220 likes | 425 Vues
Purpose of the Assessment. Safety Impact Assessment Purpose. Demonstrate that the Digital SNOWTAM infrastructure is providing a satisfactory service to the users involved The test facility fulfils its intended function It is acceptably safe. Overall Safety Argument in GSN*.
E N D
Safety Impact Assessment Purpose • Demonstrate that the Digital SNOWTAM infrastructure is providing a satisfactory service to the users involved • The test facility fulfils its intended function • It is acceptably safe SNOWTAM Trial Safety Impact Assessment
Overall Safety Argument in GSN* ‘Success’ approach Normal operations ‘Failure’ approach Failure modes GSN: Goal Structuring Notation SNOWTAM Trial Safety Impact Assessment
Intended Functions Operations Specification Implementation Design Safety ‘coverage’ of the V-cycle Arg2: Failure Mode(failure approach) Arg1: Nominal Mod (success approach) SNOWTAM Trial Safety Impact Assessment
Users and Intended Functions SNOWTAM Trial Safety Impact Assessment
System Fulfils its Intended Functions Test infrastructure fulfils intended functions How to help the Safety Expert checking this? Traceability Specification Design Implementation Operation SNOWTAM Trial Safety Impact Assessment
Specifications (*) Table partially reproduced SNOWTAM Trial Safety Impact Assessment
Design SNOWTAM Trial Safety Impact Assessment
System is Acceptably Safe Check safety requirements are covered Hazard analysis ▼ Safety requirements SNOWTAM Trial Safety Impact Assessment
Simplified process Hazard analysis Mitigation means Safety requirements Specification, Design Test infrastructure, Operations SNOWTAM Trial Safety Impact Assessment
Identified Hazards SNOWTAM Trial Safety Impact Assessment
Mitigation means => Safety Requirements (*) Table partially reproduced SNOWTAM Trial Safety Impact Assessment
Checking coverage of safety requirements (*) Table partially reproduced SNOWTAM Trial Safety Impact Assessment
Caveats - Assumptions - Outstanding Issues Digital SNOWTAM performances depend on the availability and the quality of some external data as the SNOWTAM information itself and some static aeronautical information (e.g. airport layout) - Limitations The real effectiveness for most of the Safety Requirements mainly depends on each user and their awareness on the use they can do of Digital SNOWTAM infrastructure SNOWTAM Trial Safety Impact Assessment
Assessment Conclusions - The proposed Digital SNOWTAM infrastructure fulfils the intended functions for the Digital SNOWTAM trial. - There is no impact on real ATM related operations while using Digital SNOWTAM infrastructure during the trial. SNOWTAM Trial Safety Impact Assessment
Developer’s ‘mantras’ - Integrate safety aspects in your development as soon as possible - Traceability SNOWTAM Trial Safety Impact Assessment