A systematic approach to safety case maintenance

被引:37
作者
Kelly, TP [1 ]
McDermid, JA [1 ]
机构
[1] Univ York, Dept Comp Sci, York YO10 5DD, N Yorkshire, England
关键词
safety case; maintenance; impact analysis; certification; change management; safety requirements;
D O I
10.1016/S0951-8320(00)00079-X
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
A crucial aspect of safety case management is the ongoing maintenance of the safety argument through life. Throughout the operational life of any system, changing regulatory requirements, additional safety evidence and a changing design can challenge the corresponding safety case. In order to maintain an accurate account of the safety of the system, all such challenges must be assessed for their impact on the original safety argument. This is increasingly being recognised by many safety standards. However, many safety engineers are experiencing difficulties with safety case maintenance at present, the prime reason being that they do not have a systematic and methodical approach by which to examine the impact of change on safety argument. The size and complexity of safety arguments and evidence being presented within safety cases is increasing. Nowhere is this more apparent than for Electrical, Electronic and Programmable Electronic systems attempting to comply with the requirements and recommendations of software and hardware safety standards such as IEC 61508 [Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems. International Electrotechnical Commission, Draft Standard, 1997] and UK Defence Standards 00-54 [MoD. 00-54 Requirements of Safety Related Electronic Hardware in Defence Equipment. Ministry of Defence, Interim Defence Standard, 1999], 00-55 [MoD. 00-55 Requirements of Safety Related Software in Defence Equipment. Ministry of Defence, Defence Standard, 1997], and 00-56 [MoD. 00-56 Safety Management Requirements for Defence Systems. Ministry of Defence, Defence Standard, 1996]. However, this increase ill safety case complexity exacerbates problems of comprehension and maintainability later on in the system lifecycle. This paper defines and describes a tool-supported process, based upon the principles of goal structuring, that attempts to address these difficulties through facilitating the systematic impact assessment of safety case challenges. (C) 2001 Elsevier Science Ltd. All rights reserved.
引用
收藏
页码:271 / 284
页数:14
相关论文
共 13 条
[1]  
[Anonymous], 1996, 0056 MOD
[2]  
BISHOP P, 1998, ADELARD SAFETY CASE
[3]  
CLARKE AW, 1989, NUCL ENERG-J BR NUCL, V28, P215
[4]  
FIELD M, 1987, PROJECT MANAGEMENT P
[5]  
Hogberg L., 1994, Nuclear Europe Worldscan, V14, P42
[6]  
HSE (Health and Safety Executive), 1992, SAF ASS PRINC NUCL P
[7]  
*IEC, 1997, 61508 IEC
[8]  
*JAA, 1990, JOINT AIRW REQ JAR E
[9]  
KELLY TP, 1997, P 16 INT C COMP SAF
[10]  
*MOD, 1999, 0054 MOD