Abstract. Studies about the sources of critical accidents in operating human-made systems indicate that most of them are commonly attributed to errors made by the human operators. These findings motivated the development of a guide for designing and developing systems which are resilient to operational errors. This article reports on the development of such a guide by the Gordon Center for System Engineering at the Technion. Assuming the Human Factors variant of Murphy's Law, the guide applies the STAMP paradigm of self-control in scenario-based design, relying on a model of resilient operation. The guide suggests designing three firewalls, for preventing latent threats, preventing escalation and learning from incidents. The effectiveness of the guide was evaluated collaboratively in a special INCOSE_IL working group, by examination of its applicability to case studies. The guide was validated by scoring the guidelines applicability to failure modes observed in a special database of 67 mishaps.
OverviewThis article documents an on-going project of the Gordon Center for Systems Engineering at the Technion. The goal of this project is to develop a guide for system engineers, with guidelines for assuring safe interaction between the operators and the machine.Section 2 describes prior studies in safety analysis which motivated the need to conceptualize system resilience. Section 3 discusses topics in resilience analysis showing the need for resilience assurance. Section 4 presents various subjects in resilience assurance, demonstrating the need for this project. Section 5 presents the project, including reference to the current version of the guide, description of the history of the guide development, example of using the guide, description of the validation method and outcome, and discussion of limitations in employing the guide. Section 6 includes suggestions for subsequent studies.
Why Systems Fail?This section presents references to topics in safety analysis with focus on the role of the human operator in the system failure.There are many explanations for the source of system failures. Few of them are:
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.