The hazard analysis is a key document for safety critical systems as it combines the description of the hazards, the
level of risk, system faults that can lead to the hazard, and the control measures all together in a single view. The
Fault is a non-compliance of the system that can lead to the identified hazard. The severity is a measure of how bad
the hazard is (an arbitrary scale of 1-10 is used often used). The Risk is a value computed by the likelihood
multiplied by the severity of the occurrence. This task keeps the hazard analysis up to date, re-performing fault tree
and failure modes and effect analyses as appropriate.
Reliability analyses are often maintained in Fault Means Effect Analyses. As technology decisions are made, this can
impact the reliabilty of the system and availability of services. These analyses must reflect actual reliability
numbers are development progresses.
Security analyses are represented in many ways, but a threat assessment or threat analysis document or model is most
common. These analyzes identify the assets requiring protection, their vulnerabilities, and the countermeasures put
into place to protect them. These analyses must also be kept up to date.
|