LNCS 2788 Using IEC 61508 to Guide the
Investigation of Computer Related Incidents and
Accidents 1st Edition by Chris Johnson ISBN
3540398783 9783540398783 pdf download
https://ebookball.com/product/lncs-2788-using-iec-61508-to-guide-
the-investigation-of-computer-related-incidents-and-
accidents-1st-edition-by-chris-johnson-
isbn-3540398783-9783540398783-12290/
Explore and download more ebooks or textbooks
at ebookball.com
, Get Your Digital Files Instantly: PDF, ePub, MOBI and More
Quick Digital Downloads: PDF, ePub, MOBI and Other Formats
LNCS 2788 Software Tamper Resistance Using Program Certificates 1st
Edition by Hongxia Jin, Gregory Sullivan, Gerald Masson ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-software-tamper-
resistance-using-program-certificates-1st-edition-by-hongxia-jin-
gregory-sullivan-gerald-masson-
isbn-3540398783-9783540398783-9638/
LNCS 2788 Visual Modeling and Verification of Distributed Reactive
Systems 1st Edition by Iqbal, AK Bhattacharjee, SD Dhodapkar, Ramesh
ISBN 3540398783 9783540398783
https://ebookball.com/product/lncs-2788-visual-modeling-and-
verification-of-distributed-reactive-systems-1st-edition-by-
iqbal-ak-bhattacharjee-sd-dhodapkar-ramesh-
isbn-3540398783-9783540398783-14518/
LNCS 2788 Automatic Timeliness Verification of a Public Mobile
Network 1st Edition by Ciancamerla, Minichino, Serro, Tronci ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-automatic-timeliness-
verification-of-a-public-mobile-network-1st-edition-by-
ciancamerla-minichino-serro-tronci-
isbn-3540398783-9783540398783-10904/
LNCS 2788 Critical Feature Analysis of a Radiotherapy Machine 1st
Edition by Andrew Rae, Daniel Jackson, Prasad Ramanan, Jay Flanz,
Didier Leyman ISBN 3540398783 9783540398783
https://ebookball.com/product/lncs-2788-critical-feature-
analysis-of-a-radiotherapy-machine-1st-edition-by-andrew-rae-
daniel-jackson-prasad-ramanan-jay-flanz-didier-leyman-
isbn-3540398783-9783540398783-14498/
,LNCS 2788 Security Policy Configuration Issues in Grid Computing
Environments 1st Edition by George Angelis, Stefanos Gritzalis, Costas
Lambrinoudakis ISBN 3540398783 9783540398783
https://ebookball.com/product/lncs-2788-security-policy-
configuration-issues-in-grid-computing-environments-1st-edition-
by-george-angelis-stefanos-gritzalis-costas-lambrinoudakis-
isbn-3540398783-9783540398783-10174/
LNCS 2788 A Dependability Model for Domestic Systems 1st Edition by
Guy Dewsbury, Ian Sommerville, Karen Clarke, Mark Rouncefield ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-a-dependability-model-
for-domestic-systems-1st-edition-by-guy-dewsbury-ian-sommerville-
karen-clarke-mark-rouncefield-
isbn-3540398783-9783540398783-10176/
LNCS 2788 Fault Tolerant Communication System to Improve Safety in
Railway Environments 1st Edition by César Mataix, Pedro MartÃ-n,
Francisco Javier RodrÃ-guez, MarÃ-a José Manzano, Javier Pozo ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-fault-tolerant-
communication-system-to-improve-safety-in-railway-
environments-1st-edition-by-ca-c-sar-mataix-pedro-martan-
francisco-javier-rodraguez-maraa-josa-c-manzano-javier-pozo-
isbn-354/
Introduction To 80 86 Assembly Language And Computer Architecture 1st
Edition by Detmer ISBN 0763717738 9780763717735
https://ebookball.com/product/introduction-to-80-86-assembly-
language-and-computer-architecture-1st-edition-by-detmer-
isbn-0763717738-9780763717735-12404/
Introduction to 80 86 Assembly Language and Computer Architecture 1st
Edition by Richard C Detmer ISBN 0763746622 9780763746629
https://ebookball.com/product/introduction-to-80-86-assembly-
language-and-computer-architecture-1st-edition-by-richard-c-
detmer-isbn-0763746622-9780763746629-9016/
, Using IEC 61508 to Guide the Investigation of
Computer-Related Incidents and Accidents
Chris Johnson
Dept. of Computing Science, University of Glasgow, Glasgow, G12 9QQ
Tel.: +44 141 330 6053, Fax: +44 141 330 4913
MRKQVRQ#GFVJODDFXN
Abstract. Relatively few investigation techniques have been specifically
developed to identify the causal factors that contribute to mishaps involving
safety-critical computer systems. The following pages, therefore, presents two
complementary investigation techniques that are intended to support the
analysis of Electrical, Electronic or Programmable, Electronic Systems
(E/E/PES)-related mishaps. One is intended to provide a low-cost and
lightweight approach that is appropriate for low consequence events. It is based
around a flowchart that prompts investigators to identify potential causal factors
through a series of questions about the events leading to a failure and the
context in which they occurred. The second approach is more complex. It
involves additional documentation and analysis. It is, therefore, more
appropriate for incidents that have greater potential consequences or a higher
likelihood of recurrence. This approach uses Events and Causal Factors (ECF)
modelling promoted by the US Department of Energy (1992). Both approaches
provide means of mapping causal factors back to the lifecycle phases and
common requirements described in the IEC 61508 standard. This provides an
important bridge from the products of mishap analysis to the design and
operation of future systems. The UK Health and Safety Executive sponsored
this work as part of an initiative to develop analysis techniques for E/E/PES
related incidents. The events leading to an explosion and fires in a fractional
distillation unit are used to illustrate the application of our techniques. Our
techniques are likely to identify incidents that cannot easily be attributed to
lifecycle phases or common requirements in IEC 61508. The link between
constructive design standards and analytical investigation techniques can,
therefore, yield insights into the limitations of these standards. An implicit
motivation in our work is to provide the feedback mechanisms that are
necessary to improve the application of standards, such as IEC 61508 and DO-
178B.
1 Introduction
Very few accident analysis techniques support the investigation of adverse events
involving programmable systems. There are some notable exceptions, including
Leveson’s (2002) STAMP and the Why-Because Analysis proposed by Ladkin and
Loer (1998). Unfortunately, these techniques provide limited support for the
generation of recommendations. They say little about possible intervention in the
S. Anderson et al. (Eds.): SAFECOMP 2003, LNCS 2788, pp. 410–423, 2003.
© Springer-Verlag Berlin Heidelberg 2003
Investigation of Computer Related Incidents and
Accidents 1st Edition by Chris Johnson ISBN
3540398783 9783540398783 pdf download
https://ebookball.com/product/lncs-2788-using-iec-61508-to-guide-
the-investigation-of-computer-related-incidents-and-
accidents-1st-edition-by-chris-johnson-
isbn-3540398783-9783540398783-12290/
Explore and download more ebooks or textbooks
at ebookball.com
, Get Your Digital Files Instantly: PDF, ePub, MOBI and More
Quick Digital Downloads: PDF, ePub, MOBI and Other Formats
LNCS 2788 Software Tamper Resistance Using Program Certificates 1st
Edition by Hongxia Jin, Gregory Sullivan, Gerald Masson ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-software-tamper-
resistance-using-program-certificates-1st-edition-by-hongxia-jin-
gregory-sullivan-gerald-masson-
isbn-3540398783-9783540398783-9638/
LNCS 2788 Visual Modeling and Verification of Distributed Reactive
Systems 1st Edition by Iqbal, AK Bhattacharjee, SD Dhodapkar, Ramesh
ISBN 3540398783 9783540398783
https://ebookball.com/product/lncs-2788-visual-modeling-and-
verification-of-distributed-reactive-systems-1st-edition-by-
iqbal-ak-bhattacharjee-sd-dhodapkar-ramesh-
isbn-3540398783-9783540398783-14518/
LNCS 2788 Automatic Timeliness Verification of a Public Mobile
Network 1st Edition by Ciancamerla, Minichino, Serro, Tronci ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-automatic-timeliness-
verification-of-a-public-mobile-network-1st-edition-by-
ciancamerla-minichino-serro-tronci-
isbn-3540398783-9783540398783-10904/
LNCS 2788 Critical Feature Analysis of a Radiotherapy Machine 1st
Edition by Andrew Rae, Daniel Jackson, Prasad Ramanan, Jay Flanz,
Didier Leyman ISBN 3540398783 9783540398783
https://ebookball.com/product/lncs-2788-critical-feature-
analysis-of-a-radiotherapy-machine-1st-edition-by-andrew-rae-
daniel-jackson-prasad-ramanan-jay-flanz-didier-leyman-
isbn-3540398783-9783540398783-14498/
,LNCS 2788 Security Policy Configuration Issues in Grid Computing
Environments 1st Edition by George Angelis, Stefanos Gritzalis, Costas
Lambrinoudakis ISBN 3540398783 9783540398783
https://ebookball.com/product/lncs-2788-security-policy-
configuration-issues-in-grid-computing-environments-1st-edition-
by-george-angelis-stefanos-gritzalis-costas-lambrinoudakis-
isbn-3540398783-9783540398783-10174/
LNCS 2788 A Dependability Model for Domestic Systems 1st Edition by
Guy Dewsbury, Ian Sommerville, Karen Clarke, Mark Rouncefield ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-a-dependability-model-
for-domestic-systems-1st-edition-by-guy-dewsbury-ian-sommerville-
karen-clarke-mark-rouncefield-
isbn-3540398783-9783540398783-10176/
LNCS 2788 Fault Tolerant Communication System to Improve Safety in
Railway Environments 1st Edition by César Mataix, Pedro MartÃ-n,
Francisco Javier RodrÃ-guez, MarÃ-a José Manzano, Javier Pozo ISBN
3540398783 9783540398783
https://ebookball.com/product/lncs-2788-fault-tolerant-
communication-system-to-improve-safety-in-railway-
environments-1st-edition-by-ca-c-sar-mataix-pedro-martan-
francisco-javier-rodraguez-maraa-josa-c-manzano-javier-pozo-
isbn-354/
Introduction To 80 86 Assembly Language And Computer Architecture 1st
Edition by Detmer ISBN 0763717738 9780763717735
https://ebookball.com/product/introduction-to-80-86-assembly-
language-and-computer-architecture-1st-edition-by-detmer-
isbn-0763717738-9780763717735-12404/
Introduction to 80 86 Assembly Language and Computer Architecture 1st
Edition by Richard C Detmer ISBN 0763746622 9780763746629
https://ebookball.com/product/introduction-to-80-86-assembly-
language-and-computer-architecture-1st-edition-by-richard-c-
detmer-isbn-0763746622-9780763746629-9016/
, Using IEC 61508 to Guide the Investigation of
Computer-Related Incidents and Accidents
Chris Johnson
Dept. of Computing Science, University of Glasgow, Glasgow, G12 9QQ
Tel.: +44 141 330 6053, Fax: +44 141 330 4913
MRKQVRQ#GFVJODDFXN
Abstract. Relatively few investigation techniques have been specifically
developed to identify the causal factors that contribute to mishaps involving
safety-critical computer systems. The following pages, therefore, presents two
complementary investigation techniques that are intended to support the
analysis of Electrical, Electronic or Programmable, Electronic Systems
(E/E/PES)-related mishaps. One is intended to provide a low-cost and
lightweight approach that is appropriate for low consequence events. It is based
around a flowchart that prompts investigators to identify potential causal factors
through a series of questions about the events leading to a failure and the
context in which they occurred. The second approach is more complex. It
involves additional documentation and analysis. It is, therefore, more
appropriate for incidents that have greater potential consequences or a higher
likelihood of recurrence. This approach uses Events and Causal Factors (ECF)
modelling promoted by the US Department of Energy (1992). Both approaches
provide means of mapping causal factors back to the lifecycle phases and
common requirements described in the IEC 61508 standard. This provides an
important bridge from the products of mishap analysis to the design and
operation of future systems. The UK Health and Safety Executive sponsored
this work as part of an initiative to develop analysis techniques for E/E/PES
related incidents. The events leading to an explosion and fires in a fractional
distillation unit are used to illustrate the application of our techniques. Our
techniques are likely to identify incidents that cannot easily be attributed to
lifecycle phases or common requirements in IEC 61508. The link between
constructive design standards and analytical investigation techniques can,
therefore, yield insights into the limitations of these standards. An implicit
motivation in our work is to provide the feedback mechanisms that are
necessary to improve the application of standards, such as IEC 61508 and DO-
178B.
1 Introduction
Very few accident analysis techniques support the investigation of adverse events
involving programmable systems. There are some notable exceptions, including
Leveson’s (2002) STAMP and the Why-Because Analysis proposed by Ladkin and
Loer (1998). Unfortunately, these techniques provide limited support for the
generation of recommendations. They say little about possible intervention in the
S. Anderson et al. (Eds.): SAFECOMP 2003, LNCS 2788, pp. 410–423, 2003.
© Springer-Verlag Berlin Heidelberg 2003