Downloadcont Ent&Filename=PROMAI5.Doc [Pygott&Al99] C
Total Page:16
File Type:pdf, Size:1020Kb
EUROPEAN ORGANISATION FOR THE SAFETY OF AIR NAVIGATION EUROCONTROL EUROCONTROL EXPERIMENTAL CENTRE REVIEW OF TECHNIQUES TO SUPPORT THE EATMP SAFETY ASSESSMENT METHODOLOGY EEC Note No. 01/04 Volume II - Annex Project SRD-3-E1 Issued: January 2004 The information contained in this document is the property of the EUROCONTROL Agency and no part should be reproduced in any form without the Agency’s permission. The views expressed herein do not necessarily reflect the official views or policy of the Agency. REPORT DOCUMENTATION PAGE Reference: Security Classification: EEC Note No. 01/04 - Volume II Unclassified Originator: Originator (Corporate Author) Name/Location: EUROCONTROL Experimental Centre Safety Research & Development Centre de Bois des Bordes B.P.15 F - 91222 Brétigny-sur-Orge CEDEX FRANCE Telephone : +33 (0)1 69 88 75 00 Sponsor: Sponsor (Contract Authority) Name/Location: Safety Analysis and Science (SAS) EUROCONTROL Agency Rue de la Fusée, 96 B -1130 BRUXELLES Telephone : +32 2 729 9011 TITLE: REVIEW OF TECHNIQUES TO SUPPORT THE EATMP SAFETY ASSESSMENT METHODOLOGY Volume II - Annex Author Date Pages Figures Tables Appendix References M.Everdij (NLR) 1/04 v + 153 1 1 - 347 Project Task No. Sponsor Period SRD-3-E1 2002 to 2003 Distribution Statement: (a) Controlled by: Head of AMS (b) Special Limitations: None (c) Copy to NTIS: YES / NO Descriptors (keywords): Safety assessment techniques & methods, EATMP SAM, Air Traffic Management Abstract: This is the Technical Annex to a report that presents the results of a survey aimed at collecting and evaluating techniques and methods that can be used to support the guidelines of the EATMP Safety Assessment Methodology (SAM). Over 500 techniques were collected that can possibly support SAM. Nineteen of these techniques have subsequently been selected for more detailed evaluation along a template format. These 19 techniques are believed to be able to support the SAM either immediately, or with some tailoring or adaptation to the ATM context. This technical annex explains how SAM support can be represented by different dimensions, gives details on the 500 techniques collected, explains in detail how 19 techniques were selected from these 500 during a Safety Techniques workshop, and explains how the template format was developed. Review of techniques to support the EATMP Safety Assessment Methodology EUROCONTROL TABLE OF CONTENTS 1. INTRODUCTION 1 1.1 Objective of the Safety Methods Survey project 1 1.2 Organisation of this document 1 2. ANS SAFETY ASSESSMENT DIMENSIONS 2 2.1 Introduction 2 2.2 ATM elements 3 2.3 Gate-to-gate flight phases 3 2.4 ANS design lifecycle 4 3. CANDIDATE SAFETY ASSESSMENT TECHNIQUES 6 4. DEVELOPMENT OF A TEMPLATE FORMAT 93 4.1 Collection of candidate evaluation criteria 93 4.2 Analysis of candidate evaluation criteria 98 4.3 Selected evaluation criteria for template 106 4.4 Template format developed 108 5. SAFETY TECHNIQUES WORKSHOP 109 5.1 Introduction 109 5.2 Selection process of techniques from Group 1 111 5.3 Selection process of techniques from Group 2 112 5.4 Selection process of techniques from Group 3 115 5.5 Selection process of techniques from Group 4 117 5.6 Selection process of techniques from Group 5 119 5.7 Selection process of techniques from Group 6 123 5.8 Selection process of techniques from Group 7 127 5.9 Selection process of techniques from Group 8 131 5.10 Selection process of techniques from Group 9 133 6. REFERENCES 136 v Review of techniques to support the EATMP Safety Assessment Methodology EUROCONTROL 1. Introduction The Safety Methods Survey report is the outcome of a project conducted as part of the SAFBUILD project [SAFBUILD web], which concerns Building Safety into Design, and is a safety assurance research approach to help ATM increase design robustness. This section explains the objectives the Safety Methods Survey project, then it explains the organisation of this report. 1.1 Objective of the Safety Methods Survey project The EATMP Safety Assessment Methodology (SAM) currently under development at EUROCONTROL aims to define the means for providing assurance that a Ground Air Navigation System is safe for operational use. The EATMP SAM has two aspects: x the methodology, and x how to execute the methodology. For the second aspect, the EATMP SAM gives guidelines (through Guidance material) but also freedom on how to complete the safety assessment: several techniques and methods may be used to support it. The purpose of the current Safety Methods Survey project is to identify possible techniques and methods for this support (including those developed in other domains and industries such as nuclear, chemical, telecommunication, railways, software design, but excluding commercially available tools), and to evaluate which ones are most suitable for the EATMP SAM. The Safety Methods Survey report is the outcome of a project is conducted as part of the SAFBUILD project [SAFBUILD web], which concerns Building Safety into Design, and is a safety assurance research approach to help ATM increase design robustness. This section explains the objectives the Safety Methods Survey project, then it explains the objective and organisation of this report. 1.2 Organisation of this document This document is the Technical Annex to the the Safety Methods Survey report. It contains details on the work produced by this project, which were not provided in the report itself. This document is organised as follows. Section 2 provides a description of the issues that should be covered by the safety assessment techniques collected in this project, into different dimensions. Section 3 provides all techniques collected during the course of this project, in a table with columns providing details for the techniques. Section 4 provides details on how the template format was developed. Section 5 provides details on the Safety Techniques Workshop that was organised to select from the list of candidate techniques collected during WP2, about 20 techniques that were to be evaluated along the template format. Section 6 provides references used. 1 Review of techniques to support the EATMP Safety Assessment Methodology EUROCONTROL 2. ANS safety assessment dimensions 2.1 Introduction EATMP SAM’s ultimate aim is to define the means for providing assurance that an Air Navigation System (ANS) is safe for operational use [EHQ-SAM]. An ANS is very complex due to the many issues and combinations of issues that have their influence on safety. Due to the diversity of these issues and the number of combinations possible it will be difficult to find or develop one technique that can support the safety assessment of all of them. Hence, this is not what we need to aim for; we need to be looking for a set of techniques that together cover all issues. To get some grip on the diversity of issues involved, they can be looked at from several viewpoints. Each viewpoint groups the issues in another way: Grouping according to ATM elements: humans, equipment, procedures, organisation, including their combinations, interactions, teamwork, decision making, etc. Grouping according to the gate-to-gate process elements, i.e. not only en-route, but also airports, runway incursions, risk monitoring, maintenance, etc. Grouping according to ANS design life cycle elements, i.e. definition phase, design phase, implementation phase, operations and maintenance phase, decommissioning. These viewpoints can be represented by dimensions that span the complete ANS, see Figure 1. Techniques and methods that support ANS safety assessment should cover all issues within the ANS boundaries. The view on the ANS as being spanned by dimensions serves the following advantages: Since elements in one group in one dimension may have similar qualities, techniques may exist that can cover (most of) the elements in one group. It can be verified easier that no group is forgotten in the safety assessment. The following three subsections try to provide some more detail on the different dimensions. En-route Approach t Tower Humans Equipment Procedures Organisation Environmen Definition Design Implementation Operations and maintenance Figure 1: The Air Navigation System is spanned by groups of issues in several dimensions. (Note that this diagram is simplified to illustrate the idea more effectively.) 2 Review of techniques to support the EATMP Safety Assessment Methodology EUROCONTROL 2.2 ATM elements The Air Navigation System is defined as the aggregate of organisations, humans, infrastructure, equipment, procedures, rules and information used to provide the Airspace Users Air Navigation Services in order to ensure the safety, regularity and efficiency of international air navigation [EHQ-SAM]. A methodology that is to provide the safety assessment of such Air Navigation Systems should therefore capture all these ATM elements. Roughly, these elements can be divided into five groups: Humans E.g., operational personnel, maintenance personnel, engineering personnel, skills, training, team work Equipment E.g., ground equipment, aircraft equipment, satellites, man machine interface, external services, external facilities, software, hardware Procedures E.g., operational procedures, instructions, maintenance procedures, risk monitoring Organisation E.g., safety culture, airspace sectorisation, route structures, separation standards, air traffic flight management, air traffic services, decision making, space management Environment E.g., weather influences These groups are closely linked, hence interactions between