Model - Based Analysis of Socio - Technical Risk 1

نویسنده

  • Nancy G. Leveson
چکیده

Traditional approaches to hazard analysis and safety-related risk management are based on an accident model that focuses on failure events in static engineering designs and linear notions of causality. They are therefore limited in their ability to include complex human decision-making, software errors, system accidents (versus component failure accidents), and organizational risk factors in the analysis. These traditional accident models do not adequately capture the dynamic complexity and non-linear interactions that characterize accidents in complex systems, i.e., what Perrow called system accidents. System accidents often result from adaptation and degradation of safety over time: The move to a high-risk state occurs without any particular decision to do so but simply as a series of decisions or adaptations (asynchronous evolution) that move the system into a high-risk state where almost any slight error or deviation can lead to a major loss. To handle this more comprehensive view of accidents, risk management tools and models need to treat systems as dynamic processes that are continually adapting to achieve their ends and to react to changes in themselves and their environment. Leveson’s new accident model, STAMP (Systems-Theoretic Accident Modeling and Processes), provides the foundation for such a risk management approach by describing the process leading up to an accident as an adaptive feedback function that fails to maintain safety constraints as performance changes over time to meet a complex set of goals and values. In this report, a new type of hazard analysis based on this new model of accident causation is described called STPA (STAMP-based Analysis). STPA is illustrated by applying it to TCAS II, a complex aircraft collision avoidance system, and to a public water safety system in Canada. In the first example (TCAS II), STPA is used to analyze an existing system design. A formal and executable modeling/specification language called SpecTRM-RL is used to model and simulate the technical and human components in the system and to provide the support required for the STPA analysis. The results are compared with traditional hazard analysis techniques, including a high-quality TCAS II fault tree analysis created by MITRE for the FAA. The STPA analysis was found to be more comprehensive and complete than the fault tree analysis. The second example of STPA (the public water system) illustrates its application to the organizational and social components of open systems as well as the technical. In this example, STPA is used to drive the design process rather than to evaluate an existing design. Again, SpecTRM-RL models are used to support the analysis, but this time we added system dynamics models. SpecTRM-RL allows us to capture the system’s static structure (hardware, software, operational procedures, and management controls) and is useful in performing hazard analyses 1 This research was partially supported by NASA grants NAG2-1843 and NAS2-03117 and NSF ITR grant CCR-0085829. © Copyright by Nancy Leveson, July 2003. All rights reserved.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Agent-Based Modelling of Socio-Technical Systems (Agent-Based Social Systems) by Koen H. van Dam, Igor Nikolic and Zofia Lukszo (eds.)

agent based modelling of socio technical systems agent agent-based modeling and analysis of socio-technical systems capturing socio-technical systems with agent-based human behaviour modelling in complex sociotechnical agent-based social systems springer agent based modeling of large-scale socio-technical metal substantiating agent-based quality goals for understanding chapter 9 next steps in m...

متن کامل

The Analysis of Key Elements of Socio-technical Knowledge Management System

There are different approaches to knowledge management. So, a knowledge management system could be analyzed from different viewpoints. Usually the term a “knowledge management system” is used as a synonym for the information and communication tools, and rarely is defined from a social or sociotechnical perspective. This paper acknowledges the socio-technical approach to knowledge management sys...

متن کامل

Optimal Placement of Substations Based on Economic and Technical Risk Management

Design and expansion of distribution systems seems inevitable in view of the need to satisfy the rise in energy consumption in a technical and economical way. Optimal location, sizing and determining the service area of substations is one of the principle problems in expansion of distribution systems. Also uncertainty is one of the important factors that increase risk of exact decision makings....

متن کامل

Research on Safety Risk of Dangerous Chemicals Road Transportation Based on Dynamic Fault Tree and Bayesian Network Hybrid Method (TECHNICAL NOTE)

Safety risk study on road transportation of hazardous chemicals is a reliable basis for the government to formulate transportation planning and preparing emergent schemes, but also is an important reference for safety risk managers to carry out dangerous chemicals safety risk managers. Based on the analysis of the transport safety risk of dangerous chemicals at home and abroad, this paper studi...

متن کامل

Modelling and Analysing Socio-Technical Systems

Modern organisations are complex, socio-technical systems consisting of a mixture of physical infrastructure, human actors, policies and processes. An increasing number of attacks on these organisations exploits vulnerabilities on all different levels, for example combining a malware attack with social engineering. Due to this combination of attack steps on technical and social levels, risk ass...

متن کامل

Tool-based risk assessment of cloud infrastructures as socio-technical systems

Assessing risk in cloud infrastructures is difficult. Typical cloud infrastructures contain potentially thousands of nodes that are highly interconnected and dynamic. Another important component is the set of human actors who get access to data and computing infrastructure. The cloud infrastructure therefore constitutes a socio-technical system. Attacks on socio-technical systems are still most...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005