Failure Modes and Continuous Resilience
Adrian Cockcroft
NOVEMBER 11, 2019
There are many possible failure modes, and each exercises a different aspect of resilience. Another problem is that a design control, intended to mitigate a failure mode, may not work as intended. STPA is based on a functional control diagram of the system, and the safety constraints and requirements for each component in the design.
Let's personalize your content