Transcription of NANCY G. LEVESON JOHN P. THOMAS
1 1 NANCY G. LEVESON JOHN P. THOMAS MARCH 2018 This handbook is intended for those interested in using STPA on real systems. It is not meant to introduce the theoretical foundation, which is described elsewhere. Here our goal is to provide direction for those starting out with STPA on a real project or to supplement other materials in a class teaching STPA. COPYRIGHT 2018 BY NANCY LEVESON AND JOHN THOMAS . ALL RIGHTS RESERVED. THE UNALTERED VERSION OF THIS handbook AND ITS CONTENTS MAY BE USED FOR NON-PROFIT CLASSES AND OTHER NON-COMMERCIAL PURPOSES BUT MAY NOT BE SOLD.
2 2 TABLE OF CONTENTS Preface 3 1. Introduction 4 2. How to do Basic STPA 14 3. Integrating STPA into Your System Engineering Process 54 4. Workplace Safety 72 5. Organizational and Social Analysis 86 6. Identifying Leading Indicators of Risk 101 7. Designing an Effective Safety Management System 116 8. Integrating STPA into a Large Organization 142 Appendix A: Examples of hazards 146 Appendix B: Examples of control structures 148 Appendix C: Examples of UCA tables 156 Appendix D: Guidelines for designing and evaluating a safety 163 management system Appendix E: More about why decomposition does not work for 167 complex, computer-based systems Appendix F.
3 Basic engineering and system engineering concepts for 169 non- engineers Appendix G: A new model to assist in causal scenario generation 178 Acknowledgements: Many people provided comments on early drafts of this handbook . We want to thank them for their help, including (alphabetically) Matthew Boesch (Ford), Diogo Silva Castilho (MIT and Brazilian Air Force), Christopher Degni (Akamai), Mikela Chatzimichailidou (Imperial College), Rashmi Hegde (Ford), Stephen Johnson (Fluor), Ioana Koglbauer (University of Graz), Galvani Lacerda (Embraer), Simon Lucchini (Fluor), Shem Malquist (FedEx), Maj.
4 Dan Montes ( Air Force), Sandro Nuesch (Ford), Felipe Oliveira (Embraer), Todd Pawlicki ( San Diego Medical Center), Kep Peterson (Akamai), Martin Rezjek (Zurich University of Applied Sciences), Lori Smith (Boeing), Michael Stone (Akamai), Maj. Sarah Summers ( Air Force), Mark Vernacchia (General Motors), Sarra Yako (Ford), Col. William Young ( Air Force), and members of the National Cyber Security Centre. 3 Preface This handbook is intended to assist those who want to start using STPA or who want to try using it for more than simple hazard analysis.
5 As such, we tried to provide examples and have included more examples in the appendices. An appendix is also provided to explain some basic engineering concepts needed to understand and use the handbook to those who are not trained in engineering. Other new concepts are introduced in the main chapters of the handbook itself. The introduction provides a brief introduction to STAMP, the accident causality model underlying STPA. It also shows examples accidents and explains why STPA is needed for today s complex, software-intensive systems.
6 The next chapter is an in-depth tutorial on how to perform STPA. It will be useful for the beginner as well as for those who have tried STPA and want to improve their results. The rest of the handbook describes uses for STPA, including how to integrate it into a standard system engineering process, its use in workplace safety, using STPA for organizational analysis and emergent system properties other than safety, using STPA to provide leading indicators of increasing risk, designing an effective safety management system, and cyber security.
7 The final chapter describes what we have learned about integrating STPA into a large organization and how to structure the STPA process to make it most effective but also least disruptive to the enterprise. Our goal in writing this handbook is to provide a guide for those who are actually using STPA rather than writing an academic primer. Therefore, we have omitted references to other work, etc. There are many other sources that provide this type of information but few that focus on instruction and ways to use STPA. To find many examples, published papers, theses, etc.
8 , see We encourage users of the handbook to work on examples relevant to their industry as they go through the handbook . 4 Chapter 1: Introduction NANCY LEVESON STPA (System-Theoretic Process Analysis) is a relatively new hazard analysis technique based on an extended model of accident causation. In addition to component failures, STPA assumes that accidents can also be caused by unsafe interactions of system components, none of which may have failed. Some of the advantages of STPA over traditional hazard/risk analysis techniques are that: Very complex systems can be analyzed.
9 Unknown unknowns that were previously only found in operations can be identified early in the development process and either eliminated or mitigated. Both intended and unintended functionality are handled. Unlike the traditional hazard analysis methods, STPA can be started in early concept analysis to assist in identifying safety requirements and constraints. These can then be used to design safety (and security) into the system architecture and design, eliminating the costly rework involved when design flaws are identified late in development or during operations.
10 As the design is refined and more detailed design decisions are made, the STPA analysis is also refined to help make more and more detailed design decisions. Complete traceability from requirements to all system artifacts can be easily maintained, enhancing system maintainability and evolution. STPA includes software and human operators in the analysis, ensuring that the hazard analysis includes all potential causal factors in losses. STPA provides documentation of system functionality that is often missing or difficult to find in large, complex systems.