The public standards, regulatory guidance, primary reports and literature this topic draws on. Every factual claim in the preceding chapters traces to one of these; the worked structures (the cut-set example, the risk-matrix illustration) are illustrative and belong to no source.
Definitions and cross-industry standards
- ISO/IEC Guide 51:2014, Safety aspects: Guidelines for their inclusion in standards, third edition, April 2014 (the definitions of harm, hazard, risk, tolerable risk and safety as freedom from risk which is not tolerable; supersedes the 1999 second edition).
- IEC 61508-1:2010, Functional safety of electrical/electronic/programmable electronic safety-related systems, Part 1: General requirements, Edition 2.0, International Electrotechnical Commission, April 2010 (the safety integrity levels, the random-versus-systematic failure distinction, and the low-demand and high-demand target measures; a basic safety publication from which the sector standards derive).
- IEC 60050-192:2015, International Electrotechnical Vocabulary, Part 192: Dependability, International Electrotechnical Commission, February 2015, with Amendment 1, 2016 (the dependability vocabulary shared with the other topics in this row).
Defence system safety
- MIL-STD-882E, Department of Defense Standard Practice: System Safety, US Department of Defense, 11 May 2012, with Change 1 of 27 September 2023, superseding MIL-STD-882D of 10 February 2000 (the eight-element system safety process; the severity categories and probability levels; the risk assessment code and matrix; the design order of precedence; the hazard tracking system; and the software control categories, software safety criticality matrix and level-of-rigour tasks).
Civil aviation
- SAE ARP4754A, Guidelines for Development of Civil Aircraft and Systems, SAE International, 21 December 2010, with EUROCAE ED-79A as its European equivalent; revised as SAE ARP4754B, 20 December 2023 (the development assurance process and the assignment of development assurance levels).
- SAE ARP4761, Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment, SAE International, 1 December 1996; revised as SAE ARP4761A, Guidelines for Conducting the Safety Assessment Process on Civil Aircraft, Systems, and Equipment, 20 December 2023, co-published with EUROCAE ED-135 (the functional hazard assessment, preliminary system safety assessment and system safety assessment chain, and the common cause analysis triad of zonal safety analysis, particular risks analysis and common mode analysis).
- FAA Advisory Circular 25.1309-1B, System Design and Analysis, Federal Aviation Administration, 30 August 2024, cancelling AC 25.1309-1A of 21 June 1988 (the failure condition classification and the associated average probability per flight hour objectives, as an acceptable means of compliance rather than regulation).
- EASA Easy Access Rules for Large Aeroplanes (CS-25), European Union Aviation Safety Agency (AMC 25.1309 carries the failure condition classifications and probability terms on the European side).
Sector functional safety
- ISO 26262:2018, Road vehicles: Functional safety, second edition, International Organization for Standardization, December 2018 (Part 3, Concept phase, specifies the hazard analysis and risk assessment in which the automotive safety integrity level is determined from severity, exposure and controllability).
- EN 50126-1:2017, Railway Applications: The Specification and Demonstration of Reliability, Availability, Maintainability and Safety (RAMS), Part 1: Generic RAMS Process, CENELEC, October 2017, with EN 50126-2:2017, Part 2: Systems Approach to Safety.
- EN 50129, Railway applications: Communication, signalling and processing systems, Safety related electronic systems for signalling, CENELEC; current edition 2026 (the safety case structure and the tolerable hazard rate bands for railway signalling, scoped to the lifecycle phases defined in EN 50126-1).
Tolerability and legal basis
- Health and Safety Executive, Reducing Risks, Protecting People: HSE's decision-making process, HSE Books, 2001, ISBN 0 7176 2151 0 (the tolerability of risk framework and its individual-risk boundaries: the order of one in a thousand per year for workers and one in ten thousand per year for members of the public at the unacceptable boundary, and one in a million per year between the tolerable and broadly acceptable regions).
- Edwards v National Coal Board [1949] 1 KB 704, [1949] 1 All ER 743, Court of Appeal, judgment of Asquith LJ (the gross disproportion test that governs duties qualified by "so far as is reasonably practicable", and the judicial origin of ALARP).
Primary reports
- W. E. Vesely, F. F. Goldberg, N. H. Roberts and D. F. Haasl, Fault Tree Handbook, NUREG-0492, US Nuclear Regulatory Commission, January 1981 (the founding treatment of fault tree analysis: the top event, the deductive method, minimal cut sets, and the distinction between a fault and a failure).
- Fault Tree Handbook with Aerospace Applications, Version 1.1, prepared for the NASA Office of Safety and Mission Assurance, August 2002 (the aerospace successor to NUREG-0492, adding binary decision diagram methods, dynamic fault trees, common cause and human error modelling, and importance measures).
Literature
- J. Reason, "Human error: models and management", BMJ, vol. 320, no. 7237, 18 March 2000, pp. 768-770 (the person versus system approach, active failures and latent conditions, and the layered-defences model of accident causation).
- N. G. Leveson, Engineering a Safer World: Systems Thinking Applied to Safety, MIT Press, 2012, ISBN 978-0-262-01662-9 (the argument that safety and reliability are distinct properties neither of which implies the other; the System-Theoretic Accident Model and Processes and its safety constraints, control structures and process models).
- N. G. Leveson and J. P. Thomas, STPA Handbook, March 2018 (the four-step system-theoretic process analysis: define the purpose of the analysis, model the control structure, identify unsafe control actions, identify loss scenarios).
For the failure rates every fault tree is quantified with, see the Reliability Prediction references; for the detection coverage that decides which dangerous failures stay latent, see the Testability references; and for the on-demand unavailability mathematics behind proof-tested protective functions, see the Availability references.