{"title":"Software safety analysis: using the entire risk analysis toolkit","authors":"V. Guthrie, P. Parikh","doi":"10.1109/RAMS.2004.1285460","DOIUrl":null,"url":null,"abstract":"When an accident occurs, it is common to attribute the accident to a failure in the system. Therefore, precautions must be taken to design the system to provide safeguards that supports the system even when failures occur. The problem, however, is that accident occur where there is no failure in the system (i.e., the software, hardware, and humans \"work\" as they are supposed to). The flaw is in the design oversight for specific high-risk situations. It is up to the decision maker to: (a) ensure that adequate design and safety checks have been performed before the system is put into operation (b) ensure that a comprehensive risk analysis is conducted to examine both the design element malfunctions and the design oversights to determine the loss sequences (c) be satisfied that the loss sequences are understood with adequate confidence that the system risk is at or below the risk acceptance criteria.","PeriodicalId":270494,"journal":{"name":"Annual Symposium Reliability and Maintainability, 2004 - RAMS","volume":"56 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2004-08-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Annual Symposium Reliability and Maintainability, 2004 - RAMS","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RAMS.2004.1285460","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
When an accident occurs, it is common to attribute the accident to a failure in the system. Therefore, precautions must be taken to design the system to provide safeguards that supports the system even when failures occur. The problem, however, is that accident occur where there is no failure in the system (i.e., the software, hardware, and humans "work" as they are supposed to). The flaw is in the design oversight for specific high-risk situations. It is up to the decision maker to: (a) ensure that adequate design and safety checks have been performed before the system is put into operation (b) ensure that a comprehensive risk analysis is conducted to examine both the design element malfunctions and the design oversights to determine the loss sequences (c) be satisfied that the loss sequences are understood with adequate confidence that the system risk is at or below the risk acceptance criteria.