9 Hazard Identification
119
• used to generate risk scenarios which have to be evaluated, ranked in the Hazard/Risk register and properly communicated to various audiences linked to the
project to allow preliminary decision making.
Provided the steps above are developed in a consistent scientific way, risks can
then be compared to a risk tolerance criteria leading to rational and transparent
risk ranking, but even more importantly to performing risk-based decision making
(RBDM) or risk-informed decision making (RIDM) which can be understood and
shared with all the project’s stakeholder.
Table 9.2 displays the various “families” of elements with the potentially impinging hazards (not necessarily all apply to the specific case), scenarios, related effects
and mechanisms, and finally their possible evolution to ultimate failure.
Hazard scenarios linked to information technology (IT) malfunctioning (for example sensors or monitoring delivering erroneous information for technical/intrinsic
reasons) are included in the line to which they pertain for each element as IT.
Hazards linked to malevolent or criminal hacks on IT systems are included in the
line to which they pertain for each element as “Cyber”.
In this chapter we focus on the methods to be used to gather information on the
potential hazards impinging on the system’s elements and sub-elements. We will
close the chapter by discussing how to ensure the hazard register is maintained alive,
how to check for future discrepancies, and how to decide if updates are necessary.
9.1 Standard Methods
9.1.1 Workshops, Interviews
We have seen dozens of “workshops” where a few “alpha-dogs” of any gender influenced everyone else and subordinates did not dare to talk. Furthermore, in general,
these “tribal gatherings” are meaningless because the glossary is not defined or
adhered to, and the system is not defined beforehand. Below is our proposed remedy
to alleviate these pains.
Disruption is Key
If one watches Tim Harford’s TED talk entitled “How Frustration can Make us more
Creative (https://www.youtube.com/watch?v=N7wF2AdVy2Q)” a world opens up.
Harford reports that psychological tests have shown that students who received handouts written with “difficult-to-read fonts” did better than students with handouts with
“easy fonts”! Those tests show that “a little difficulty” leads to better results because
it slows down the students and forces them to think more.
He then cites complex problem solving, which are generally considered to require
a step-by-step procedure: prototype, tweak, test, improve. This widely-applied procedure leads to incremental improvements, but can also lead to painful dead-ends. If
randomness is added (stupid moves, mistakes (http://www.riskope.com/2013/03/28/
119
• used to generate risk scenarios which have to be evaluated, ranked in the Hazard/Risk register and properly communicated to various audiences linked to the
project to allow preliminary decision making.
Provided the steps above are developed in a consistent scientific way, risks can
then be compared to a risk tolerance criteria leading to rational and transparent
risk ranking, but even more importantly to performing risk-based decision making
(RBDM) or risk-informed decision making (RIDM) which can be understood and
shared with all the project’s stakeholder.
Table 9.2 displays the various “families” of elements with the potentially impinging hazards (not necessarily all apply to the specific case), scenarios, related effects
and mechanisms, and finally their possible evolution to ultimate failure.
Hazard scenarios linked to information technology (IT) malfunctioning (for example sensors or monitoring delivering erroneous information for technical/intrinsic
reasons) are included in the line to which they pertain for each element as IT.
Hazards linked to malevolent or criminal hacks on IT systems are included in the
line to which they pertain for each element as “Cyber”.
In this chapter we focus on the methods to be used to gather information on the
potential hazards impinging on the system’s elements and sub-elements. We will
close the chapter by discussing how to ensure the hazard register is maintained alive,
how to check for future discrepancies, and how to decide if updates are necessary.
9.1 Standard Methods
9.1.1 Workshops, Interviews
We have seen dozens of “workshops” where a few “alpha-dogs” of any gender influenced everyone else and subordinates did not dare to talk. Furthermore, in general,
these “tribal gatherings” are meaningless because the glossary is not defined or
adhered to, and the system is not defined beforehand. Below is our proposed remedy
to alleviate these pains.
Disruption is Key
If one watches Tim Harford’s TED talk entitled “How Frustration can Make us more
Creative (https://www.youtube.com/watch?v=N7wF2AdVy2Q)” a world opens up.
Harford reports that psychological tests have shown that students who received handouts written with “difficult-to-read fonts” did better than students with handouts with
“easy fonts”! Those tests show that “a little difficulty” leads to better results because
it slows down the students and forces them to think more.
He then cites complex problem solving, which are generally considered to require
a step-by-step procedure: prototype, tweak, test, improve. This widely-applied procedure leads to incremental improvements, but can also lead to painful dead-ends. If
randomness is added (stupid moves, mistakes (http://www.riskope.com/2013/03/28/