<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-19T05:13:30Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/49685" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/49685</identifier><datestamp>2022-01-13T07:54:11Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor" lang="en_US">Nancy G. Leveson.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author" lang="en_US">Stringfellow, Margaret Virgina</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">Massachusetts Institute of Technology. Dept. of Aeronautics and Astronautics.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department">Massachusetts Institute of Technology. Department of Aeronautics and Astronautics</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2009-11-06T16:19:47Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2009-11-06T16:19:47Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="copyright" lang="en_US">2008</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="en_US">2008</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">http://hdl.handle.net/1721.1/49685</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="oclc" lang="en_US">436221503</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Thesis (S. M.)--Massachusetts Institute of Technology, Dept. of Aeronautics and Astronautics, 2008.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">MIT Barker Library copy: leaves 82 to 106 bound upside-down.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Includes bibliographical references (leaves 56-59).</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">As the demand for high-performing complex systems has increased, the ability of engineers to meet that demand has not kept pace. The creators of the traditional system engineering processes did not anticipate modern complex systems, and the application of traditional processes to complex systems such as spacecraft has repeatedly led to disastrous results. Too often, system safety is considered late in the design process, after much of the design is set. This thesis presents an iterative safety-driven system engineering process to address this problem. The process integrates safety into the design process, ensuring that safety is designed into the system, rather than added on. The techniques used in this process are: I) Intent Specifications, a framework for organizing system development and operational information in a hierarchical structure; 2) the System-Theoretic Accident Modeling and Processes (STAMP) model of accident causation, a framework upon which to base powerful safety engineering techniques; 3) STAMP-based Hazard Analysis (STPA) a novel hazard analysis technique; and 4) SpecTRM-Requirements Language (SpecTRM-RL), a formal modeling language. Intent Specification is used to document the design with complete traceability from system goals, requirements, and constraints to the operational design and software code. The STAMP framework is used to apply concepts from control theory to system engineering. STPA is used to identify hazards and eliminate them or mitigate their effects to ensure a safe system design. Finally, SpecTRM-RL is used to create the blackbox behavior models. An example of this process applied to an outer moon exploration mission is presented (in the form of an intent specification) and discussed. The specification focuses on the design of the control system and functionality of the scientific instruments, while also including a high-level design of the entire spacecraft. The application of the process described in this thesis demonstrates that design decisions are safety-driven, and that the results of the hazard analysis are integrated into all aspects of the design.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="statementofresponsibility" lang="en_US">by Margaret Virginia Stringfellow.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree" lang="en_US">S.M.</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent" lang="en_US">107 leaves</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US">eng</dim:field>
   <dim:field mdschema="dc" element="publisher" lang="en_US">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights" lang="en_US">M.I.T. theses are protected by 
copyright. They may be viewed from this source for any purpose, but 
reproduction or distribution in any format is prohibited without written 
permission. See provided URL for inquiries about permission.</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri" lang="en_US">http://dspace.mit.edu/handle/1721.1/7582</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">Aeronautics and Astronautics.</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US">Safety-driven system engineering process</dim:field>
   <dim:field mdschema="dc" element="type" lang="en_US">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dspace" element="authorsordered">false</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="57deefee-1f48-4b0a-8e45-568f6f9d5e56">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
	&lt;Language>eng&lt;/Language>
   	&lt;Title>Safety-driven system engineering process&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2008&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Stringfellow, Margaret Virgina&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>http://dspace.mit.edu/handle/1721.1/7582&lt;/License>
    &lt;Keyword>Aeronautics and Astronautics.&lt;/Keyword>
   	&lt;Abstract>As the demand for high-performing complex systems has increased, the ability of engineers to meet that demand has not kept pace. The creators of the traditional system engineering processes did not anticipate modern complex systems, and the application of traditional processes to complex systems such as spacecraft has repeatedly led to disastrous results. Too often, system safety is considered late in the design process, after much of the design is set. This thesis presents an iterative safety-driven system engineering process to address this problem. The process integrates safety into the design process, ensuring that safety is designed into the system, rather than added on. The techniques used in this process are: I) Intent Specifications, a framework for organizing system development and operational information in a hierarchical structure; 2) the System-Theoretic Accident Modeling and Processes (STAMP) model of accident causation, a framework upon which to base powerful safety engineering techniques; 3) STAMP-based Hazard Analysis (STPA) a novel hazard analysis technique; and 4) SpecTRM-Requirements Language (SpecTRM-RL), a formal modeling language. Intent Specification is used to document the design with complete traceability from system goals, requirements, and constraints to the operational design and software code. The STAMP framework is used to apply concepts from control theory to system engineering. STPA is used to identify hazards and eliminate them or mitigate their effects to ensure a safe system design. Finally, SpecTRM-RL is used to create the blackbox behavior models. An example of this process applied to an outer moon exploration mission is presented (in the form of an intent specification) and discussed. The specification focuses on the design of the control system and functionality of the scientific instruments, while also including a high-level design of the entire spacecraft. The application of the process described in this thesis demonstrates that design decisions are safety-driven, and that the results of the hazard analysis are integrated into all aspects of the design.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>