13.07.2015 Views

In-flight upset - 154 km west of Learmonth, WA, 7 October 2008,

In-flight upset - 154 km west of Learmonth, WA, 7 October 2008,

In-flight upset - 154 km west of Learmonth, WA, 7 October 2008,

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 54: Summary <strong>of</strong> results <strong>of</strong> SSA activities for FCPC algorithmThere were alternative algorithm designs or additional features that, in hindsight,would have prevented the design limitation or reduced its influence. Examplesinclude rate limiting on the three AOA input values, range checks on the inputvalues, or reasonableness checks involving comparisons between pitch and AOA.However, a system development process needs to balance many competingrequirements, such as minimising the risk <strong>of</strong> introducing new failure conditions anddesign errors, minimising the data processing resources required, and unnecessarycomplexity. The inclusion <strong>of</strong> specific design features must be based on an identifiedneed, and in this case the system development process did not identify the designlimitation and therefore the need for any additional features.The development <strong>of</strong> the new algorithm occurred in the period from 1991 to 1992,and determining the exact reasons why all <strong>of</strong> the development activities at that timedid not identify the design limitation was made difficult by the amount <strong>of</strong>information available nearly 20 years later. Nevertheless, it is possible to discusssome contextual factors and inherent limitations associated with the systemdevelopment process.Limitations <strong>of</strong> using identified equipment failure modesDuring design reviews and SSA activities, design engineers and safety analysts usea variety <strong>of</strong> approaches and sources <strong>of</strong> information to identify design problems (orfailure scenarios) that will lead to the failure conditions <strong>of</strong> concern. A key approachis to use knowledge <strong>of</strong> how relevant items <strong>of</strong> equipment can fail or produceincorrect outputs, examine the effects <strong>of</strong> these failure modes in a particular design,- 195 -

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!