Argument A1.2.2.1.7.3.3 All hazards are tolerable and ALARP holistically because...
[Back to main map]
Parent nodes:
Child nodes:
The prevention, protection and mitigation strategies for Hazard 1 and 2 have been analised and the following has been found:
- They are not exclusive i.e. one hazard's strategy implementation does not prevent the other's implementation
- Priorities are decided within the symbolic AI, however, the ultimate safe state for both hazards is to remove power to the propellers
- A single point of failure exists (symbolic AI), however, this has been analysed and shown to be ALARP as the combined likelihood of the two hazard initiating events is still mitigated to a level which is tolerable and ALARP.