safety-critical system are systems in which failures may affect the environment of the system and cause injury or death to the people in that environment. The principal concern of safety specification is to identify requirements that will minimize the probability that system failures will occur. Safety requirements are primarily protection requirements and are concerned with normal system operation. They may specify that the system should be shut down so that safety is maintained in deriving safety requirements. You, therefore, need to find an acceptable balance between safety and functionality and avoid overprotection. There is a unit in banking a very safe system if it does not operate in a cost-effective way. Safety specification is usually focused on the hazards that may arise in a given situation, and the events that can lead to these hazards. The activities in the general risk-based identification process map onto the safety specification process as follows.
1.(问题1).In safety specification, this is the hazard identification process that identifies hazards that may threaten the system.
2.(问题2).This is a process of hazard assessment to decide which hazards are the most dangerous and or the most likely to occur. These should be prioritized when deriving safety requirements.
3.(问题3).This process is concerned with discovering the events that can lead to the occurrence of a hazard. In safety specification, the process is known as hazard analysis.
4.(问题4).This process is based on the outcome of (问题5) and leads to identification of safety requirements. These may be concerned with ensuring that a hazard does not arise or lead to an accident or that if an accident does occur, the associated damage is minimized.
本题考察的是安全关键系统(safety-critical system)的安全需求规范过程与风险管理过程的映射。
在安全规范中,通常需要识别危险、评估危险、分析危险发生的原因,并将风险分解为具体的安全需求。
问题 1:描述的是“hazard identification”,即识别可能威胁系统的危险。
- A选项 Risk decomposition:这是将风险进一步分解为可管理的部分,不是识别风险的过程,错误。
- B选项 Risk analysis:分析风险的严重性和可能性,不是最初的识别环节,错误。
- C选项 Risk reduction:是风险控制或降低的措施阶段,不符合题干描述,错误。
- D选项 Risk identification:是风险管理的第一步,目的是识别可能影响系统的潜在风险,对应 hazard identification,正确。
所以答案是 D。
问题 2:描述的是“hazard assessment”,即对已识别的危险进行分析,评估其严重性和发生概率,并进行优先级排序。
- A选项 Risk decomposition:强调将风险分解,和评估无关,错误。
- B选项 Risk analysis:风险分析正是对危险的可能性和后果进行评估,与 hazard assessment 对应,正确。
- C选项 Risk reduction:是风险控制措施的制定,不是评估环节,错误。
- D选项 Risk identification:已经在小题 1 说明,不是评估,错误。
所以答案是 B。
问题 3:描述的是“hazard analysis”,即发现可能导致危险的事件。
- A选项 Risk decomposition:这是后续将风险分解为安全需求的环节,不是发现事件的过程,错误。
- B选项 Risk specification:风险规格化过程,正对应 hazard analysis 的作用,即明确风险触发的事件以及其条件,正确。
- C选项 Risk reduction:指采取措施降低风险,不是分析事件的过程,错误。
- D选项 Risk identification:是最初识别危险,不是分析事件的过程,错误。
所以答案是 B。
问题 4:描述的是基于小题 5 的结果(hazard assessment),提出安全需求,确保危险不会引发事故,或者事故的损害最小化。
- A选项 Risk decomposition:这是根据风险分析结果,将其分解为具体的安全需求的过程,正确。
- B选项 Risk analysis:风险分析已经发生在小题 2,不是此处要求,错误。
- C选项 Risk reduction:是最终采取的措施,不是需求分解,错误。
- D选项 Risk identification:是第一步,和这里描述不符,错误。
所以答案是 A。
问题 5:题干明确指出“based on the outcome of ()”,而该结果来自小题 2 的 hazard assessment。
- A选项 hazard identification:这是识别危险,不是提供优先级评估结果的环节,错误。
- B选项 hazard assessment:正是小题 2 所述的结果,提供危险的优先级和严重性,正确。
- C选项 safety specification:这是整个过程的目标,而不是中间的评估步骤,错误。
- D选项 hazard analysis:这是小题 3 的过程,不是这里的结果,错误。
所以答案是 B。
