Normally, hazards due to faults in a safety add-on are latent. However, their effect when they materialize is sometimes traumatic.
resilience add-ons introduce
secondary risks
(new risks, not present in the
original systems).
Secondary risks are those introduced by adding resilience features (mainly, safety add-ons) to the system, in order to mitigate the primary risks (the risks of the original system).
Typically, secondary risks are rare compared with original risks, but their hazards are higher.
It is a major design concern and challenge to identify the risks imposed by resilience features, and to evaluate the marginal resilience level obtained.
hazard indicators should be tested regularly, to verify that they can generate
alarms when needed .
Updated on 30 Mar 2017.