The fault triggering this accidence was due to human-machine mismatch.
This fault could have been prevented by defining:
Guidelines for human-machine cooperation assurance
The alarm was not set prior to the accident, because the design did not provide means to detect the exceptional situation
Alarm could have been provided, by extending the scenarios, to include:
Guidelines for
alarm generation
This case study does not demonstrate any method for escalation prevention.
If the hazard became obvious in time, recovery could be accomplished by stopping the flyover maneuver early, and activating the throttle in time.
This case study does not demonstrate any method for Rescue facilitation.
Updated on 10 May 2016.