The hazard analysis method "Systems Theoretic Process Analysis" (STPA) makes use of a functional system representation in the form of a Hierarchical Control Structure and uses this model as the starting point for the analysis process. The development of the Hierarchical Control Structure typically involves multiple iterations and starts at a rather abstract view, which is refined during the modelling process. Usually, no differentiation is made between the Hierarchical Control Structure model and its representation as a diagram. In addition, the representation is typically restricted to a single diagram. This paper addresses the opportunities of explicitly differentiating between model and views and introduces a concept encouraging use of multiple diagrams representing one model. This paper also discusses the rulesets and consistency considerations necessary to ensure the analysis is complete and the Hierarchical Control Structure representations are consistent with the model and with each other.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.