Massachusetts Institute of Technology
A framework for dynamic safety and risk management modeling in complex engineering systems
Abstract
dc:description.abstractAlmost all traditional hazard analysis or risk assessment techniques, such as failure modes and effect analysis (FMEA), fault tree analysis (FTA), and probabilistic risk analysis (PRA) rely on a chain-of-event paradigm of accident causation. Event-based techniques have some limitations for the study of modem engineering systems. Specifically, they are not suited to handle complex software-intensive systems, complex human-machine interactions, and systems-of-systems with distributed decision-making that cut across both physical and organizational boundaries. STAMP (System-Theoretic Accident Model and Processes) is a comprehensive accident model created by Nancy Leveson that is based on systems theory. It draws on concepts from engineering, mathematics, cognitive and social psychology, organizational theory, political science, and economics. The general notion in STAMP is that accidents result from inadequate enforcement of safety constraints in design, development, and operation. STAMP includes traditional failure-based models as a subset, but goes beyond physical failures to include causal factors involving dysfunctional interactions among non-failing components; software and logic design errors; errors in complex human decision-making; various organizational characteristics such as workforce, safety processes and standards, contracting; and other managerial, social, organizational, and cultural factors. The main contribution of this thesis is the augmentation of STAMP with a dynamic executable modeling framework in order to further improve safety in the development and operation of complex engineering systems. This executable modeling framework: 1) enables the dynamic analysis of safety-related decision-making in complex systems, 2) assists with the design and testing of non-intuitive policies and processes to better mitigate risks and prevent time-dependent risk increase, and 3) enables the identification of technical and organizational factors to detect and monitor states of increasing risk before an accident occurs.
Degree
thesis:*- Department dc:contributor.department
- Massachusetts Institute of Technology. Dept. of Aeronautics and Astronautics.
- Grantor dc:publisher
- Massachusetts Institute of Technology
- Year dc:date.issued
- 2007
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Dulac, Nicolas, 1978-
- Advisor dc:contributor.advisor
-
- Nancy G. Leveson, Deborah Nightingale and Nelson P. Repenning.
Subjects
dc:subject × 1Rights
dc:rights- Statement dc:rights
-
- M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.
- Licence dc:rights.uri
- Language dc:language.iso
- eng
Identifiers
dc:identifier.*- Identifier URI
- http://dspace.mit.edu/handle/1721.1/42175
- OAI identifier oai:identifier
- oai:dspace.mit.edu:1721.1/42175