| P. Bishop, R. Bloomfield, L. Emmet, C. Jones, and P. Froome, Adelard Safety Case Development Manual. London: Adelard, 1998. 336 |
....detected by a checksum in the result) This could be tested or subject to third party review. In this way the claim of mitigation has an argument associated with it and this argument needs evidence following the classic safety case approach (e.g. as described in Fig. 6. Output from HAZART ASCAD [1]) The verification of mitigation arguments is especially important in systems where traditional intuition about failure modes and consequences is often inadequate. 7 Future Work The tool has been implemented to a stage that allows evaluation of its features and the theory it is based on. It was ....
P Bishop, R Bloomfield, L Emmet, C Jones, and P Froome. Adelard Safety Case Development Manual. Adelard, London, 1998.
....the argument step by step downwards until the claims can be related back to the available evidence. 5 An Illustrative Example This section illustrates the application of the impact assessment process to part of the safety argument for a nuclear reactor trip system (derived from details given in [8]) Figure 8 shows the structure of claims made regarding the timeliness of the trip system response. 7 Worst case cycle time determined to be 2.7 G.TIM.STATIC Instruction times are correct A ADC conversions and output time are correct A Static analysis used to determined worst case ....
P. Bishop, R. Bloomfield, L. Emmet, C. Jones, and P. Froome, Adelard Safety Case Development Manual. London: Adelard, 1998. Appendix: Key to Goal Structuring Notation (GSN) Symbols A Goal Solution Context Assumption SolvedBy InContextOf
....and limb but includes also equipment damage and threats to the environment. The concept of a Safety Case is central in many safety standards. A Safety Case documents the evidence providing assurance that the system will be safe to operate, and assumptions on which the assurance is based [15] [16]. Emphasis in the past has often been on documenting the quality of the engineering process, but certifiers increasingly require also product assurance details of safety features of the design and evidence of their effectiveness. For example, the UK Ministry of Defence s flight certification ....
P. Bishop, R. Bloomfield, L. Emmet, C. Jones, and P. Froome, Adelard Safety Case Development Manual, 1998.
....presented in this thesis, this approach presupposes that the system in question is amenable to formal specification and that arguments of cause and effect are sufficient for the safety case. 2.4. 4 Adelard Safety Case Development Method The recently published Adelard Safety Case Development Manual [36] represents one of the first attempts to present a total safety case development methodology. With respect to the presentation of safety arguments, it is heavily based upon the qualitative aspects of the SHIP approach. In particular, it adopts the same view of safety argument structure, shown in ....
....Traceability matrices are a means of representing how one statement (claim, requirement, objective etc. relates to a series of other requirements. Traceability matrices are popular within the requirements engineering and security domains. Table 6 shows an example traceability matrix (taken from [36]) Requirement Design Feature TRIP PFD STR TIM FIX TST F1 F2 UPD SEC Redundant channels and thermocouples Fail safe design features Separate Monitor Computer Design Simplicity Formally Proved Software Table 6 An Example Traceability Matrix ....
[Article contains additional citation context not shown here]
P. Bishop, R. Bloomfield, L. Emmet, C. Jones, and P. Froome, Adelard Safety Case Development Manual. London: Adelard, 1998. 336
No context found.
P. Bishop, R. Bloomfield, L. Emmet, C. Jones, and P. Froome, Adelard Safety Case Development Manual. London: Adelard, 1998. 336
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC