HAZOP HAZOP Method for Safety Analysis of Software Requirements Specification.. HAZOP (Hazard and Operability). HAZOP. HAZOP HAZOP. Abstract The digit

Similar documents
example code are examined in this stage The low pressure pressurizer reactor trip module of the Plant Protection System was programmed as subject for

<30362E20C6EDC1FD2DB0EDBFB5B4EBB4D420BCF6C1A42E687770>

ISO17025.PDF

Sensitive Compartmented Information Facility (SCIF) and Special Access Program Facility (SAPF) Criteria

Microsoft Word - 1-차우창.doc

untitled

<32382DC3BBB0A2C0E5BED6C0DA2E687770>

F1-1(수정).ppt

학습영역의 Taxonomy에 기초한 CD-ROM Title의 효과분석

13 Who am I? R&D, Product Development Manager / Smart Worker Visualization SW SW KAIST Software Engineering Computer Engineering 3


PowerChute Personal Edition v3.1.0 에이전트 사용 설명서

WS2003°¡À̵åÃÖÁ¾

04-다시_고속철도61~80p

Microsoft PowerPoint - Ieee standard pptx


4 CD Construct Special Model VI 2 nd Order Model VI 2 Note: Hands-on 1, 2 RC 1 RLC mass-spring-damper 2 2 ζ ω n (rad/sec) 2 ( ζ < 1), 1 (ζ = 1), ( ) 1

ecorp-프로젝트제안서작성실무(양식3)

소프트웨어개발방법론

Å©·¹Àγ»Áö20p

03신경숙내지작업

PowerPoint 프레젠테이션

IKC43_06.hwp

Microsoft PowerPoint - 3.공영DBM_최동욱_본부장-중소기업의_실용주의_CRM

원고스타일 정의

03.Agile.key

歯3-한국.PDF

<C5EBC0CFB0FA20C6F2C8AD2E687770>

歯전용]

歯1.PDF

Ver. T3_DWS.UTP-1.0 Unit Testing Plan for Digital Watch System Test Plan Test Design Specification Test Cases Specification Date Team Infor

1.장인석-ITIL 소개.ppt

04_이근원_21~27.hwp

Oracle Apps Day_SEM

06_ÀÌÀçÈÆ¿Ü0926

SW¹é¼Ł-³¯°³Æ÷ÇÔÇ¥Áö2013

< C6AFC1FD28B1C7C7F5C1DF292E687770>

09김정식.PDF

0312젠-가이드라인-표지최종.ps, page Normalize

<313920C0CCB1E2BFF82E687770>

12È«±â¼±¿Ü339~370

04서종철fig.6(121~131)ok

<BFA9BAD02DB0A1BBF3B1A4B0ED28C0CCBCF6B9FC2920B3BBC1F62E706466>

+À¯½Å.PDF

공학박사학위 논문 운영 중 터널확대 굴착시 지반거동 특성분석 및 프로텍터 설계 Ground Behavior Analysis and Protector Design during the Enlargement of a Tunnel in Operation 2011년 2월 인하대

untitled

2012프로그램내지

<31372DB9CCB7A1C1F6C7E22E687770>

<31325FB1E8B0E6BCBA2E687770>

2

목차 생활용품오염물질방출시험및방출특성연구 (IV) - 전기 전자제품방출오염물질권고기준 ( 안 ) 도출 - ⅰ ⅱ ⅲ Abstract ⅳ 환경기반연구부생활환경연구과 Ⅰ,,,,,, 2010 Ⅱ i

0125_ 워크샵 발표자료_완성.key

Slide 1

<30322D28C6AF29C0CCB1E2B4EB35362D312E687770>


2010

Journal of Educational Innovation Research 2018, Vol. 28, No. 3, pp DOI: NCS : * A Study on

(Table of Contents) 2 (Specifications) 3 ~ 10 (Introduction) 11 (Storage Bins) 11 (Legs) 11 (Important Operating Requirements) 11 (Location Selection)

<4D F736F F F696E74202D20C0CEC5CDB1D7B7A1C7C120C8B8BBE7BCD2B0B320666F F E BC0D0B1E220C0FCBFEB5D>

thesis

30이지은.hwp

Manufacturing6

00내지1번2번

<31372DB9DABAB4C8A32E687770>

8-VSB (Vestigial Sideband Modulation)., (Carrier Phase Offset, CPO) (Timing Frequency Offset),. VSB, 8-PAM(pulse amplitude modulation,, ) DC 1.25V, [2

VOL /2 Technical SmartPlant Materials - Document Management SmartPlant Materials에서 기본적인 Document를 관리하고자 할 때 필요한 세팅, 파일 업로드 방법 그리고 Path Type인 Ph

08원재호( )

Microsoft Word - P02.doc

PowerPoint 프레젠테이션

[ 영어영문학 ] 제 55 권 4 호 (2010) ( ) ( ) ( ) 1) Kyuchul Yoon, Ji-Yeon Oh & Sang-Cheol Ahn. Teaching English prosody through English poems with clon

2015

우리들이 일반적으로 기호

저작자표시 - 비영리 - 변경금지 2.0 대한민국 이용자는아래의조건을따르는경우에한하여자유롭게 이저작물을복제, 배포, 전송, 전시, 공연및방송할수있습니다. 다음과같은조건을따라야합니다 : 저작자표시. 귀하는원저작자를표시하여야합니다. 비영리. 귀하는이저작물을영리목적으로이용할

Microsoft Word - KSR2012A037

보험판매와 고객보호의 원칙

<333820B1E8C8AFBFEB2D5A B8A620C0CCBFEBC7D120BDC7BFDC20C0A7C4A1C3DFC1A42E687770>

Coriolis.hwp

DC Link Application DC Link capacitor can be universally used for the assembly of low inductance DC buffer circuits and DC filtering, smoothing. They

강의10

Microsoft PowerPoint 원전 전력계통의 전력품질 영향과 규제적용 방안_김문영(KINS) [호환 모드]

대경테크종합카탈로그

-

Journal of Educational Innovation Research 2019, Vol. 29, No. 1, pp DOI: (LiD) - - * Way to

(specifications) 3 ~ 10 (introduction) 11 (storage bin) 11 (legs) 11 (important operating requirements) 11 (location selection) 12 (storage bin) 12 (i

ETL_project_best_practice1.ppt

<23C0B1C1A4B9E65FC6EDC1FDBFCFBCBA E687770>

<BCF6BDC D31385FB0EDBCD3B5B5B7CEC8DEB0D4C5B8BFEEB5B5C0D4B1B8BBF3BFACB1B85FB1C7BFB5C0CE2E687770>

03 장태헌.hwp

~41-기술2-충적지반

step 1-1

11¹Ú´ö±Ô

- 2 -

<B1A4B0EDC8ABBAB8C7D0BAB8392D345F33C2F75F E687770>

10¿ÀÁ¤ÁØ

장양수

<B7CEC4C3B8AEC6BCC0CEB9AEC7D B3E23130BFF9292E687770>

Ł?

歯두산3.PDF

2016년 5월호 E 세계로, 미래로 나아가는 힘. nergy 우리의 열정과 노력이 KEPCO E&C의 에너지를 만들어냅니다. C ommunication 더 현명하게, 더 여유롭게 더 건강하게, 더 적극적으로 이 세상과 소통합니다. 04 K-Message 경영 메시지

Journal of Educational Innovation Research 2019, Vol. 29, No. 1, pp DOI: * Suggestions of Ways

Transcription:

HAZOP HAZOP Method for of Software Requirements Specification HAZOP (Hazard and Operability) HAZOP HAZOP HAZOP Abstract The digitalization of the instrumentation and control system of nuclear power plant makes the safety of computer software be the most important issue Recently, licensing criteria requires the safety analysis on the product from each phase of the lifecycle A HAZOP (Hazard and Operability) method for safety analysis of software requirements phase has been suggested HAZOP is a powerful hazard analysis technique which has a long history in process industries As the use of digital systems for nuclear power plant becomes more common, it is clear that there is a need for a HAZOP method which can be used effectively with such systems This paper describes several attempts to derive the guide phrases, checklist and the procedure for software HAZOP

HAZOP HAZOPHazard and Operability HAZOP Life Cycle Activity Groups Planning Requirements Design Implementation Integration Validation Installation Operation & Maintenance Software Requirements Management Plan Specification Design Specification Listings System Build Documents Operations Manuals Software Development Plan Software QA Plan Hardware & Software Architecture Installation Configuration Tables Integration Plan Installation Plan Design outputs Maintenance Plan Maintenance Manuals Training Plan Operations Plan Training Manuals Process Implementation Software Safety Plan Requirements Design Integration Validation Installation Change Software V&V Plan V&V Requirements Analysis V&V Design Analysis V&V ImplementationAnalysis & Test V&V Integration Analysis & Test V&V Validation Analysis & Test V&V Installation Analysis & Test V&V Change Software CM Plan CM Requirements CM Design CM Implementation CM Integration CM Validation CM Installation CM Change Process requirements Source: NUREG-0800 HAZOP (Standard Review Plan) 1, IEEE 1228-1994 2 KNICS

System Design Spec SAR PHA PHL System Design Spec SRS SAD SDD SRS SRS SAD SAD SDD SDD SRS SAD SRS SAD SDD SDD PHA: Preliminary Hazard Analysis PHL: Preliminary Hazard List SAD: SW Architecture Description SAR: SDD: SW Design Description SRS: SW Requirements Spec (V&V),,,,,,, (risk), Checklist Hazard and Operability (HAZOP) Failure Mode Effect Analysis (FMEA), Fault Tree Analysis (FTA) FTA 1960

FTA HAZOP, FMEA FTA FTA fault tree, fault tree FTA,, :,,,,,,,, HAZOP,,,,,,

HAZOP Checklist

1 (risk) 2 3 (SRS) 4 5 Checklist 6 3 HAZOP 7 8

HAZOP (Deviation) HAZOP 2 HAZOP

3Guide Phrase,,,,,,,, Guide Phrases Guide Phrases4Checklist HAZOP 3Hazard,,, RADC Stuck at all zeroes RADC Stuck at all ones RADC Stuck elsewhere RADC Below minimum range RADC Above maximum range RADC Within range, but wrong RADC Physical units are incorrect RADC Wrong data type or data size RADC Stuck at all zeroes RADC Stuck at all ones RADC Stuck elsewhere RADC Below minimum range RADC Above maximum range RADC Within range, but wrong RADC Physical units are incorrect RADC Wrong data type or data size RA Numerical value below acceptable range RA Numerical value above acceptable range RA Numerical value within range, but wrong RA Numerical value has wrong physical units RA Numerical value has wrong data type or data size RA Non-numerical value incorrect RDC RDC Calculated result is outside acceptable error bounds (too low) Calculated result is outside acceptable error bounds (too high) RDC Formula or equation is wrong RDC Physical units are incorrect RDC Wrong data type or data size R: Requirements, A: Architectual Design, D: Detail Design, C: Coding

Function is not carried out as specified (for each mode of operation) Function is not initialized properly before being executed Function executes when trigger conditions are not satisfied Trigger conditions are satisfied but function fails to execute Function continues to execute after termination conditions are satisfied Termination conditions are not satisfied but function terminates Function terminates before necessary actions, calculations, events, etc are completed Function is executed in incorrect operating mode Function uses incorrect inputs Function produces incorrect outputs

Software fails in the presence of unexpected input data Software fails in the presence of incorrect input data Software fails when anomalous conditions occur Software fails to recover itself when required HAZOP HAZOP HAZOP HAZOP,,, KNICS HAZOP

[1] NUREG/CR-6101, "Software Reliability and Safety in Nuclear Reactor Protection Systems," Lawrence Livermore National Laboratory, November 1993 [2] IEEE Std 1228, "Standard for Software Safety Plan," Institute of Electronic and Electrical Engineers, 1994 [3] NUREG/CR-6430, "Software Safety Hazard Analysis," Lawrence Livermore National Laboratory, February 1996 [4], -, KNICS-ESF-SSP121, 2003 [5] McDermid, J A & Pumfrey, D J, A Development of Hazard Analysis To Aid Software Design, COMPASS, 1994