19.11.2014 Views

Development of a military Operating Safety Case Report - Adelard

Development of a military Operating Safety Case Report - Adelard

Development of a military Operating Safety Case Report - Adelard

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

UNCLASSIFIED<br />

<strong>Development</strong> <strong>of</strong> a <strong>military</strong><br />

<strong>Operating</strong> <strong>Safety</strong> <strong>Case</strong> <strong>Report</strong><br />

Mark Templeton<br />

A presentation to: The ASCE User Group<br />

Thursday 6 th December 2012<br />

Ref: QINETIQ/TIS/S&AS/PUB1203018/1<br />

All example data and screenshots in this presentation<br />

were developed by QinetiQ under contract to the UK<br />

Defence Evaluation & Support organisation<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

1


UNCLASSIFIED<br />

Contents slide<br />

1 The task – an outline<br />

2 Initial GSN<br />

3 Initial tuning<br />

4 Colour scheme<br />

5 Evidence capture<br />

6 Traffic lights<br />

7 Automating the export<br />

8 The last minute<br />

9 The result<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

2


UNCLASSIFIED<br />

1 The task – an outline<br />

Customer requirements<br />

• <strong>Safety</strong> <strong>Case</strong> <strong>Report</strong><br />

− Primarily to demonstrate Operation <strong>of</strong> the fleet will be acceptably safe<br />

− Demonstrate progress to the men in long trousers<br />

− Manage a staged Release To Service<br />

− Identify missing evidence<br />

− Identify “critical path” evidence<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

3


UNCLASSIFIED<br />

2 Initial GSN<br />

Initial safety argument<br />

• Developed pre-contract<br />

• Massive – 645 nodes<br />

Figure 1: Initial safety argument<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

4


UNCLASSIFIED<br />

3 Initial tuning 1/3<br />

Wall charts<br />

• Four A0 charts<br />

• Single plot 2.1m long<br />

Issues<br />

• Very hard to navigate<br />

• Easy to get lost<br />

• Where can I find X?<br />

• Have we already considered Y?<br />

• Hard to manage “split” issues<br />

− Certified equipment,<br />

− maintained well,<br />

− risks to maintainers, operators and public<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

5


UNCLASSIFIED<br />

3 Initial tuning 2/3<br />

Figure 2: Key to safety argument<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

6


UNCLASSIFIED<br />

3 Initial tuning 3/3<br />

New argument – supporting<br />

User Views<br />

• Easy to maintain<br />

• Hard to get lost<br />

• Only 436 nodes now!<br />

• Example…<br />

Figure 3: Initial Top Level view<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

7


UNCLASSIFIED<br />

4 Colour scheme 1/3<br />

Too much red!<br />

Figure 4: Embarrassingly red Top Level view<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

8


UNCLASSIFIED<br />

4 Colour scheme 2/3<br />

New schema:<br />

C1.1<br />

C1.7<br />

• Swap spectra and status<br />

<strong>Safety</strong><br />

Regulatory<br />

Authorities<br />

Definition <strong>of</strong><br />

required RAF<br />

Military Roles<br />

• Better ownership<br />

• Add second status<br />

C1.2<br />

Definition <strong>of</strong><br />

Tolerably Safe<br />

C1.3<br />

[>]<br />

G1<br />

XXX is tolerably safe to operate<br />

C1.8<br />

Definition <strong>of</strong> XXX<br />

Service<br />

− Status now and at RTS<br />

• Example…<br />

Defining<br />

document: XXX<br />

<strong>Safety</strong><br />

Management<br />

Plan"<br />

M1.6<br />

C1.9<br />

KURs, SOIU<br />

Definition <strong>of</strong> XXX<br />

system<br />

C1.5<br />

Secretary <strong>of</strong><br />

State's <strong>Safety</strong> &<br />

Environmental<br />

Protection Policy<br />

[>]<br />

[>]<br />

G1.4<br />

G1.10<br />

The aircraft is<br />

safe<br />

Operations are<br />

carried out safely<br />

[>]<br />

G1.11<br />

XXX SMS is effective in<br />

managing safety <strong>of</strong> the<br />

service<br />

[>]<br />

G1.12<br />

All assumptions and<br />

prerequisites are<br />

discharged<br />

Figure 5: Enhanced Top Level view<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

9


UNCLASSIFIED<br />

4 Colour scheme 3/3<br />

One level down<br />

• Project Team responsible to ensure aircraft is safe…<br />

• Retain airworthiness responsibility<br />

• Delegate some responsibility to Design Organisation…<br />

• …and some to Operator<br />

Figure 6: Colour denotes ownership<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

10


UNCLASSIFIED<br />

5 Evidence capture 1/3<br />

Plugin: GSN Status <strong>of</strong> Evidence<br />

• Identify:<br />

− evidence,<br />

− expected date <strong>of</strong> arrival,<br />

− contracted date,<br />

− owner<br />

Process<br />

• Create spreadsheet from table <strong>of</strong> ASCE Solutions<br />

• Manual reconciliation took around two days<br />

• Developed Status <strong>of</strong> Evidence plugin<br />

− Press “Create” and…<br />

Figure 7: Dialog box for plugin<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

11


UNCLASSIFIED<br />

5 Evidence capture 2/3<br />

Create spreadsheet<br />

• New Excel spreadsheet created<br />

• Keys<br />

− Column A<br />

− Row 1<br />

• Other fields all editable<br />

Figure 8: Spreadsheet created by plugin<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

12


UNCLASSIFIED<br />

5 Evidence capture 3/3<br />

Synchronise<br />

• “Synchronise” button on plugin<br />

• For each changed Solution node<br />

− Display text<br />

− Select action<br />

• Result<br />

− Model updated<br />

− New spreadsheet<br />

Figure 9: Data comparison by plugin<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

13


UNCLASSIFIED<br />

6 Traffic lights<br />

Plugin: Update twin status fields<br />

• 436 nodes x 2 traffic lights = 872 data items<br />

• A manual nightmare<br />

• Modified Goal Completed plugin<br />

G1<br />

− Support for second status field<br />

− New logic<br />

• Around 2 seconds to update all fields<br />

G1.1 G1.2 G1.3<br />

G1.1.1<br />

G1.1.2 G1.2.1 G1.2.2 G1.3.1<br />

S1.1.1.1 S1.1.1.2 S1.1.2.1 S1.1.2.2 S1.2.1.1 S1.2.1.2 S1.2.2.1 S1.2.2.2 S1.3.1.1 S1.3.1.2<br />

Figure 10: Traffic light demo<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

14


UNCLASSIFIED<br />

7 Automating the export 1/2<br />

Plugin: One click export<br />

• Simplistic approach<br />

− Use ACSE as a graphical editor<br />

− Copy and paste diagrams to word processor<br />

− Missies the point <strong>of</strong> ASCE<br />

• Intermediate approach<br />

− Create an output path<br />

− Export a Word document and modify it<br />

− Updates difficult<br />

• Educated approach<br />

− Maintain argument in ASCE<br />

− NEVER modify Word document<br />

− Use Word Macros<br />

ASCE<br />

Word<br />

Word<br />

Word<br />

ASCE<br />

ASCE<br />

ASCE<br />

Word<br />

Word<br />

Word<br />

Figure 11: Maintenance processes (old and new)<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

15


UNCLASSIFIED<br />

7 Automating the export 2/2<br />

Word macros<br />

• ASCE does not rely on Word macros – so do what you want<br />

• Issue 1 – Appendices<br />

− Create magic token<br />

− From that point on, change all headings to appendix headings<br />

− Adjust Table <strong>of</strong> Contents heading levels<br />

− Regenerate TOC twice<br />

• Issue 2 – Front pages<br />

− Front few pages differ – but outside <strong>of</strong> ASCE<br />

− Test for FrontPages.doc<br />

− Prepend if found<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

16


UNCLASSIFIED<br />

8 The last minute<br />

Evidence always arrives late…<br />

• Three days to delivery and evidence arrives, but not as expected<br />

• Meeting with customer to adjust the safety argument<br />

• Generation <strong>of</strong> new report took under one minute<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

17


UNCLASSIFIED<br />

9 The result<br />

We made it!<br />

• <strong>Safety</strong> case delivered when required<br />

• The argument matched the evidence<br />

• Now updating for next phase <strong>of</strong> programme<br />

Lessons learned<br />

• Well worth using ASCE as intended<br />

• Develop plugins or schemas<br />

Further work<br />

• Collaborative working<br />

• Extra traffic light – differentiate “not relevant” from “not set”<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

18


UNCLASSIFIED<br />

Questions?<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

19


www.QinetiQ.com<br />

© Copyright QinetiQ Limited 2005-2012 QinetiQ Proprietary<br />

20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!