Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Michal Sojka
SESAMO
Security and Safety Modelling
1 / 79
Outline
1 What is safety?
2 System safety
3 Standards
4 Example
5 Achieving safety
Generic safety process
Safety case
Safety integrity
Miscellaneous
2 / 79
What is safety?
Outline
1 What is safety?
2 System safety
3 Standards
4 Example
5 Achieving safety
Generic safety process
Safety case
Safety integrity
Miscellaneous
3 / 79
What is safety?
What is safety?
4 / 79
What is safety?
What is safety?
Classical definition
Freedom from those conditions that can cause death, injury, occupational
illness, damage to or loss of equipment or property, or damage to the
environment.
5 / 79
What is safety?
What is safety?
Classical definition
Freedom from those conditions that can cause death, injury, occupational
illness, damage to or loss of equipment or property, or damage to the
environment.
Alternative definition
Safety = Managing complexity without going crazy and ensuring
completeness and consistency.
6 / 79
What is safety?
Environment Environment
Source: TU Wien
7 / 79
What is safety?
Environment Environment
Source: TU Wien
9 / 79
What is safety?
10 / 79
What is safety?
11 / 79
What is safety?
12 / 79
What is safety?
13 / 79
What is safety?
14 / 79
What is safety?
15 / 79
System safety
Outline
1 What is safety?
2 System safety
3 Standards
4 Example
5 Achieving safety
Generic safety process
Safety case
Safety integrity
Miscellaneous
16 / 79
System safety
System safety
17 / 79
System safety
System safety
18 / 79
System safety
System safety
19 / 79
System safety
System safety
20 / 79
System safety
System safety
21 / 79
System safety
System safety
22 / 79
System safety
System safety
23 / 79
System safety
What is a system?
24 / 79
System safety
What is a system?
25 / 79
System safety
What is a system?
26 / 79
System safety
Is terminology important?
27 / 79
System safety
Is terminology important?
28 / 79
System safety
Is terminology important?
29 / 79
System safety
Functional safety
Part of the overall safety […] that depends on the correct functioning of
the electrical and/or electronic and/or programmable electronic
safety-related systems and other risk reduction measures.
[IEC 61508-4/Ed.2, clause 3.1.12]
30 / 79
System safety
Functional safety
Part of the overall safety […] that depends on the correct functioning of
the electrical and/or electronic and/or programmable electronic
safety-related systems and other risk reduction measures.
[IEC 61508-4/Ed.2, clause 3.1.12]
31 / 79
Standards
Outline
1 What is safety?
2 System safety
3 Standards
4 Example
5 Achieving safety
Generic safety process
Safety case
Safety integrity
Miscellaneous
32 / 79
Standards
33 / 79
Standards
Liability
MOD Def Stan 00-74 Part 1 Preface (or any other Def Stan)
Compliance with this Defence Standard shall not in itself relieve any
person from any legal obligations imposed upon them.
This standard has been devised solely for the use of the Ministry of
Defence (MOD) and its contractors in the execution of contracts for
the MOD. To the extent permitted by law, the MOD hereby excludes
all liability whatsoever and howsoever arising (including, but without
limitation, liability resulting from negligence) for any loss or damage
however caused when the standard is used for any other purpose.
34 / 79
Standards
36 / 79
Example
Outline
1 What is safety?
2 System safety
3 Standards
4 Example
5 Achieving safety
Generic safety process
Safety case
Safety integrity
Miscellaneous
37 / 79
Example
38 / 79
Example
What happened?
39 / 79
Example
40 / 79
Example
41 / 79
Example
42 / 79
Example
43 / 79
Example
44 / 79
Example
45 / 79
Example
46 / 79
Example
47 / 79
Example
48 / 79
Example
Outline
1 What is safety?
2 System safety
3 Standards
4 Example
5 Achieving safety
Generic safety process
Safety case
Safety integrity
Miscellaneous
50 / 79
Achieving safety
51 / 79
Achieving safety
Risk-based approach
52 / 79
Achieving safety
Using standards
53 / 79
Achieving safety → Generic safety process
54 / 79
Achieving safety → Generic safety process
55 / 79
Achieving safety → Generic safety process
56 / 79
Achieving safety → Safety case
Lowest-level “standard”
57 / 79
Achieving safety → Safety case
Safety case
Definition
A safety case is an evidence-based explanation of why it is believed that a
system is safe enough to be used in its intended application.
Specific for each application. This can be a Word document or a
structured safety case.
Structured safety case
Overall approach.
Claim-Argument-Evidence (CAE) structure.
Top-level claim supported by arguments and evidences that the
arguments are correct.
Split into sub-claims.
Safety standards give guidance how to construct arguments.
58 / 79
Achieving safety → Safety case
CAE example
59 / 79
Achieving safety → Safety case
Safety integrity
Safety-related systems are used to reduce
System
the identified risks to tolerable level.
Safety-related
Therefore, safety of the whole system system
61 / 79
Achieving safety → Safety integrity
Safety integrity
Safety-related systems are used to reduce
System
the identified risks to tolerable level.
Safety-related
Therefore, safety of the whole system system
Two components:
Random failure integrity
Systematic failure integrity
Question: How can I determine, that my safety-related system has
sufficient safety integrity?
62 / 79
Achieving safety → Safety integrity
63 / 79
Achieving safety → Safety integrity
65 / 79
Achieving safety → Safety integrity
66 / 79
Achieving safety → Safety integrity
67 / 79
Achieving safety → Safety integrity
68 / 79
Achieving safety → Safety integrity
69 / 79
Achieving safety → Safety integrity
70 / 79
Achieving safety → Safety integrity
71 / 79
Achieving safety → Safety integrity
72 / 79
Achieving safety → Safety integrity
73 / 79
Achieving safety → Safety integrity
74 / 79
Achieving safety → Safety integrity
75 / 79
Achieving safety → Safety integrity
Risk classes
MIL-STD-882E, Table III
76 / 79
Achieving safety → Miscellaneous
Traceability
77 / 79
Achieving safety → Miscellaneous
Safety culture
78 / 79
Achieving safety → Miscellaneous
References
79 / 79