Quantitative Risk Management for Safety–Critical Systems
摘要
All safety-oriented systems, where unsafe failures called hazards causing injury or death, e.g., transportation systems, nuclear power plants, medical surgeries and manufacturing plants etc., must have thorough safety management, including safety assurance, minimizing hazards. These systems are designed to go to fail-safe or fault-tolerant conditions in the case of any safety–critical subsystem or component failure. Unsafe failures can be classified as per likelihood of occurrence and as per the severity of consequence. Based on likelihood-severity matrix, there are international classification of Safety Integration Levels (SIL) depending on the effect of accidents. Though hazard free systems should be of highest SIL, higher costs in design and manufacture can be minimised by adopting As Low as Reasonably Possible (ALARP) principle. For that, the Tolerable Hazard Rate (THR) threshold must be defined. Failures can be classified as random failures caused by specific component failures, which can be quantified and systematic failures, which cannot be quantified. The safety life cycle consists of top-down and bottom-up processes. Top-down stages are hazard and risk analysis involving the quantified risk assessment, system/subsystem/equipment safety requirement specifications and allocations. For electronic equipment, both hardware and software safety requirement specification and analysis are to be verified and validated. Bottom-up stages are equipment/subsystem/system integration and integration and validation. Documented hazard analysis activities are of two types—discrete hazard analysis levels like preliminary, system, subsystem and assets manufacturing. There are some continuous activities like system verification and validation before asset installation and hazard log maintenance, safety audit and safety assurance after installation. Electronic systems must have third party Independent Safety Assessment (ISA). Human errors must be considered in safety analysis. Hazard analysis activities are identification based on continuously updated checklists, severity assessment and mitigation plans. Manufacturers must provide Safety Case documents and full failure mode effect and criticality analysis reports before supplying. Quantified fault tree analysis from past failure reports of installed systems, in depth component failure mode effect analysis and compliance to domain specific international safety standards, help in better design and maintenance of safety–critical systems.