Defenses against inadequate response to alarms

Hazard prevention

  In this case study, the operators did not perceive properly the system situation, and consequently, they made the wrong action, turning off the auxiliary pumps.

  The guide suggests that rules about the proper system behavior should be defined and implemented also for exceptional situations.

  The system had the data, based on various sensors, which enable analysis of the system situation better than that obtained by reading the pressure.

  The rules could be applied to provide better information to the operators, to prevent the mistake.

Alarming

The system could warn the operators if they apply the wrong response to the original alarm

Escalation prevention

The guide recommends on intervention by the supervision unit, which may change the control from the primary station to the recovery station. This is not demonstrated in this case study.

Recovery facilitation

Based on the rules for operation under hazard, the system could guide the operators in the recovery procedures.

The guide recommends on intervention by the supervision unit, which may change the control from the primary station to the recovery station. This is not demonstrated in this case study.

Rescue facilitation

The guide recommends on intervention by the supervision unit, which may change the control from the recovery station to the rescue station. This is not demonstrated in this case study.


Updated on 20 Apr 2016.