAZOP Analysis Mistakes to Avoid |
|
|
313 | (1) |
|
|
313 | (3) |
18 Event Tree Analysis (ETA) |
|
316 | (11) |
|
|
316 | (1) |
|
|
316 | (1) |
|
|
317 | (1) |
|
|
317 | (1) |
|
|
318 | (2) |
|
|
320 | (3) |
|
|
323 | (1) |
|
|
323 | (1) |
|
|
323 | (1) |
|
|
324 | (1) |
|
|
324 | (1) |
|
18.12 ETA Advantages and Disadvantages |
|
|
324 | (1) |
|
18.13 Common ETA Mistakes to Avoid |
|
|
325 | (1) |
|
|
326 | (1) |
19 Cause—Consequence Analysis |
|
327 | (12) |
|
|
327 | (1) |
|
|
327 | (1) |
|
|
328 | (1) |
|
|
328 | (1) |
|
|
329 | (1) |
|
|
330 | (1) |
|
|
331 | (1) |
|
|
332 | (1) |
|
19.9 CCA Example 1: Three-Component Parallel System |
|
|
332 | (1) |
|
19.10 CCA Example 2: Gas Pipeline System |
|
|
333 | (4) |
|
19.10.1 Reducing Repeated Events |
|
|
335 | (2) |
|
19.11 CCA Advantages and Disadvantages |
|
|
337 | (1) |
|
19.12 Common CCA Mistakes to Avoid |
|
|
338 | (1) |
|
|
338 | (1) |
20 Common Cause Failure Analysis |
|
339 | (24) |
|
|
339 | (1) |
|
|
340 | (1) |
|
|
340 | (1) |
|
|
341 | (3) |
|
|
341 | (1) |
|
|
341 | (1) |
|
20.4.3 Independence (in Design) |
|
|
341 | (1) |
|
20.4.4 Dependence (in Design) |
|
|
341 | (1) |
|
20.4.5 Common Cause Failure |
|
|
342 | (1) |
|
20.4.6 Common Mode Failure |
|
|
342 | (1) |
|
|
343 | (1) |
|
20.4.8 Mutually Exclusive Events |
|
|
343 | (1) |
|
|
343 | (1) |
|
20.4.10 CCF Coupling Factor |
|
|
343 | (1) |
|
20.4.11 Common Cause Component Group |
|
|
343 | (1) |
|
|
344 | (2) |
|
|
346 | (8) |
|
20.6.1 CCFA Process Step 2: Initial System Fault Tree Model |
|
|
347 | (1) |
|
20.6.2 CCFA Process Step 3: Common Cause Screening |
|
|
348 | (3) |
|
20.6.3 CCFA Process Step 4: Detailed CCF Analysis |
|
|
351 | (3) |
|
20.7 CCF Defense Mechanisms |
|
|
354 | (1) |
|
|
354 | (4) |
|
|
358 | (1) |
|
20.10 CCFA Advantages and Disadvantages |
|
|
359 | (1) |
|
20.11 Common CCFA Mistakes to Avoid |
|
|
360 | (1) |
|
|
361 | (2) |
21 Software Hazard Analysis |
|
363 | (18) |
|
|
363 | (1) |
|
|
364 | (1) |
|
|
365 | (1) |
|
|
365 | (1) |
|
|
366 | (1) |
|
|
367 | (1) |
|
21.7 Software Criticality Level |
|
|
368 | (1) |
|
|
369 | (7) |
|
21.9 Software Fault Tree Analysis |
|
|
376 | (1) |
|
21.10 SwHA Advantages and Disadvantages |
|
|
377 | (2) |
|
21.11 SwHA Mistakes to Avoid |
|
|
379 | (1) |
|
|
379 | (2) |
22 Process Hazard Analysis |
|
381 | (9) |
|
|
381 | (1) |
|
|
381 | (1) |
|
|
382 | (1) |
|
|
382 | (1) |
|
22.5 Process Safety Management |
|
|
383 | (1) |
|
|
384 | (1) |
|
|
385 | (1) |
|
|
386 | (1) |
|
|
387 | (1) |
|
22.10 PHA Advantages and Disadvantages |
|
|
388 | (1) |
|
22.11 Common PHA Mistakes to Avoid |
|
|
389 | (1) |
|
|
389 | (1) |
23 Test Hazard Analysis |
|
390 | (16) |
|
|
390 | (1) |
|
|
390 | (1) |
|
|
391 | (1) |
|
|
391 | (2) |
|
|
393 | (1) |
|
|
394 | (1) |
|
|
395 | (1) |
|
|
395 | (1) |
|
|
395 | (1) |
|
23.8 Testing in the System Development Life Cycle |
|
|
396 | (1) |
|
|
397 | (1) |
|
23.9.1 Standard Development Test Types |
|
|
397 | (1) |
|
|
397 | (1) |
|
23.9.3 Software Performance Tests |
|
|
397 | (1) |
|
23.9.4 Special Safety-Related Testing |
|
|
398 | (1) |
|
|
398 | (6) |
|
23.11 THA Advantages and Disadvantages |
|
|
404 | (1) |
|
23.12 Common THA Mistakes to Avoid |
|
|
404 | (1) |
|
|
404 | (2) |
24 Fault Hazard Analysis |
|
406 | (10) |
|
|
406 | (1) |
|
|
406 | (1) |
|
|
407 | (1) |
|
|
407 | (1) |
|
|
408 | (2) |
|
|
410 | (1) |
|
|
411 | (3) |
|
24.8 FHA Advantages and Disadvantages |
|
|
414 | (1) |
|
24.9 Common FHA Mistakes to Avoid |
|
|
414 | (1) |
|
|
414 | (2) |
25 Sneak Circuit Analysis |
|
416 | (14) |
|
|
416 | (1) |
|
|
417 | (1) |
|
|
418 | (1) |
|
|
418 | (1) |
|
|
419 | (1) |
|
|
419 | (5) |
|
25.6.1 Step 1: Acquire Data |
|
|
420 | (1) |
|
|
421 | (1) |
|
25.6.3 Step 3: Process Data |
|
|
421 | (1) |
|
25.6.4 Step 4: Produce Network Trees |
|
|
422 | (1) |
|
25.6.5 Step 5: Identify Topographs |
|
|
422 | (1) |
|
25.6.6 Step 6: Perform Analysis |
|
|
423 | (1) |
|
25.6.7 Step 7: Generate SCA Report |
|
|
424 | (1) |
|
25.7 Example 1: Sneak Path |
|
|
424 | (1) |
|
25.8 Example 2: Sneak Label |
|
|
425 | (1) |
|
25.9 Example 3: Sneak Indicator |
|
|
425 | (1) |
|
25.10 Example Sneak Clues |
|
|
425 | (1) |
|
25.11 Software Sneak Circuit Analysis |
|
|
425 | (3) |
|
25.12 SCA Advantages and Disadvantages |
|
|
428 | (1) |
|
25.13 Common SCA Mistakes to Avoid |
|
|
428 | (1) |
|
|
429 | (1) |
26 Markov Analysis |
|
430 | (16) |
|
|
430 | (1) |
|
|
430 | (1) |
|
|
431 | (1) |
|
|
431 | (1) |
|
|
432 | (2) |
|
|
434 | (4) |
|
26.6.1 State Transition Diagram Construction |
|
|
434 | (2) |
|
26.6.2 State Equation Construction |
|
|
436 | (2) |
|
|
438 | (3) |
|
|
438 | (1) |
|
26.7.2 Markov Model of Two-Component Series System with No Repair |
|
|
438 | (1) |
|
26.7.3 Markov Model of Two-Component Parallel System with No Repair |
|
|
439 | (1) |
|
26.7.4 Markov Model of Two-Component Parallel System with Component Repair |
|
|
439 | (1) |
|
26.7.5 Markov Model of Two-Component Parallel System with Component/System Repair |
|
|
440 | (1) |
|
26.7.6 Markov Model of Two-Component Parallel System with Sequencing |
|
|
440 | (1) |
|
26.8 MA and FTA Comparisons |
|
|
441 | (1) |
|
26.9 MA Advantages and Disadvantages |
|
|
442 | (3) |
|
26.10 Common MA Mistakes to Avoid |
|
|
445 | (1) |
|
|
445 | (1) |
27 Petri Net Analysis |
|
446 | (10) |
|
|
446 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
448 | (1) |
|
|
448 | (4) |
|
|
452 | (1) |
|
|
452 | (1) |
|
27.8 PNA Advantages and Disadvantages |
|
|
453 | (1) |
|
27.9 Common PNA Mistakes to Avoid |
|
|
454 | (1) |
|
|
454 | (2) |
28 Barrier Analysis |
|
456 | (15) |
|
|
456 | (1) |
|
|
456 | (1) |
|
|
457 | (1) |
|
|
457 | (1) |
|
|
458 | (1) |
|
|
458 | (1) |
|
|
458 | (1) |
|
|
458 | (1) |
|
|
459 | (6) |
|
28.6.1 Example Checklist of Energy Sources for BA |
|
|
460 | (3) |
|
|
463 | (2) |
|
|
465 | (2) |
|
|
467 | (2) |
|
28.9 BA Advantages and Disadvantages |
|
|
469 | (1) |
|
28.10 Common Barrier Analysis Mistakes to Avoid |
|
|
469 | (1) |
|
|
470 | (1) |
29 Bent Pin Analysis |
|
471 | (12) |
|
|
471 | (1) |
|
|
471 | (1) |
|
|
472 | (1) |
|
|
472 | (2) |
|
|
474 | (1) |
|
|
474 | (2) |
|
|
476 | (2) |
|
29.8 BPA Advantages and Disadvantages |
|
|
478 | (1) |
|
29.9 Common BPA Mistakes to Avoid |
|
|
478 | (4) |
|
|
482 | (1) |
30 Management Oversight Risk Tree Analysis |
|
483 | (7) |
|
30.1 Introduction To MORT Analysis |
|
|
483 | (1) |
|
|
483 | (1) |
|
|
484 | (1) |
|
|
484 | (1) |
|
|
485 | (1) |
|
30.6 MORT Analysis Worksheet |
|
|
486 | (1) |
|
30.7 MORT Advantages and Disadvantages |
|
|
487 | (2) |
|
30.8 Common MORT Analysis Mistakes to Avoid |
|
|
489 | (1) |
|
|
489 | (1) |
31 Job Hazard Analysis |
|
490 | (16) |
|
|
490 | (1) |
|
|
491 | (1) |
|
|
492 | (1) |
|
|
492 | (1) |
|
|
493 | (4) |
|
|
497 | (2) |
|
31.7 Example Hazard Checklist |
|
|
499 | (2) |
|
|
501 | (1) |
|
|
502 | (1) |
|
31.10 JHA Advantages and Disadvantages |
|
|
502 | (3) |
|
31.11 Common JHA Mistakes to Avoid |
|
|
505 | (1) |
|
|
505 | (1) |
32 Threat Hazard Analysis |
|
506 | (14) |
|
|
506 | (1) |
|
|
506 | (1) |
|
|
507 | (1) |
|
|
507 | (2) |
|
|
509 | (2) |
|
32.5.1 Cradle-to-Grave Sequences |
|
|
509 | (1) |
|
|
510 | (1) |
|
32.5.3 Characterization of Environments |
|
|
511 | (1) |
|
|
511 | (1) |
|
|
511 | (4) |
|
|
515 | (3) |
|
32.8 THA Advantages and Disadvantages |
|
|
518 | (1) |
|
32.9 Common THA Mistakes to Avoid |
|
|
518 | (1) |
|
|
518 | (2) |
33 System of Systems Hazard Analysis |
|
520 | (17) |
|
|
520 | (1) |
|
|
521 | (1) |
|
|
522 | (1) |
|
|
522 | (4) |
|
33.5 SoS Safety and Hazards |
|
|
526 | (2) |
|
|
528 | (3) |
|
|
528 | (2) |
|
33.6.2 SoS Component System Matrix |
|
|
530 | (1) |
|
|
531 | (2) |
|
|
533 | (1) |
|
|
534 | (1) |
|
|
535 | (1) |
|
33.11 SoSHA Advantages and Disadvantages |
|
|
535 | (1) |
|
33.12 Common SoSHA Mistakes to Avoid |
|
|
535 | (1) |
|
|
536 | (1) |
34 Summary |
|
537 | (12) |
|
34.1 Tenets of Hazard Analysis |
|
|
537 | (1) |
|
34.2 Description of Tenets |
|
|
538 | (9) |
|
34.2.1 Hazards and Mishaps are Not Chance Events; Hazards Lead to Mishaps If Left Unchecked |
|
|
538 | (1) |
|
34.2.2 Hazards are Created During System Design and Exist with the Design |
|
|
538 | (1) |
|
34.2.3 Hazards are Comprised of Three Components: HA, IMs, and TTO |
|
|
539 | (1) |
|
34.2.4 Many Hazards Cannot be Eliminated due to the Hazard Sources that are Required by the System |
|
|
540 | (1) |
|
34.2.5 Hazards Present Risk; Risk is the Metric for Measuring the Criticality or Danger Level of a Hazard |
|
|
541 | (1) |
|
34.2.6 Hazards can be Modified via Design Methods, which in Turn can Reduce Risk |
|
|
541 | (2) |
|
34.2.7 Hazard Analysis is the Key to Preventing Mishaps; Hazard Identification and Mitigation Reduce Mishap Risk |
|
|
543 | (1) |
|
34.2.8 The System Mishap Model is an Effective Hazard Analysis Tool |
|
|
543 | (1) |
|
34.2.9 Hazard Analysis and Hazard Descriptions can Easily Become Abused, Confused, and/or Misused |
|
|
544 | (1) |
|
34.2.10 Utilizing More than One Hazard Analysis Technique is Recommended |
|
|
544 | (1) |
|
34.2.11 Hazard Mitigation is not Hazard Elimination |
|
|
545 | (1) |
|
34.2.12 Hazard Risk is the Same as Mishap Risk |
|
|
546 | (1) |
|
34.2.13 There are Both Primary and Secondary Hazard Analysis Techniques |
|
|
546 | (1) |
|
34.2.14 There are Pseudo-Hazards and Real Hazards |
|
|
546 | (1) |
|
|
547 | (2) |
Appendix A List of Acronyms |
|
549 | (3) |
Appendix B Glossary |
|
552 | (15) |
Appendix C Hazard Checklists |
|
567 | (42) |
Appendix D References |
|
609 | (4) |
Index |
|
613 | |