CAST Analysis. 2013 John Thomas and Nancy Leveson. All rights reserved.



Similar documents
Safety in Management John Thomas and Nancy Leveson. All rights reserved.

On-Site Risk Management Audit Checklist for Program Level 3 Process

Introduction to system safety and risk management in complex systems. Dr. John Thomas Massachusetts Institute of Technology

Investigating Safety and Cybersecurity Design Tradespace for Manned-Unmanned Aerial Systems Integration Using Systems Theoretic Process Analysis

System Theoretic Approach To Cybersecurity

SAFETY LIFE-CYCLE HOW TO IMPLEMENT A

Aviation Safety: Making a safe system even safer. Nancy Graham Director, Air Navigation Bureau International Civil Aviation Organization

Academy of Model Aeronautics. Requirements for the Operation of Remote Control (RC) Aircraft at Full Scale Airshows

AIRCRAFT RESCUE AND FIREFIGHTING

Safety and Security Driven Design. Unmanned Aircraft-National Airspace System Integration Case Study

Basic Fundamentals Of Safety Instrumented Systems

Operational Reactor Safety /22.903

Dynamic Behavior of BWR

Process Safety Management of Highly Hazardous & Explosive Chemicals. Management of Change

SHE Standards. Safety, Health and Environmental Protection Standards

Routine and Emergency Boiler Operation

University of Paderborn Software Engineering Group II-25. Dr. Holger Giese. University of Paderborn Software Engineering Group. External facilities

Why Process Safety Management Audits Fail?

> THE SEVEN GREATEST THREATS TO PROCESS PLANT > WHAT S INSIDE: SAFETY, AND HOW TO MANAGE THEM WHITE PAPER

E3211. DOT Hazmat Security Awareness. Leader s Guide

Truck Automation for the Ready Mixed Concrete Industry. Michael J. Hoagland (205) ext

Preventing Overheated Boiler Incidents

Using Incident Investigation Tools Proactively for Incident Prevention.

A Comprehensive Safety Engineering Approach for Software Intensive Systems based on STPA

Revised April (May) 2015

ASSESSMENT OF THE ISO STANDARD, ROAD VEHICLES FUNCTIONAL SAFETY

The case for rail transportation of hazardous materials

FACILITY FIRE PREVENTION AND EMERGENCY PREPAREDNESS INSPECTION CHECKLIST

Safe management of industrial steam and hot water boilers A guide for owners, managers and supervisors of boilers, boiler houses and boiler plant

For the purpose of see-and-avoid, visual observers must be utilized at all times

"DOT IN-DEPTH HAZMAT SECURITY TRAINING"

The introduction covers the recent changes is security threats and the effect those changes have on how we protect systems.

AUDIT REPORT. Materials System Inventory Management Practices at Washington River Protection Solutions

DC400 Dispensing Cutoff System

FAA s Progress and Challenges in Integrating Unmanned Aircraft Systems into the National Airspace System

Usability does the system meet user needs & operate within their capabilities;

SIS Smart SIS 15 minutes

Bradlee Boilers Ltd. Instruction Manual for starting up Bradlee Hire Boiler from Cold

Confined spaces can be deadly. What is a confined space?

DOT HAZMAT SECURITY AWARENESS TRAINING

MD 52 WASTE MANAGEMENT AUTHORITY CORPORATE HEALTH AND SAFETY PROGRAM

Government Degree on the Safety of Nuclear Power Plants 717/2013

Safety Requirements Specification Guideline

Unmanned Aircraft Systems (UAS)

3088 Lockout-Tagout Training Program Course Outline

The Steelworker Perspective on Behavioral Safety

LOCKOUT GUIDELINE. To ensure that a piece of equipment cannot be turned on, pressurized or switched on accidently while an employee is working on it.

Alarm Management Standards Are You Taking Them Seriously?

Developing System-Based Leading Indicators for Proactive Risk Management in the Chemical Processing Industry. Ibrahim A. Khawaji

Safety Management System

SDA R-0001 Residential Alarms Systems Copenhagen, Denmark QUESTIONS & ANSWERS

Safety Management Challenges for Aviation Cyber Physical Systems

Control of Hazardous Energy LOCKOUT/TAGOUT 29 CFR

Asset Integrity - Process Safety Management

ISRS. For the health of your business SAFER, SMARTER, GREENER

Guidance on Safe Operation of Boilers

Hospital Heliport Inspection Basics

Management of Change: Addressing Today s Challenge on Documenting the Changes

Management of change at a major hazard facility

Chapter 34 Ambulance Operations. DOT Directory Limmer et al., Emergency Care, 11th Edition 2009 by Pearson Education, Inc., Upper Saddle River, NJ

ISA108 Intelligent Device Management (IDM)

Software Safety Basics

Nonroad SCR Certification

Alfa Laval PureBallast 3.1

Improving safety through accident investigation: An NTSB perspective Robert Sumwalt

The Role of Automation Systems in Management of Change

WATER SUPPLY SYSTEMS FOR 150/5220-4B AAS-100 AIRCRAFT FIRE AND RESCUE PROTECTION

HUMAN FACTORS STUDIES OF AN ADS-B BASED TRAFFIC ALERTING SYSTEM FOR GENERAL AVIATION

ENVIRONMENTAL HEALTH AND SAFETY. Fire Protection System Impairment Procedure

Process Safety Management Program

Connected Aircraft Cockpit and Maintenance Process Improvements Panel

Selecting Sensors for Safety Instrumented Systems per IEC (ISA )

Tank Gauging & Inventory Management Solutions

Explosives Safety Initial Training. Course # 5.01 Rev TO

U.S. DEPARTMENT OF TRANSPORTATION FEDERAL AVIATION ADMINISTRATION. Air Traffic Organization Policy

Safety Driven Design with UML and STPA M. Rejzek, S. Krauss, Ch. Hilbes. Fourth STAMP Workshop, March 23-26, 2015, MIT Boston

Six steps to Occupational Health and Safety

Industry and government have increased their efforts to prevent major chemical accidents. But CSB investigations show that much more needs to be done

DISCRETE EVENT SIMULATION IN THE DESIGN, LAYOUT AND SCHEDULING OF PIPELESS BATCH PLANTS

Process Safety Management of Highly Hazardous & Explosive Chemicals. Application, Exclusions & Definitions

IMPLEMENTATION OF PROCESS SAFETY MANAGEMENT (PSM) IN CAPITAL PROJECTS

AC REUSABLE SOFTWARE COMPONENTS

TANKER - SHORE SAFETY CHECK-LIST

Version: 1.0 Last Edited: Guideline

Plantcom s. Fleet Management. solutions are your competitive advantage. plantcom.com.au. l

CHECKLIST FOR APRON OPERATIONS INSPECTION

2. System Based Design Descriptions and ITAAC AP1000 Design Control Document

COST BENEFIT ANALYSIS

Liberty Mutual Insurance RISK ENGINEERING PROCEDURE. REP 07 Incident Planning For external use

USER MANUAL OPERATION AND USE OF CAR WITH. Diego G3 / NEVO SEQUENTIAL GAS INJECTION SYSTEM

Emergency Response Planning. Construction Projects

Based on the initial size-up and any information available, Command will formulate an action plan to deal with the situation.

Safety critical communication. Overview. Communication. Andy Brazier

Understanding the task

Background on Airspace

Transcription:

CAST Analysis 1

CAST Process Identify the Accident (Loss) Identify the Hazards Identify the Safety Constraints Identify the Proximal Events Draw the Safety Control Structure Analyze each component 2

CAST Process Identify the Accident (Loss) Identify the Hazards Identify the Safety Constraints Identify the Proximal Events Draw the Safety Control Structure Analyze each component 3

CAST Process Identify the Accident (Loss) Identify the Hazards Identify the Safety Constraints Identify the Proximal Events Draw the Safety Control Structure Analyze each component 4

Basic Control Loop Controller Process Model Control Actions Feedback Controlled Process 5

Safety Control Structure ESW p354 From Leveson, Nancy (2012). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Massachusetts Institute of Technology. Used with permission. 6

From Leveson, Nancy (2012). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Massachusetts Institute of Technology. Used with permission. ESW p206: U.S. pharmaceutical safety control structure 7

Example High-level control structure Congress Directives, funding Reports FAA Regulations, procedures Reports ATC Instructions Acknowledgement, requests Pilots Execute maneuvers Aircraft status, position, etc Aircraft 8

Air Traffic Control (ATC) ATC Front Line Manager (FLM) Instructions Status Updates Instructions Status Updates Instructions Status Updates Instructions Company Dispatch Status Updates Instructions ATC Ground Controller Query Status Updates and acknowledgements ATC Radio Other Ground Controllers Execute maneuvers Pilots Pilots Pilots Pilots Aircraft Execute maneuvers Aircraft Execute maneuvers Aircraft Execute maneuvers Aircraft ACARS Text Messages 9

ESW p216: Ballistic Missile Defense System 10 From Leveson, Nancy (2012). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Massachusetts Institute of Technology. Used with permission.

CAST Process Identify the Accident (Loss) Identify the Hazards Identify the Safety Constraints Identify the Proximal Events Draw the Safety Control Structure Analyze each component Physical System Controllers 11

Analyze physical system Responsibilities (safety constraints)? Emergency and Safety Equipment (controls)? Failures and inadequate controls? Contextual Factors? Physical System From Leveson, Nancy (2012). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Massachusetts Institute of Technology. Used with permission. 12

Analyze physical system Responsibilities (safety constraints) Prevent runaway reactions Prevent inadvertent release of toxic chemicals or explosion Convert released chemicals into a nonhazardous of less hazardous form Provide indicators (alarms) of the existence of hazardous conditions Emergency and Safety Equipment (controls) Air monitors Windsock Pressure relief system Process sensors, gauges and indicators Spare tank 13

Analyze physical system (cont) Failures and Inadequate Controls Inadequate protection against water getting into tanks Inadequate monitoring of chemical process: Gauges were missing or inoperable Inadequate emergency relief system (jammed, valves too small, lines too small) Contextual Factors The plant was built in a remote location 30 years ago so it would have a buffer area around it, but the city grew closer over the years Approximately 24 different chemical products are manufactured at Oakbridge, most of which are toxic to humans and some very toxic At the time of the start of the accident proximal events, Unit 7 was shut down and was not being used. It was restarted to provide extra K34 The plant already was operating at capacity before the decision to increase production of K34 14

Analyze controllers Operations Manager Software systems Maintenance Manager/Worker Plant Manager Corporate Management Etc. Controllers From Leveson, Nancy (2012). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Massachusetts Institute of Technology. Used with permission. 15

Analyze Controller: Operations Manager Safety-related responsibilities? Unsafe Decisions and Control actions? Process model flaws? Context? 16

Analyze Controller: Operations Manager Safety-related responsibilities Develop operating procedures that adequately control hazards Provide operator training on plant hazards and safe operating procedures. Audit to ensure training is effective Oversee operations to ensure that policies and procedures are being followed Unsafe Decisions and Control actions Decides to take level gauge from tank 702 and put it on 701; runs unit 7 without a level gauge on 702. Ignores concerns by operators about operating a tank with no gauge Agrees to or makes changes without thoroughly analyzing hazards involved Agrees to start unit 7 in ten days knowing he does not have the personnel to do a thorough inspection and adequate startup activities 17

Analyze Controller: Operations Manager (cont) Process model flaws Thinks tank 702 is empty. Does not know that water was found by maintenance in tank 701. Inaccurate assessment of likelihood of having to use Tank 702 Like the others, most likely does not understand the limitations of the design of the safety equipment Context Under same performance pressures as everyone else No organization responsible for safety analyses and risk assessments Understaffed 18

A note about Unsafe Control Actions vs. Hazards Hazards Generally should not name a specific component Should describe general behavior of the system (aircraft, train, space vehicle, chemical plant, etc.) Unsafe Control Actions (UCAs) Describe behavior of a specific component (pilot, manager, software automation, etc.) Cause system-level hazards 19

MIT OpenCourseWare http://ocw.mit.edu 16.63J / ESD.03J System Safety Fall 2012 For information about citing these materials or our Terms of Use, visit: http://ocw.mit.edu/terms.