Top 5 system engineers omissions that make safety engineer s lives harder

Similar documents
Understanding safety life cycles

D-Case Modeling Guide for Target System

Purpose. Scope. Process flow OPERATING PROCEDURE 07: HAZARD LOG MANAGEMENT

The Safety Case. Structure of Safety Cases Safety Argument Notation

CHAPTER 28 DEPENDENT FAILURE ANALYSIS CONTENTS

Safe High Pressure Water Washing (HPWW) Requirement

Keeping People Safe CHURCH HEALTH & SAFETY TOOLKIT. Health and Safety Policy

Hazard Identification or Complacency?? Which is the Bigger Problem?? Speakers: Brett James & Reginald Whitaker, CSP Oklahoma Steel & Wire

Unit 5: Prioritize and Manage Hazards and Risks STUDENT GUIDE

Safety-critical systems: Basic definitions

The IEC61508 Inspection and QA Engineer s hymn sheet

The evolution of the Ex-proof flame path

Using what we have. Sherman Eagles SoftwareCPR.

EUROCONTROL Guidance Material for Area Proximity Warning Appendix B-1: Initial Safety Argument for APW System

HAZARD MANAGEMENT PROCEDURE

MANUAL HANDLING CODE OF PRACTICE

Risk Management Series Article 8: Risk Control

A Simple Horizontal Velocity Model of a Rising Thermal Instability in the Atmospheric Boundary Layer

IGEM/TD/2 Edition 2 with amendments July 2015 Communication 1779 Assessing the risks from high pressure Natural Gas pipelines

Hazard Identification

The Safety Case. The safety case

CONTENTS OF THE PCSR CHAPTER 1 - INTRODUCTION AND GENERAL DESCRIPTION

Safety Management in Multidisciplinary Systems. SSRM symposium TA University, 26 October 2011 By Boris Zaets AGENDA

ALIGNING MOD POSMS SAFETY AND POEMS ENVIRONMENTAL RISK APPROACHES EXPERIENCE AND GUIDANCE

D Accessories that actively cooperate DRÄGER INFINITY ID-ACCESSORIES

Having an Impact Using Hazard Elimination and Control at Mount Isa s Copper Mine. Brett Cribb Senior Long Term Planning Engineer Mount Isa Operations

SUP 15 Health & Safety Management Pressure Systems. Unified procedures for use within NHS Scotland

RACING RULES / RACE OFFICIALS

THE CANDU 9 DISTRffiUTED CONTROL SYSTEM DESIGN PROCESS

The IEC61508 Project Manager's & Project Engineer's hymn sheet

EYE DOMINANCE. You WILL be one of the three. If you re not sure, use the provided test sheet to check.

THE FUTURE OF WATER IS WIRELESS

Kiefner & Associates, Inc.

Performing Hazard Analysis on Complex, Software- and Human-Intensive Systems

Workshop Functional Safety

Health and Safety is Managed

Health and Safety Policy

4. Please Do Break the Crystal

Gold Seal s Top Five Landing Mistakes

Hazard Recognition. Leader s Guide and Quiz

This manual provides necessary requirements for meeting the IEC or IEC functional safety standards.

Safety assessments for Aerodromes (Chapter 3 of the PANS-Aerodromes, 1 st ed)

ROSE-HULMAN INSTITUTE OF TECHNOLOGY Department of Mechanical Engineering. Mini-project 3 Tennis ball launcher

Security & Stability Advisory Committee. Update of Activities

24 rules that will change the landscape of golf By Missy March 1, 2017

Blease900 Ventilator PATIENT CENTERED VENTILATION

Questions & Answers About the Operate within Operate within IROLs Standard

Review and Assessment of Engineering Factors

GPS technology. The use of the GPS technology has the objective of finding out movement patterns in the neighborhood. /16

CHANGE TO LAW (From 1st April 2019) OFFICIAL. Marylebone Cricket Club. Change to Law 47.1 (From 1st April 2019) 1

WHEN TO RUSH A BEHIND IN AUSTRALIAN RULES FOOTBALL: A DYNAMIC PROGRAMMING APPROACH

VERIFICATION OF ONSHORE LNG AND GAS FACILITIES

Waste Industry Safety & Health

Managing for Liability Avoidance. (c) Lewis Bass

Low Level Cycle Signals used as repeaters of the main traffic signals Appendices

Guidance on Risk Evaluation and Risk Acceptance

Safety Manual. Process pressure transmitter IPT-1* 4 20 ma/hart. Process pressure transmitter IPT-1*

Keeping People Safe CHURCH HEALTH & SAFETY TOOLKIT. Working at Height

Health and Safety Policy

UNITY 2 TM. Air Server Series 2 Operators Manual. Version 1.0. February 2008

Application of Dijkstra s Algorithm in the Evacuation System Utilizing Exit Signs

Discussion and guidance on the definition and qualification of porous loads

Session: 14 SIL or PL? What is the difference?

FUNCTIONAL SKILLS MATHEMATICS (level 1)

FIRST NAME: (PRINT ABOVE (UNDERNEATH LAST NAME) IN CAPITALS)

AUSTRALIA ARGENTINA CANADA EGYPT NORTH SEA U.S. CENTRAL U.S. GULF. SEMS HAZARD ANALYSIS TRAINING September 29, 2011

SAEMA Document No. SDN Original Issue Date: April 2017 Revision Reference: Revision Date: Not later than end of April 2019

George Cleland 6 th December 2011

RISK ASSESSMENT POLICY

Application of pipeline risk assessment to proposed developments in the vicinity of high pressure Natural Gas pipelines

THESE FORMS ARE NOT A SUBSTITUTE FOR LEGAL ADVICE.

C. Mokkapati 1 A PRACTICAL RISK AND SAFETY ASSESSMENT METHODOLOGY FOR SAFETY- CRITICAL SYSTEMS

ADA Transition Plan. City of Gainesville FY19-FY28. Date: November 5, Prepared by: City Of Gainesville Department of Mobility

Implementing IEC Standards for Safety Instrumented Systems

New Airfield Risk Assessment / Categorisation

Evaluation and Improvement of the Roundabouts

Fit for Purpose Compositional Input for Allocation Using Equations of State Thomas Hurstell, Letton Hall Group

How to achieve fluid traffic

Health and Safety Policy

QUANTIFYING THE TOLERABILITY OF POTENTIAL IGNITION SOURCES FROM UNCERTIFIED MECHANICAL EQUIPMENT INSTALLED IN HAZARDOUS AREAS

So it s Reliable but is it Safe? - a More Balanced Approach To ATM Safety Assessment

Amusement Device Safety Council. Safety of Amusement Devices: Pre-use inspection

Traditional Approaches to Risk Management and Medical Device Software. Are They Good Enough? Can We Do Better?

Ultima. X Series Gas Monitor

Downloaded from SAE International by Universiti Teknologi Malaysia, Monday, October 05, 2015

2011 Annual Symposium " Leading Entrepreneurial and Innovative Projects Eugene Maltsev

EX0-008 exin. Number: EX0-008 Passing Score: 800 Time Limit: 120 min.

Safety Analysis: Event Classification

Calculation of Trail Usage from Counter Data

Awakening 1 PROGRAM INSTRUCTIONS

INTERIM ADVICE NOTE 150/12. Guidance for Alternative Temporary Traffic Management Techniques for Relaxation Schemes on Dual Carriageways.

Lecture 04 ( ) Hazard Analysis. Systeme hoher Qualität und Sicherheit Universität Bremen WS 2015/2016

Introduction to Machine Safety Standards

6/19/2014. Children s Hospital of Philadelphia: Recent Changes. Recent Changes in CHOP IRB Procedures

ZORE-X. CORE SERIES 9x19. Owner s Manual. Watch the video before initial use

Safety manual for Fisher GX Control Valve and Actuator

Outside Air Nonresidential HVAC Stakeholder Meeting #2 California Statewide Utility Codes and Standards Program

Bending Vibration Analysis of Pipes and Shafts Arranged in Fluid Filled Tubular Spaces Using FEM

Applications & Tools. Evaluation of the selection of a safetyrelated mode using non-safety-related components

Phase B: Parameter Level Design

Transcription:

Top 5 system engineers omissions that make safety engineer s lives harder Colin Brain SE Validation Limited INCOSE President s Award Winners 2004, 2007 and 2008 INCOSE Gold Circle Award Winners 2003-2009

1. Safety Requirements Don t define any safety requirements its easier to simply quote a standard Similarly with CONOPS/ CONEMP/ CONUSE 2

Requirement? 3

No Safety Requirements - Impact Most safety engineers seldom see real safety requirements Acceptance then depends on demonstrating process compliance during design, rather than through-life safety in operation System safety is about freedom from harm during operations, without CONOPS etc. safety team have to: Guess how the system will be used and misused Ask potential users, who may have to guess 4

2. Safety Architecture Don t define any safety architecture, i.e. no defined system safety boundaries no defined safety interfaces with neighbouring systems no documentation of cross-interface safety assumptions no allocation of safety requirements to sub-systems Simply flow down standards required 5

Lack of Safety Architecture - Impact Without an architecture it is difficult to record safety reliance on sub-systems... Without interface information the safety team can only try to communicate their assumptions We produce safety requirements reports saying what we have done, but system engineers rarely know what to do with them Radio therapy machine 6

3. Test & Analysis Don t make provision for safety tests or analyses This is easier if you don t bring in safety specialists until the documentation phase (safety case) If you don t define safety requirements or specifications then no satisfaction evidence is required for these 7

Lack of Test & Analysis - Impact You cannot test something to prove that it is safe, but; tests can show it to be unsafe you can test for satisfaction of derived safety requirements Analysis can be effective, but always depends on the validity of the analysis models chosen Titanic Effect: The severity with which a system fails is proportional to the designer s belief that it cannot fail 8

4. Safety in Design Don t fix safety problems in design, leave them to be fixed in operation Leave it to the human factor folk to provide guidance and training If necessary provide personal protective equipment Don t worry about producing a safe design just produce a safety case 9

Lack of Safety in Design - Impact If you can eliminate a hazard, get rid of it If you cannot eliminate it, reduce its probability of causing an accident When you can t do anything else, mitigate the severity of the accident Managing safety in operation is never as satisfactory as managing it by design, however well intentioned However, beware the assumption that automation eliminates human error it doesn t 10

5. Safety Modifications Don t consult the safety engineer when making modifications to fix identified safety defects 11

No Safety Mod Consultation - Impact Modification may make the problem worse, not better...may be true of other mods...especially without an architecture! Significant defects should also trigger process and competence reviews 12

Conclusion: 5 Top Omissions 1. Safety requirements 2. Safety architectures 3. Safety test & analysis 4. Safety in design 5. Consulting on safety modifications I look forward to the discussion!!! 13