This is an archived course. A more recent version may be available at

Archived Versions



1 Introduction to Class, Accident Causation, System Safety Discussion questions (This resource may not render correctly in a screen reader.PDF)
2 Discussion Questions and In-class Debate on Responsibility for Risk, PHA and Risk Assessment, Traditional Hazard Analysis Techniques, Intent Specifications Preliminary hazard analysis for ACC including a list of the hazards, hazard levels, and design constraints derived from them (written, due on Ses #3).
3 Discussion Questions and In-class Debate on Responsibility for Risk (cont.), A New Systems-theoretic Accident Model, Review Preliminary Hazard Analysis for ACC Build a STAMP model of the Ueberlinger aircraft collision using the official accident report (PDF - 4.0 MB), Appendix 1 (This resource may not render correctly in a screen reader.PDF), and Appendix 2 (This resource may not render correctly in a screen reader.PDF) (team, written, and perhaps oral, due one day after Ses #8). Use that to provide a summary of the causal factors in the accident. Did you find any additional recommendations not included in the accident report or any other differences from the official accident report?
4 STPA STPA for one of the ACC controllers.
5 Catch Up  
6 Requirements Analysis and Level 1 Reviews for ACC Take each of the completeness criteria and provide an example (if it applies) from the ACC requirements. Describe how you accounted for it in your design and why it does or does not apply (written, due on Ses #13 as part of final project report).
7 Design for safety  
8 Humans and Automation  
9 Robert Francis Visit, Accident Investigation, Presentation of STAMP Analyses of Ueberlingen Accident Take the Titan/Centaur/Milstar loss and using the official report (PDF), apply the techniques for analyzing data described in the DOE standard (Events and Causal Factor Chaining, Barrier Analysis, Change Analysis, Events and Causal Factors Analysis, and Root Cause Analysis), an Ishikawa Diagram, and a Fault Tree Analysis of the accident. How do they compare to the STAMP analysis in New-8? (written, due one day after Ses #10).
10 Operations and Management by Prof. John Carroll  
11 Visitor  
12 Visitors from Electric Boat (Submarine Safety)  
13 Review of ACC Designs, Wrap-up  


Beyond the weekly assignments given in class, a term project was defined assigned, described as the following:

Do a hazard analysis and high-level design for Adaptive Cruise Control (PDF) and build Levels 1, 2, and 3 of an intent specification for it. A more detailed description of the problem can be found here in the Adaptive Cruise Control document. Intent specifications are described in N-9 and a tutorial (PDF) is available for using the tools. Also, perform at least a partial STPA on Nancy's Shuttle with a written analysis of your process and results.