Blog

  • Sub-System Hazard Analysis with Mil-Std-882E

    Sub-System Hazard Analysis with Mil-Std-882E

    In this video lesson, I look at Sub-System Hazard Analysis with Mil-Std-882E (SSHA, which is Task 204). I teach the mechanics of the task, but not just that. I’m using my long experience with this Standard to teach a pragmatic approach to getting the work done.

    Task 204 is one of three tasks that integrate tightly in a Systems Engineering framework. (The others are System Hazard Analysis, Task 205, and System of Systems Hazard Analysis, Task 209.)

    SSHA is designed to be used where a formal Sub-System Specification (SSS) has been created. However, an SSS is not essential to perform this Task. The need for SSHA is usually driven by the complexity of the system and/or that sub-system development is contracted out.

    Together, we will explore Task 204’s aim, description, scope, and contracting requirements. There’s value-adding commentary, and I explain the issues with SSHA – how to do it well and avoid the pitfalls.

    This is the seven-minute demo, the full video is 40-minutes’ long.

    Topics: Sub-System Hazard Analysis

    • Preamble: Sub-system & System HA.
    • Task 204 Purpose:
      • Verify subsystem compliance;
      • Identify (new) hazards; and
      • Recommend necessary actions.
    • Task Description (six slides);
    • Reporting;
    • Contracting; and
    • Commentary.

    Transcript: Sub-System Hazard Analysis

    Introduction

    Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial instruction on all things system safety. I’m Simon – I’m your host for today, as always and it’s the fourth of April 22. With everything that’s going on in the world, I hope that this video finds you safe and well.

    Sub-System Hazard Analysis

    Let’s move straight on to what we’re going to be doing. We’re going to be talking today about subsystem hazard analysis and this is task 204 under the military standard 882E. Previously we’ve done 201, which was preliminary hazard identification, 202, which is preliminary hazard analysis, and 203, which is safety requirements hazard analysis. And with task 204 and task 205, which is system has analysis, we’re now moving into getting stuck into particular systems that we’re thinking about, whether they be physical systems or intangible. We’re thinking about the system under consideration and I’m really getting into that analysis.

    Topics for this Session

    So, the topics that we’re going to cover today, I’ve got a little preamble to set things in perspective. We then get into the three purposes of task 204. First, to verify compliance. Secondly, to identify new hazards. And thirdly, to recommend necessary actions. That would be recommended control measures for hazards and risks. We’ve got six slides of task description, a couple of slides on reporting, one on contracting, and then a few slides on some commentary where I put in my tuppence worth and I’ll hopefully add some value to the basic bones of the standard.

    It’s worth saying that you’ll notice that subsystem is highlighted in yellow and the reason for that is that the subsystem and system hazard analysis tasks are very, very similar. They’re identical except for certain passages and I’ve highlighted those in yellow. Normally I use a yellow highlighter to emphasize something I want to talk about. This time around, I’m using underlining for that and the yellow is showing you what these are different for subsystem analysis as opposed to system [hazard analysis]. And when you’ve watched both sessions on 204 and 205, I think you’ll see the significance of what I’ve done.

    Preamble – Sub-system & System HA

    Before we get started, we need to explain the system model that the 882 is assuming. If we look at the left-hand side of the hexagons, we’ve got our system in the center, which we’re considering. Maybe that interfaces with other systems. They work within the operating environment; hence we have the icon of the world, and the system and maybe other systems are there for a purpose. They’re performing some task; they’re doing some function and that’s indicated by the tools. We’re using the system to do something, whatever it might be.

    Then as we move to the right-hand side, the system is itself broken down into subsystems. We’ve got a couple here. We’ve got sub-systems A and B and then A further broken down into A1 and A2, for example. There’s some sort of hierarchy of subsystems that are coming together and being integrated to form the overall system. That is the overall picture that I’d like to bear in mind while we’re talking about this. The assumption in the 882, is we’re going to be looking at this subsystem hierarchy bottom upwards, largely. We’ll come on to that.

    Sub-System Hazard Analysis (T204)

    The purpose of the task, as I’ve said before, it’s threefold. We must verify subsystem compliance with requirements. Requirements to deal with risk and hazards. We must identify previously unidentified hazards that may emerge as we’re working at a lower level now. And we must recommend actions as necessary. Those are further requirements to eliminate all hazards or mitigate associated risks. We’ll keep those three things in mind and that will keep coming up.

    [Video continues…]

    End: Sub-System Hazard Analysis

    My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

    You can find a free PDF of the System Safety Engineering Standard, Mil-Std-882E, here.

  • Safety Case Lifecycle: How to Develop a Safety Case

    Safety Case Lifecycle: How to Develop a Safety Case

    Safety Case Lifecycle: How to Develop a Safety Case is Part 4 of a four-part series on safety cases. In it, we look at timing issues and typical content through the safety case lifecycle.

    A Comprehensive Guide to Ensuring Project Safety

    When embarking on any significant project, ensuring safety isn’t just a step in the process—it’s the foundation of success. A Safety Case is the bedrock of this commitment, systematically building the evidence needed to demonstrate that a system is safe for use throughout its lifecycle. Here’s a vibrant, step-by-step guide to understanding and implementing Safety Cases effectively.

    Starting the Safety Journey: Initiation

    The moment that Safety Management activity kicks off, the Safety Case begins to take shape. Think of it as an evolving tapestry where each thread represents a layer of safety assurance.

    Milestone Checkpoints: Producing Safety Case Reports

    Safety Case Reports should be produced at pivotal milestones to maintain accountability and ensure progress. These reports not only showcase progress but also serve as vital checkpoints to align all stakeholders. Common milestones include:

    1. Approval of the Outline Business Case
    2. Approval of the Full Business Case
    3. Authorization to begin demonstration trials
    4. Completion of major design phases
    5. Commitment to production
    6. Testing, acceptance, and user trials
    7. System introduction to service
    8. Design or material state updates (e.g., midlife refresh)
    9. Operational changes
    10. Disposal of the system

    These reports should align with the Project Safety Management Plan, serving as contractual deliverables between the contractor and the project team.

    Keeping it Alive: Periodic Reviews

    Safety isn’t static. The Safety Case is a living document requiring ongoing updates, reviews, and configuration control. Regular reviews ensure it adapts to new challenges, emerging risks, and evolving system requirements.

    Gathering Insights: Required Inputs

    To build a robust Safety Case, a wealth of inputs is essential. These include data and outputs from key procedures such as hazard identification, risk estimation, risk reduction, and safety requirements. The journey is a collaborative effort where insights from all corners of the project feed into the evolving safety narrative.

    The Safety Case and Safety Case Report require inputs from:

    1. Outputs from Procedure SMP01 – Safety Initiation;
    2. Outputs from Procedure SMP02 – Safety Committee;
    3. Outputs from Procedure SMP03 – Safety Planning;
    4. Outputs from Procedure SMP04 – Preliminary Hazard Identification and Analysis;
    5. Outputs from Procedure SMP05 – Hazard Identification and Analysis;
    6. Outputs from Procedure SMP06 – Risk Estimation;
    7. Outputs from Procedure SMP07 – Risk and ALARP Evaluation;
    1. Outputs from Procedure SMP08 – Risk Reduction;
    2. Outputs from Procedure SMP09 – Risk Acceptance;
    3. Outputs from Procedure SMP10 – Safety Requirements and Contracts;
    4. Outputs from Procedure SMP11 – Hazard Log.

    Delivering Confidence: Required Outputs

    At its core, the Safety Case outputs are more than just documents—they are the backbone of confidence for all stakeholders. The primary outputs include:

    • Controlled documentation supporting the safety of the system
    • Detailed Safety Case Reports tailored to each project phase
    • Evidence-backed arguments showcasing tolerable risk levels

    Breaking It Down: Typical Safety Case Report Content

    An effective Safety Case Report doesn’t just inform; it assures. Here’s what it typically includes:

    • Executive Summary: Assurance of safety progress and stakeholder alignment
    • System Description: Boundaries, scope, and interface clarity
    • Assumptions: Factors underpinning safety requirements
    • Progress Assessment: Updates on safety activities and milestones
    • Risk Management: Documentation of hazards, risks, and mitigation strategies
    • Emergency and Contingency Plans: Preparedness for unforeseen circumstances
    • Operational Guidance: Practical safety insights for operators

    The Lifecycle Perspective: Safety Cases at Every Stage

    Concept Stage

    Here, safety begins with identifying risks early, crafting strategies, and ensuring feasibility. By the Outline Business Case, the safety vision should be clear, even if some areas remain undefined.

    Assessment Phase

    Building on the Concept Stage, this phase involves a deeper analysis of risks and strategies for mitigation, culminating in a Safety Case Report for the Full Business Case.

    Demonstration & Trials

    Safety during trials ensures a controlled environment for testing and evaluation. Detailed Safety Management Plans guide this phase, ensuring all involved parties understand their responsibilities.

    Introduction to Service

    At this stage, safety extends to operational readiness—ensuring support facilities, training, and logistic arrangements are in place.

    Disposal

    Disposal planning begins early, considering risks throughout the system’s life. Safety Cases for disposal ensure proper handling, whether through recycling, scrapping, or resale, minimizing liability and environmental impact.

    Conclusion

    The Safety Case is more than a procedural requirement—it’s a commitment to integrity, collaboration, and responsibility. By weaving together comprehensive safety practices at every stage, projects can achieve a level of confidence that benefits all stakeholders.

    Are you ready to take your Safety Case to the next level? Share your thoughts and experiences in the comments below!

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • System Hazard Analysis with Mil-Std-882E

    System Hazard Analysis with Mil-Std-882E

    In this 45-minute session, I look at System Hazard Analysis with Mil-Std-882E. SHA is Task 205 in the Standard. I explore Task 205’s aim, description, scope, and contracting requirements.

    I also provide commentary, based on working with this Standard since 1996, which explains SHA. How to use it to complement Sub-System Hazard Analysis (SSHA, Task 204). How to get the maximum benefits from your System Safety Program.

    Using Task 205 effectively is not just a matter of applying it in number order with the other Tasks. We need to use it within the Systems Engineering framework. That means using it top-down, to set requirements, and bottom-up to verify that they are met.

    This is the seven-minute-long demo. The full video is 47 minutes long.

    System Hazard Analysis: Topics

    • Task 205 Purpose [differences vs. 204];
      • Verify subsystem compliance;
      • ID hazards (subsystem interfaces and faults);
      • ID hazards (integrated system design); and
      • Recommend necessary actions.
    • Task Description (five slides);
    • Reporting;
    • Contracting; and
    • Commentary.

    Transcript: System Hazard Analysis with Mil-Std-882E

    Introduction

    Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial safety training resources and videos. I’m Simon, your host, and I’m recording this on the 13th of April 2020. And given the circumstances when I record this, I hope this finds you all well.

    System Hazard Analysis Task 205

    Let’s get on to our topic for today, which is System Hazard Analysis. Now, system hazard analysis is, as you may know, Task 205 in the Mil-Std-882E system safety standard.

    Topics for this Session

    What we’re going to cover in this session is purpose, task description, reporting, contracting, and some commentary – although I’ll be making commentary all the way through. Going back to the top, the yellow highlighting with this (and with Task 204), I’m using the yellow highlighting to indicate differences between 205 and 204 because they are superficially quite similar. And then I’m using underlining to emphasize those things that I want to bring to your attention and emphasize.

    Within Task 205, Purpose. We’ve got four purpose slides for this one. Verify subsistent compliance and recommend necessary actions – fourth one there. And then in the middle of the sandwich, we’ve got the identification of hazards, both between the subsystem interfaces and faults from the subsystem propagating upwards to the overall system and identifying hazards in the integrated system design. So, quite a different emphasis to 204, which was thinking about subsystems in isolation. We’ve got five slides of task description, a couple on reporting, one on contracting – nothing new there – and several commentaries.

    System Requirements Hazard Analysis (T205)

    Let’s get straight on with it. The purpose, as we’ve already said, there is a three-fold purpose here; Verify system compliance, hazard identification, and recommended actions, and then, as we can see in the yellow, the identifying previously unidentified hazards is split into two. Looking at subsystem interfaces and faults and the integration of the overall system design. And you can see the yellow bit, that’s different from 204 where we are taking this much higher-level view, taking an inter-subsystem view and then an integrated view.

    Task Description (T205) #1

    On to the task description. The contract has got to do it and document, as usual, looking at hazards and mitigations, or controls, in the integrated system design, including software and human interface. We must come onto that later.

    All the usual stuff about we’ve got to include COTS, GOTS, GFE, and NDI. So, even if stuff is not being developed, if we’re putting together a jigsaw system from existing pieces, we’ve still got to look at the overall thing. And as with 204, we go down to the underlined text at the bottom of the slide, areas to consider. Think about performance, and degradation of performance, functional failures, timing and design errors, defects, inadvertent functioning – that classic functional failure analysis that we’ve seen before.

    Again, while conducting this analysis, we’ve got to include human beings as an integral component of the system, receiving inputs, and initiating outputs.  Human factors were included in this standard from long ago…

    The End

    You can see all the Mil-Std-882E Analysis Tasks here.

    Get a free PDF of the System Safety Engineering Standard, Mil-Std-882E, here.

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Principles of Safe Software Course

    Principles of Safe Software Course

    The Principles of Safe Software Course – Learn how to develop safe software – and understand what the safety standards are really asking you to do.

    Software is everywhere. And increasingly, safety depends on it.

    Modern aircraft, vehicles, ships, railways, industrial systems and other safety-critical systems rely on software to perform functions that can affect human life.

    But software safety can be difficult to understand.

    Software engineers may understand software development extremely well, but have limited experience with safety engineering.

    Safety engineers may understand hazards, risk and safety assurance, but not the realities of software development.

    And engineers and managers who sit between the two disciplines can struggle to understand how software, safety and standards fit together.

    This course bridges that gap.

    Principles of Safe Software gives you a practical introduction to software safety, software development, and the major safety standards used in safety-critical industries.

    3+ hours of video • 38 lessons • Quizzes • Course resources • Self-paced online learning

    $495


    Why is software safety so difficult?

    Software is not physically dangerous in the same way as a failed structural component, leaking pipe or broken mechanical part.

    Yet software can control those things.

    A software defect can cause a system to:

    • issue the wrong command;
    • fail to issue a required command;
    • respond at the wrong time;
    • enter an unsafe state;
    • prevent a safety function from operating;
    • misinterpret sensor information; or
    • behave correctly according to its specification while the specification itself is unsafe.

    That creates a fundamental challenge:

    How do we gain confidence that software will contribute to system safety throughout its lifecycle?

    The answer is not simply “test the software”.

    Safe software requires an understanding of system hazards, safety requirements, software development, verification and validation, independence, assurance and the relationship between software and the wider system.

    This course introduces those principles and shows how they appear in major safety standards.


    Principles of Safe Software Course: What you will learn

    By the end of the course, you will have a practical understanding of:

    Software development

    Understand the fundamentals of software development and why the software lifecycle matters to safety.

    Software safety

    Understand what makes software safety different from conventional software engineering and why software assurance must be considered in the context of the complete system.

    Safe software principles

    Learn the core principles used to develop and assure safety-related software.

    Safety standards

    Understand why safety standards exist, what they are trying to achieve, and how different standards approach software safety.

    RTCA DO-178 / ED-12

    Understand the principles behind the internationally recognised software considerations used for airborne systems.

    IEC 61508

    Understand the role of IEC 61508 as a foundational functional-safety standard and how it addresses software within the overall safety lifecycle.

    ISO 26262

    Understand the principles of automotive functional safety and how ISO 26262 addresses software in safety-related road-vehicle systems.

    Comparing standards

    Learn to recognise the common principles shared by different safety standards — and the important differences between them.

    Lessons learned

    Consolidate the key ideas and consider what they mean when applying software safety in real projects.


    What’s inside the Principles of Safe Software Course?

    Introduction to the Principles of Safe Software Course

    The course contains 38 lessons organised into ten sections.

    1. Introduction

    Start with an overview of the course and explore free previews from the main chapters.

    2. Software Development Facts

    Explore the realities of software development and the implications for safety.

    3. Software Safety Facts

    Understand the characteristics of software that make safety assurance challenging.

    4. Safe Software Principles

    Learn the fundamental principles for developing and assuring safe software.

    5. Overview of Software Standards

    Explore the landscape of software and functional-safety standards.

    6. RTCA DO-178 / ED-12

    Examine the principles behind DO-178 and its approach to airborne software.

    7. IEC 61508

    Explore the software-safety principles within IEC 61508 and the wider functional-safety lifecycle.

    8. ISO 26262

    Understand the software-safety principles applied in automotive functional safety.

    9. Review of Standards

    Bring the standards together and compare their approaches.

    10. Lessons Learned

    Consolidate the key principles and consider how to apply them in practice.


    The Principles of Safe Software Course is for you if…

    You’re a software engineer

    You understand software development, but want to understand why safety engineers care about your software and what they need from you.

    You will gain a foundation in safety concepts, hazards, safety requirements, and software assurance.

    You’re a safety engineer

    You understand system safety, hazard analysis and risk, but want to understand how software development affects your safety argument.

    You will gain an introduction to software development and the principles used to assure safety-related software.

    You’re a systems engineer

    You need to understand how software fits into the overall system safety process.

    This course provides the bridge between system-level safety and software-level development and assurance.

    You’re an engineering or project manager

    You don’t need to become a software developer or software safety specialist.

    You do need to understand the issues well enough to ask the right questions, challenge assumptions and make informed decisions.


    Stop treating software as a black box

    A common mistake is to treat software safety as something that happens after software development.

    It doesn’t.

    Safety needs to influence the system lifecycle from the beginning.

    That means understanding the relationship between:

    System → Functions → Hazards → Safety Requirements → Software Requirements → Design → Implementation → Verification → Validation → Safety Assurance

    When these relationships are poorly understood, safety activities can become disconnected from software development.

    When they are understood properly, software safety becomes part of the engineering process rather than an additional compliance exercise.

    That’s the perspective this course is designed to provide.


    One Principles of Safe Software Course. Three major safety standards.

    You don’t need to learn three standards independently and hope that the principles eventually make sense.

    This course introduces:

    RTCA DO-178 / ED-12
    Airborne software

    IEC 61508
    Functional safety

    ISO 26262
    Automotive functional safety

    The objective isn’t simply to memorise clauses.

    It’s to understand the engineering principles behind the standards.

    Once you understand those principles, it becomes much easier to understand why different standards ask for particular processes, activities, evidence and assurance.


    What makes this Principles of Safe Software Course different?

    It focuses on principles, not clause memorisation.

    Standards change. Technologies change. Projects change.

    The underlying engineering principles are much more durable.

    It connects software engineering with system safety.

    Software cannot be considered safely in isolation from the system in which it operates.

    It is industry-aware.

    The course draws on approaches used across safety-critical industries rather than presenting software safety as an exclusively software-development problem.

    It is practical and accessible.

    You don’t need to be a software specialist to understand the course.

    And you don’t need to be a safety specialist.

    The course is designed to help people from both disciplines understand each other.

    It is self-paced.

    Work through the material when it suits you, revisit difficult topics, and learn at your own pace.


    Learn from decades of safety-critical engineering experience

    The Safety Artisan was created to make practical system safety and safety engineering knowledge accessible to engineers and professionals.

    The course material is informed by more than 30 years of experience working with safety-critical systems across aerospace, defence and other complex engineering environments.

    The objective is simple:

    Give engineers the knowledge they need to do better safety engineering.

    Not just understand the terminology.

    Not just pass an assessment.

    But understand what the principles mean when applied to real systems.


    What you’ll get

    Your course enrolment includes:

    • 38 lessons
    • More than 3 hours of video instruction
    • Software development lessons
    • Software safety lessons
    • Safe software principles
    • Coverage of major software safety standards
    • RTCA DO-178 / ED-12
    • IEC 61508
    • ISO 26262
    • Quizzes to reinforce learning
    • Course transcripts
    • Course slides
    • Lessons learned
    • Self-paced online access

    Don’t just learn the standards. Understand the engineering.

    A safety standard can tell you what activities and evidence are expected.

    It doesn’t automatically tell you how to think about the underlying engineering problem.

    That’s why understanding the principles matters.

    If you understand:

    why software can contribute to hazards,

    how safety requirements relate to software requirements,

    why verification and validation matter,

    how assurance provides confidence,

    and

    how different standards address these problems,

    you have a much stronger foundation for applying any particular software safety standard.


    Start learning Principles of Safe Software today

    Whether you’re a software engineer moving into safety, a safety engineer moving into software, a systems engineer working across both disciplines, or a manager responsible for safety-critical development, this course will give you a practical foundation in software safety.

    38 lessons.

    3+ hours of instruction.

    Three major safety standards.

    One practical introduction to the principles of safe software.

    Enrol today for $495

    Learn at your own pace. Build your understanding. Apply the principles to your own safety-critical systems.


    Frequently Asked Questions

    Do I need to be a software engineer?

    No.

    The course is designed for both software and non-software specialists. A basic understanding of engineering and software concepts will help, but the course introduces the relevant principles as it progresses.

    Do I need to be a safety engineer?

    No.

    If you are a software engineer, systems engineer or engineering manager who needs to understand software safety, this course provides a structured introduction.

    Does the course teach me how to comply with DO-178, IEC 61508 or ISO 26262?

    The course introduces the principles and approaches contained in these standards. It is not a clause-by-clause compliance course and should not be treated as a substitute for the applicable standard or your organisation’s compliance process.

    Is this course suitable for beginners?

    Yes.

    The course starts with the fundamentals and progressively introduces software safety concepts and standards.

    Is the course self-paced?

    Yes. The course is delivered online and can be completed at your own pace.

    How much video content is included?

    The course currently contains more than three hours of video content across 38 lessons.

    What standards are covered?

    The course covers the principles of RTCA DO-178 / ED-12, IEC 61508 and ISO 26262, together with an overview of software standards and a review comparing their approaches.

    What does the course cost?

    The current listed price is $495.


    Ready to understand safe software?

    Software safety doesn’t have to be a black box.

    Learn the principles. Understand the standards. Build better safety-critical software.

    Enrol in Principles of Safe Software

    $495

    38 lessons • 3+ hours of video • Self-paced online learning

  • CISSP 2021: What’s New and How to Prepare

    CISSP 2021: What’s New and How to Prepare

    CISSP 2021: What’s New and How to Prepare? Let’s look at the significant changes made to the CISSP Official Exam Outline (the course syllabus).

    What You Can Learn

    • What’s new in the CISSP Curriculum, from May 1st, 2021 (next update in 2024)
    • There are still Eight Domains – D1, D3 & D7 are still broader in content than others.
    • Very small changes (+/-1%) to the weighting of two domains.
    • Notable changes to all domains, except D1.
    • As of late 2019, some of the changes were Already in Official Course (AOC), i.e. the Student (course) Guide; Study Guide; and Official Practice Tests.
    • D2: Resource types and data activities listed (AOC);
    • D3: Fourteen designs/solutions listed (50% AOC); and thirteen cryptanalytic attacks listed (some AOC);
    • D4: Lists several new network architectures;
    • D5: Additions to all existing sub-domains & new 5.6 on authentications systems;
    • D6: More detail on security test output and reporting;
    • D7: Minor changes to 6/15 sub-domains; and
    • D8: More detail added to all sub-domains.
    This is the Introduction & Foreword to the full three-hour course.

    Who is this Course for?

    Students wishing to become Certified Information Systems Security Professionals.

    Are there any Prerequisites?

    I designed this course to help students prepare for the current (2021-2024) version of the CISSP Exam. It does not replace the official ISC2 course materials, but it will help you get the most out of them.

    CISSP 2021: What’s New?

    I’ve just passed the new version of the CISSP Exam, and I created this Course to help you pass as well!

    This course describes the changes to the Certified Information Systems Security Professional Exam Outline. Now, CISSP has been around for quite some time and the previous version of the course syllabus was established in April 2018.  In 2021, ISC2 updated the Exam Outline significantly.  In this course, I’m going to go through all of that material for you and show you what has changed, in detail, to help you with your revision.

    Here, I give you an overview of what’s changed and how this material has been developed for you.

    In the course, we’re going to cover all eight domains from ‘Security and Risk Management’ all the way through to ‘Software Development Security.  The CISSP is a very broad course and it covers all sorts of things like physical security and fire prevention right through to some more detailed technical stuff on the workings of the Internet, software development, and security testing as well.

    There have been significant changes to all of those domains except one. (There’s a small change to number one, as we will see, but it’s not huge.) However, Domains 2 to 8 have all gone undergone significant changes.  (Some of those changes were already in the official course material, in the study guide and some were already in the official practice tests; we will cover that too.)

    Course Creation

    Also, I wanted to let you know what I’ve done to create this course.

    I went on the official five-day course, which cost about $2,500 (US), where we went through hundreds of slides per day.  You get a course guide with it, which is 800-pages long.  There is a lot of good material in there, an awful lot to learn.  In addition, I’ve also been through the official study guide, which is 1,000 pages and contains quite a lot of material that wasn’t in the official course. 

    Then there is the CISSP glossary, which is about 50 pages and that’s got over 400 definitions in.  (The glossary is not so much use. It seems to be quite out of date to me. There are a lot of definitions that you don’t need and quite a few that you do need that are missing.) 

    The bibliography lists 50+ references for you to read.  You shouldn’t have to read 50+ books and standards!

    Just the first two are 1,800 pages long.  So it’s an enormous hill to climb without some guidance to help you where to look.  I’ve included page numbers for the Official Study Guide – where it covers the material we’re going to talk about.  However, even the Study Guide doesn’t cover everything – as you will see.  So, I’ve been online and looked up the information to get you started.

    Links to CISSP 2021: What’s New?

    (Learn about my CISSP 2021 Exam Journey here. That course is also FREE.)

  • Master the Complete System Safety Assessment Process

    Master the Complete System Safety Assessment Process

    Master the Complete System Safety Assessment Process. Learn how to design, tailor, and execute a comprehensive system safety assessment programme — from Preliminary Hazard Identification through to Environmental Hazard Analysis.

    Mil-Std-882E Tasks 201–210 · 69 lessons · 10.5 hours of video · Self-paced online training

    Learn the process. Master the analyses. Build a defensible safety assessment.


    Can you design a complete System Safety Assessment Programme?

    System safety is more than identifying a few hazards and putting them into a spreadsheet.

    A credible safety programme needs to establish:

    • what can go wrong;
    • how and why it can happen;
    • who or what can be harmed;
    • how hazards are controlled;
    • whether safety requirements are adequate;
    • whether controls have been implemented;
    • whether residual risk is acceptable; and
    • whether the evidence supports your safety assessment.

    And different stages of the system lifecycle require different forms of analysis.

    That’s where this course comes in.

    System Safety Assessment takes you through the complete suite of Mil-Std-882E Tasks 201–210, showing you how the analyses fit together and, importantly, how to put them together into a coherent safety assessment programme.


    From Hazard Identification to a Complete Safety Assessment

    The course takes you through the complete sequence:

    System Safety Process

    Tailor the Safety Assessment Programme

    Identify Hazards

    Analyse Hazards

    Derive and Assess Safety Requirements

    Analyse Subsystems and the Complete System

    Analyse Operations, Human Health and Functions

    Analyse System-of-Systems and Environmental Hazards

    Build the Safety Assessment

    This is not a collection of disconnected hazard-analysis techniques.

    It is a system safety process.


    What You’ll Learn

    By completing this course, you will develop the knowledge and practical understanding to:

    Design a System Safety Assessment Programme

    Understand the overall Mil-Std-882E system safety process and determine which analyses are appropriate for your system.

    Tailor the Process

    Learn how to tailor your safety assessment activities to the characteristics, lifecycle, complexity and risk profile of your system.

    Identify Hazards Early

    Use Preliminary Hazard Identification to establish an initial understanding of the system’s hazard environment.

    Analyse Hazards Systematically

    Apply the appropriate hazard-analysis techniques at different levels of the system lifecycle and architecture.

    Assess Safety Requirements

    Understand how system requirements can introduce, control or fail to adequately address hazards.

    Analyse System and Subsystem Hazards

    Follow hazards through the system architecture and examine how subsystem design contributes to system-level risk.

    Analyse Operations and Support

    Consider hazards arising from operation, maintenance, logistics, servicing and other support activities.

    Assess Health Hazards

    Identify and analyse hazards that can affect personnel health.

    Analyse System Functions

    Apply Functional Hazard Analysis to understand how failures or abnormal functional behaviour can contribute to hazards.

    Analyse Systems of Systems

    Understand the additional challenges created when multiple systems interact to create a larger operational capability.

    Analyse Environmental Hazards

    Assess hazards associated with the operating environment and environmental conditions.


    The Complete Mil-Std-882E Task 201–210 Programme

    Task 201 — Preliminary Hazard Identification

    Start by identifying the hazards associated with the system, its intended use and its operating environment.

    Learn how to establish the foundation for subsequent safety analyses.


    Task 202 — Preliminary Hazard Analysis

    Move from initial hazard identification to structured analysis.

    Understand how hazards, causes, effects, controls and risk can be examined early enough to influence system design.


    Task 203 — System Requirements Hazard Analysis

    Examine system requirements from a safety perspective.

    Identify requirements that may introduce hazards, fail to control hazards adequately, or require additional safety provisions.


    Task 204 — Subsystem Hazard Analysis

    Take the analysis down into the subsystem level.

    Understand how subsystem design and implementation can contribute to hazards identified at the system level.


    Task 205 — System Hazard Analysis

    Bring the analysis back to the complete system.

    Examine interactions between components and subsystems and assess how the integrated system can produce hazardous outcomes.


    Task 206 — Operating and Support Hazard Analysis

    Safety doesn’t stop when the system is designed.

    Analyse hazards associated with:

    • operation;
    • maintenance;
    • servicing;
    • logistics;
    • support equipment;
    • personnel activities; and
    • other operating and support activities.

    Task 207 — Health Hazard Analysis

    Examine hazards that may affect personnel health.

    Consider the relationship between system design, operating conditions, human exposure and health effects.


    Task 208 — Functional Hazard Analysis

    Analyse system functions and determine how functional failures, degraded performance or abnormal behaviour can contribute to hazardous conditions.


    Task 209 — System-of-Systems Hazard Analysis

    Modern capabilities rarely operate in isolation.

    Learn how to consider hazards arising from the interactions between multiple systems that collectively deliver an operational capability.


    Task 210 — Environmental Hazard Analysis

    Consider the effects of the operating environment on system safety.

    Analyse environmental conditions that can contribute to hazards or affect the effectiveness of safety controls.


    Understand How the Analyses Fit Together

    One of the biggest challenges in system safety is knowing which analysis to perform, when to perform it, and how the results connect.

    The course therefore begins with the overall system safety process before working through the individual analyses.

    You will see how:

    Hazard Identification

    leads to

    Hazard Analysis

    which leads to

    Safety Requirements

    which lead to

    Design Controls

    which lead to

    Verification and Validation

    which ultimately contribute to

    Residual Risk Assessment and Safety Acceptance.

    The objective is not simply to complete ten Mil-Std-882E tasks.

    The objective is to create a coherent safety argument.


    Learn the Principle Behind the Task

    Mil-Std-882E provides a framework.

    But knowing the task number is not the same as knowing how to perform the analysis effectively.

    This course focuses on understanding:

    • what each analysis is intended to achieve;
    • what information you need before starting;
    • how to structure the analysis;
    • what questions the analyst needs to ask;
    • how the analysis relates to other safety activities;
    • what outputs should be produced;
    • how results should inform system design;
    • and how the individual analyses contribute to the overall safety assessment.

    The result?

    You develop a systems-thinking approach to safety assessment, rather than simply learning a collection of templates.


    Who Is This Course For?

    System Safety Engineers

    If system safety is your profession, this course provides a structured way to develop or refresh your understanding of the complete Mil-Std-882E analysis suite.


    Safety Engineers Moving Into a New Industry

    The principles of system safety are widely applicable.

    Use the course to understand how the Mil-Std-882E task structure can be applied across different types of complex and safety-critical systems.


    Systems Engineers

    Systems engineering and system safety are closely connected.

    This course helps you understand how hazards, requirements, architecture, design and verification interact.


    Engineering Managers and Technical Leads

    You don’t need to perform every analysis yourself.

    But you do need to understand what a good analysis looks like, what questions to ask, and whether the resulting safety evidence is credible.


    Defence and Aerospace Professionals

    Mil-Std-882E is widely associated with defence system safety.

    If you work on defence acquisition, development, integration, modification or sustainment programmes, this course provides a comprehensive foundation in the standard’s hazard-analysis framework.


    What Makes This Course Different?

    One Complete Programme

    Rather than taking isolated courses on individual hazard-analysis techniques, you can learn how the full Task 201–210 suite fits together.

    Practical System Safety

    The emphasis is on understanding how to perform the analyses, not simply reading the standard.

    Lifecycle Perspective

    The analyses are considered in the context of the system lifecycle and the decisions they are intended to support.

    Tailoring

    Not every system needs exactly the same safety programme.

    Learn how to tailor your assessment activities rather than applying a one-size-fits-all process.

    Safety Engineering Thinking

    Develop the ability to ask the right questions about hazards, causes, consequences, controls, requirements and evidence.


    What You Get

    Your enrolment provides access to:

    69 lessons

    A comprehensive programme covering the system safety process and Tasks 201–210.

    10.5 hours of video

    More than ten hours of structured instruction that you can work through at your own pace.

    Course transcripts

    Use transcripts to review and search the material.

    Course slides

    Downloadable supporting material for reference and revision.

    Quizzes

    Knowledge checks to reinforce your understanding.

    Free previews

    Preview lessons from each major section before enrolling. (The Safety Artisan)


    Course Structure

    Section 1

    The System Safety Process

    Understand the overall Mil-Std-882E system safety process.

    Section 2

    Tailoring Your System Safety Assessment Programme

    Determine how to structure an assessment programme appropriate to your system.

    Section 3

    Preliminary Hazard Identification — Task 201

    Identify the initial hazard set.

    Section 4

    Preliminary Hazard Analysis — Task 202

    Analyse hazards and establish the foundations for risk control.

    Section 5

    System Requirements Hazard Analysis — Task 203

    Examine requirements from a system safety perspective.

    Section 6

    Subsystem Hazard Analysis — Task 204

    Analyse subsystem-level hazards and controls.

    Section 7

    System Hazard Analysis — Task 205

    Analyse hazards at the integrated system level.

    Section 8

    Operating and Support Hazard Analysis — Task 206

    Analyse hazards associated with operation and support.

    Section 9

    Health Hazard Analysis — Task 207

    Assess hazards affecting personnel health.

    Section 10

    Functional Hazard Analysis — Task 208

    Analyse hazardous consequences of functional failures and abnormal behaviour.

    Section 11

    System-of-Systems Hazard Analysis — Task 209

    Analyse interactions between systems within a larger capability.

    Section 12

    Environmental Hazard Analysis — Task 210

    Assess hazards associated with environmental conditions.

    The current course contains all of these sections and associated lesson resources. (The Safety Artisan)


    From a List of Hazards to a Defensible Safety Assessment

    A safety assessment should answer more than:

    “What are the hazards?”

    It should help answer:

    What can go wrong?

    Why can it go wrong?

    What are the consequences?

    What controls prevent or mitigate the hazard?

    How do we know those controls are effective?

    What requirements implement the controls?

    What evidence demonstrates that the controls have been implemented?

    What risk remains?

    This is the thinking that turns hazard analysis into system safety engineering.


    Learn From More Than 30 Years of Safety-Critical Engineering

    The Safety Artisan was created to make practical system safety and safety engineering knowledge accessible to engineers and professionals.

    The training draws on more than 30 years of experience working with safety-critical systems across aerospace, defence and other complex engineering environments.

    The focus is deliberately practical:

    Understand the problem.

    Apply the engineering method.

    Produce useful safety evidence.


    Your Investment

    System Safety Assessment

    $995

    69 lessons · 10.5 hours of video · Self-paced online training

    Build the knowledge you need to design and execute a comprehensive system safety assessment programme.


    Frequently Asked Questions

    Is this course only for defence engineers?

    No.

    Although the course is based on the Mil-Std-882E framework, the underlying system safety principles and hazard-analysis techniques can be applied to many types of complex and safety-critical systems.


    Do I need to be an experienced safety engineer?

    No.

    The course is designed to provide a structured progression from the overall system safety process through the individual analyses.

    A basic understanding of systems engineering and engineering risk will be useful.


    Does the course cover all Mil-Std-882E Tasks 201–210?

    Yes.

    The current course covers the system safety process and Tasks 201 through 210, including Preliminary Hazard Identification, Preliminary Hazard Analysis, System Requirements Hazard Analysis, Subsystem Hazard Analysis, System Hazard Analysis, Operating and Support Hazard Analysis, Health Hazard Analysis, Functional Hazard Analysis, System-of-Systems Hazard Analysis and Environmental Hazard Analysis. (The Safety Artisan)


    Does the course teach me how to use a particular software tool?

    The focus is on system safety engineering methods and analysis, rather than training in a particular software package.

    The principles can therefore be applied using the tools and processes used by your organisation.


    Is this a clause-by-clause explanation of Mil-Std-882E?

    No.

    The objective is to help you understand and apply the system safety process and associated analyses, rather than simply memorising the wording of the standard.


    Can I work through the course at my own pace?

    Yes.

    The course is delivered online and is designed for self-paced learning.

    You can work through the lessons when it suits you and revisit material as required.


    How much material is included?

    The course currently contains 69 lessons and approximately 10.5 hours of video content, together with supporting transcripts, slides and quizzes. (The Safety Artisan)


    Ready to Build Your System Safety Assessment Skills?

    You don’t need another collection of disconnected hazard-analysis techniques.

    You need to understand how the analyses fit together into a system safety programme.

    System Safety Assessment gives you a structured path through the complete Mil-Std-882E Task 201–210 analysis suite.

    Learn the process.

    Master the analyses.

    Build a defensible safety assessment.

    $995

    69 lessons · 10.5 hours of video · Self-paced online training


    Don’t Just Identify Hazards.

    Learn How to Engineer Safety.

  • The Safety Artisan’s Resume

    The Safety Artisan’s Resume

    The Safety Artisan’s Resume, or Curriculum Vitae (CV), if you prefer, is quite long. Why should you listen to me? If you want to know how I know what I know, read on…

    Simon Di Nucci – Principal Safety Consultant

    BEng, MSc, CPEng, FIE(Aust), NER, Cert CMi, CISSP

    Key Skills

    • Implementing System and Software Safety in Agile programs,
    • Safety in Air, Maritime, Land & EW/C4I domains,
    • Teaching System Safety Engineering,
    • Implementing Australian Work Health & Safety,
    • Seaworthiness (Navy Operation Effectiveness, Safety & Environmental Protection),
    • Business Development and Bidding,
    • Engineering Management,
    • Software Engineering, and
    • Cybersecurity Management & Engineering.

    Qualifications

    MSc in Safety Critical Systems Engineering (SCSE), University of York
    BEng (Hons) in Aerospace Systems Engineering, University of Southampton
    Certificate of Management, Chartered Management Institute.
    Certified Information Systems Security Professional


    Membership of Professional Institutions:
    Chartered Engineer & Fellow, Engineers Australia
    National Engineering Register
    Professional Training
    Principles of Systems Engineering
    Ship Safety Management Office (SSMO) Ship Safety Management Course


    Market Sectors: Defence, Aerospace, Cybersecurity, Nuclear

    Profile

    Simon has over thirty years’ experience in safety, particularly maritime safety and airworthiness. He works with organizations to help them comply with complex requirements and manage risks through the pragmatic and proportionate application of engineering discipline.

    Since 2012, he has worked in Australia, and before that he worked on major UK, US, and European programs in different regulatory risk frameworks.  Simon’s experience includes work on aviation (fast jets, large aircraft, helicopters, ISTAR/EW platforms), submarines, surface vessels, rail, Air Traffic Management, air battle management systems and systems-of-systems.

    His wide experience of projects varies from the small, through to some of the largest multi-national defence programs ever undertaken. Simon has more than 20 years’ experience in managing and advising organizations on safety-and-software-related engineering. Simon has been a Chartered Engineer since 1997 and has presented to international conferences in Australia, the US, UK and Canada on seaworthiness, system safety, ship-air integration, and software support. He has designed several safety and airworthiness courses and taught thousands of students.

    Work Experience

    Career Roles and Responsibilities

    System Safety Consultant   Austal Landing Craft Heavy (LC-H) | Jan 26 – present
    Key Responsibilities: Technical Safety Lead for the Procurement System Safety Program for LC-H: Rewriting the System Safety Program Plan; Conducting System Requirements and Preliminary Hazard Identification & Analyses (SRHA and PHI&A); Writing the Safety Case Report; Leading O&SHA workshops; and Planning and supervising System, Operating & Support, and Zone/Compartment Hazard Analyses.  
    Leidos Sea Archer USV | Sep 25 – Dec 25
    Safety assessment of prototype, experimental USV: Using EMSA Risk-Based Assessment Tool (RBAT); and Certification to DNV Autonomous and Remotely Operated Ships (AROS) framework.  
    Australian Nuclear Science & Technology Organisation | Mar 25 – Aug 25  
    Key Responsibilities: Periodic Safety & Security Review of Nuclear Medicine Facility: In accordance with ARPANSA guidance; Conducting Safety Factor 6, Deterministic Safety Assessment.Intermediate Liquid Waste Capacity Increase Procurement Program: Review and screening of HAZOP results (1,000+ pages); Level Of Protection Analysis for radiological safety. Actinide Suite Laboratory – Quantitative Risk Analysis of legacy research facility.  
    System Safety Discipline Lead Raytheon Australia | Jan 22 – Feb 25  
    Key Responsibilities: Lead system safety engineer for Raytheon Australia (1,500 staff)Curating the system safety process guidanceRecruiting and competency assessment of safety engineersCreating & providing training to staffFor major programs: Leading safety teams Setting up System Safety Programs & Management SystemsConducting hazard analyses & creating safety casesMajor programs: SEA5011 Maritime EW System of SystemsAIR6500-1 Joint Air Battle Management SystemMobile Threat Training Emitter SystemSpace Surveillance TelescopeLAND 555-6 FLEWS. Contributing to major bids and creating bid estimates.
    Frazer-Nash Consultancy | Jan 12 – Dec 21  
    Key Responsibilities: Business development – aerospace and submarines campaignsSystem Safety Engineering for major programs: Setting up System Safety Programs & Management SystemsConducting hazard analyses & creating safety casesMajor Programs: Collins Life of Type Extension cybersecurity and Integrated Ship Control, Management & Monitoring System safetySEA 1180 Offshore Patrol Vessel, SEA1000 Future Submarine Program (FSP) SCADA systems for explosives & countermeasures productionCybersecurity of rail management systemSafety and Human Factors assessment of Long-Range Air Traffic Flow Management system for Airservices AustraliaPuma HC2 helicopter upgradeAlso, FSP System Integration Laboratory assessment, safety course creation and delivery.  
    Principal Safety Consultant QinetiQ Safety Aviation Team | May 06 – Dec 11  
    Key Responsibilities: Member of business development team, bringing in $24M of repeat and new business, personally achieving $3M of orders in final year  System Safety Engineering for major programs: Setting up System Safety Programs & Management SystemsConducting hazard analyses & creating safety casesMajor Programs: Ship Approach and Recovery AidsFast jets – Tornado, Harrier II, Typhoon, and F-35 JSFISTAR platforms – R1 Sentinel (ASTOR), Nimrod MRA4 & RC-135Chinook and Puma HC3Safety/airworthiness course development and presentation:Presenter: UK MoD Safety Management & Safety Tools & Techniques coursesLed course development for EuroFighter Typhoon, R1 Sentinel (ASTOR) system, BAES Harrier II, and Duty Holder Air Safety for UK Military Aviation Authority.  
    Engineering Manager, UK Royal Air Force | Sep 1986 – July 2006  
    Key Responsibilities:   Senior engineering Authority and Delegation holder on EuroFighter Typhoon; during introduction to service Software Support Consultancy Team Leader, Software and Systems Specialist Officer on EuroFighter Typhoon; Junior engineering manager on Software Integration Laboratory for Tornado F3; Junior engineering manager on Tornado GR1 Squadron; Junior engineering manager on Ground Equipment Bay

    Summary of Experience

    • SEA5011 Maritime EW System of Systems,
    • AIR6500-1 Joint Air Battle Management System,
    • Mobile Threat Training Emitter System,
    • Space Surveillance Telescope,
    • Collins Life of Type Extension cybersecurity and Integrated Ship Control, Management & Monitoring System safety,
    • SEA 1180 Offshore Patrol Vessel,
    • SEA1000 Future Submarine (FSM) Program:
      • Developed the Program response to the Defence Seaworthiness Management System initiative, and  
      • Part of the team conducting the Competitive Evaluation Program (CEP) on the French, German, and Japanese design submissions, including review of the design, Integrated Logistic Support, risk management and program management elements.
    • Safety of SCADA systems for explosives and countermeasures production,
    • Cybersecurity of rail management system; and
    • Safety and Human Factors assessment of Long-Range Air Traffic Flow Management system for Airservices Australia

    Systems and Software Safety in Multiple Regulatory/Risk Frameworks

    • Development of the safety strategy, SFARP process/statements and the Safety Case Report for multiple systems, and
    • Wrote the Operating Safety Case report for the Ship Approach and Recovery Aids, including an aircraft carrier and aircraft, including human factors/workload analysis and ship/air integration into the System of Systems.

    Airworthiness and Aircraft Safety

    • Fast jets, including Tornado, Harrier, Typhoon, and the F-35 JSF,
    • ISTAR platforms including R1 Sentinel (ASTOR), Nimrod MRA4 and RC-135 Rivet Joint,
    • Chinook and Puma HC3,
    • Typhoon Engineering Authority and LOD holder:
      • Managed engineering, logistic support, and airworthiness on a major safety-critical aircraft system, sustaining air operations and bringing needed modifications into service, and
      • UK delegation leader to international meetings, managing Systems Integration and Software issues for the Typhoon PT.

    Combat aircraft operational engineering officer authorised to defer maintenance and accept defects to clear aircraft for flight. Unit Certifying Officer for the Aircraft Nuclear Weapon Armament Electrical Installation. Qualified Weapon Loading Supervisor for tactical nuclear weapons.

    Tools and Techniques

    • Safety Management Systems & Plans,
    • Goal Structuring Notation,
    • Safety Cases & Reports,
    • Functional and Physical hazard identification and analysis,
    • Safety Integrity Level (SIL) allocation & assessment,
    • Software-intensive systems,
    • Software safety engineering,
    • Cause (e.g. FTA) & consequence (e.g. ETA) analyses,
    • HAZOP and CHAZOP,
    • SFARP/ALARP & tolerability evaluation and Cost Benefit Analysis,
    • Qualitative risk assessment & loss models,
    • Independent safety audit & assessment,
    • Hazard logs and tools,
    • Support Analysis for Software,
    • Integrated Logistic Support Manager,
    • Reliability Centred Maintenance Analysis,
    • ISO 9000:2000 TickIT Lead Auditor,
    • Cyber Security for acquisition/CISSP, and
    • Functional Safety Practitioner.

    Teaching & Course Development

    • Teaching 9,000+ students online (2019 – present),
    • Course development & presentation: Safety Case Development & Review (2020),
    • Presenter: UK MoD Safety Management & Safety Tools & Techniques courses (2006-2010),
    • Led course development & presentation: Safety Airworthiness & Environmental Management for:
      • EuroFighter Typhoon (2006-2011),
      • R1 Sentinel (ASTOR) system, (2007-2011), and
      • BAES Harrier II (2009-2010).
    • Led Training Needs Analysis, course development & presentation: Duty Holder Air Safety for UK Military Aviation Authority (2010), and
    • Led course development & presentation: RAF Software Introduction to Service (2001-2003).

    Employment History

    March 2024 – Present                                       Director, The Safety Artisan

    January 2022 – March 2024                            System Safety Discipline Lead, Raytheon Australia

    January 2012 – December 2021                     Senior Consultant, Frazer-Nash Consultancy

    May 2006 – January 2012                                 Principal Safety Consultant, QinetiQ Safety Aviation Team

    August 2003 – April 2006                                 Engineering (Airworthiness) Authority, Typhoon Project Team

    October 2000 – August 2003                          Software Support Consultancy Team Leader

    September 1996 – August 1999                     Systems and Software Specialist Manager, Typhoon Field Team

    February 1994 – August 1996                         Support Manager, Tornado Software Maintenance Team

    August 1992 – January 1994                            Engineering Operations Manager, 27/12 Squadron

    October 1990 – February 1992                       Engineering Manager, Ground Support Equipment

    Publications

    “Risk Based Marine Certification,” 5th Submarine Science, Technology and Engineering Conference (SubSTEC5), November 2019.

    “Aircraft Software Certification Strategy,” Aircraft Airworthiness and Sustainment Conference, Brisbane, July 2015.

    “Weapon Effects Modelling for Safety Applications,” H. Gordon-Wright, S. Di Nucci*, G. Anderson, A. Keddie, and A Kwong* (*presenters), PARARI, Canberra, 2013.

    “Integrated Munition Health Management (IMHM),” on behalf of Dr Steven Wagstaff, PARARI, Canberra, 2013.

    “Assuring the Safety of Future Submarines,” Submarine Institute of Australia’s 2nd Technology Conference Science, Technology & Engineering, Adelaide SA, 2013.

    “Assuring Operational Systems – a Safety Case Study,” presented to the Systems Software Technology Conference, Salt Lake City, 2008.

    “Software Supportability in the Royal Air Force,” Major Willis Jacobs & Flight Lieutenant Simon Di Nucci, Canadian Department of National Defence Software Conference, Ottawa, Feb 2002.

    “Software Safety and Supportability Analysis,” Simon Di Nucci, University of York, Sep 2000.

    “Airborne Collision Avoidance Systems, Past, Present and Future,” S. Di Nucci, University of Southampton, May 1989.


    You can see my profile on LinkedIn, or go back to the Home Page. Subscribe to get a free course with a third-party accredited Certificate and Digital Badge!


  • Supporting a Vision Worth Sharing

    Supporting a Vision Worth Sharing

    At The Safety Artisan, we recently received a Certificate of Appreciation from The Fred Hollows Foundation in recognition of our support. We are genuinely honoured to receive this acknowledgement. More importantly, we are proud to support an organisation whose work has transformed millions of lives around the world.

    Our Business is Improving Safety

    Our business is improving safety. Every day, we help organisations identify hazards, manage risk, and design systems that protect people. Although our work is focused on engineering, defence, transportation, and other safety-critical industries, our aim is always the same: use knowledge and expertise to improve people’s lives.

    The Fred Hollows Foundation embodies that same principle in a different but equally important field.

    The Fred Hollows Foundation

    Founded on the vision of Professor Fred Hollows, the Foundation works to eliminate avoidable blindness and vision impairment by providing high-quality eye care where it is needed most. Its work extends far beyond performing sight-restoring operations. The Foundation trains local doctors, nurses, and health workers, strengthens healthcare systems, improves access to affordable treatments, and works with communities to create sustainable eye-care services that continue long after individual projects have finished.

    The impact is extraordinary. Restoring someone’s sight does much more than improve their health. It enables children to return to school, adults to work and support their families, older people to regain their independence, and entire communities to benefit from increased opportunity and wellbeing. Few medical interventions have such an immediate and life-changing effect.

    One aspect of the Foundation’s work that particularly resonates with us is its emphasis on creating sustainable capability. Rather than simply providing short-term assistance, the Foundation invests in local people, local healthcare systems, and long-term solutions. This philosophy mirrors many of the principles we value in systems engineering and system safety. We create solutions that continue to deliver benefits well into the future.

    Supporting a Vision Worth Sharing

    Businesses of every size have an opportunity to contribute to causes that extend beyond their immediate commercial activities. Supporting organisations such as The Fred Hollows Foundation is one way that companies can help improve lives while contributing to stronger, healthier communities worldwide.

    We are therefore delighted to receive this Certificate of Appreciation. Our contribution is small, but we are pleased to play a role in supporting Fred’s remarkable mission.

    We would like to thank everyone at The Fred Hollows Foundation for their dedication, compassion, and tireless work. Their commitment has restored sight to millions of people and continues to create opportunities for countless others.

    We look forward to continuing our support. We humbly encourage others to learn more about the Foundation’s work and the difference it is making around the world.

    If you would like to know more about our work, please click here to receive regular email updates. You can find our suite of Courses here, now with Digital Certificates. Our free blog articles on System Safety are here.

    Drop a Question or Comment below:

  • ISSS Credentialing Initiative: System Safety Professionals

    ISSS Credentialing Initiative: System Safety Professionals

    The ISSS Credentialing Initiative: System Safety Professionals. Where is the Next Generation of System Safety Professionals? We need a Workforce Development Program for Safety-Critical Industries.

    The International System Safety Society (ISSS) is launching a major credentialing initiative designed to strengthen and expand system safety capability across Canada and the United States.

    Developed as a three-year industry partnership and sponsorship program, the initiative will create a structured pathway for professionals working with complex and safety-critical systems. The program combines modular learning, stackable micro-credentials, and verifiable digital certifications to help organizations build a stronger and more resilient safety workforce.

    The initiative is being led by an ISSS sub-committee including Jenn Downing, ISSS Director of Education and Professional Development, and Carol-Ann Haggarty.

    Why This Initiative Matters

    Organizations operating in safety-critical environments face increasing challenges in recruiting, developing, and retaining personnel with the skills required to manage system safety throughout the lifecycle of complex systems.

    Whether in defence, aerospace, transportation, energy, healthcare technology, telecommunications, or critical infrastructure, employers require practitioners who understand:

    • Hazard identification and analysis
    • Risk assessment and acceptance
    • Safety assurance and evidence generation
    • Lifecycle safety management
    • Safety-informed decision making

    The ISSS Credentialing Initiative addresses these challenges by creating a common, industry-recognized framework for developing and validating system safety competencies.

    A Three-Year Development and Trial Program

    The initiative will be delivered through a structured three-year model.

    Year 1 – Build

    The first year focuses on developing:

    • The credentialing framework
    • Course architecture and learning pathways
    • Pilot training materials
    • Instructor guidance
    • Digital credentialing mechanisms
    • Evaluation and assessment strategies

    Year 2 – Pilot

    Pilot courses will be delivered with industry, academic, and professional partners. Feedback will be collected to evaluate:

    • Learning effectiveness
    • Practical relevance
    • User experience
    • Workforce applicability

    Year 3 – Refine and Scale

    Following the pilot phase, the program will be refined and prepared for wider deployment across Canada and the United States. The goal is to establish a sustainable and scalable credentialing model that meets long-term workforce needs.

    Creating a Workforce Pipeline

    The credentialing pathway is designed to support professional development from entry into the workforce through to advanced practice.

    The model provides a clear progression:

    Students and Early-Career Professionals → ISSS Micro-Credentials → Verified Skills → Industry Deployment → Career Progression

    This approach helps organizations identify talent, validate competencies, and accelerate workforce readiness.

    Cross-Industry Applicability

    A key strength of the program is its portability across industries.

    The credentialing model is intended to be standards-aware while remaining industry-neutral, making it applicable to sectors including:

    • Defence and aerospace
    • Space systems
    • Nuclear and energy
    • Rail and public transit
    • Automotive and autonomous systems
    • Medical technology
    • Mining and industrial operations
    • Critical infrastructure
    • Software-intensive systems
    • Manufacturing and robotics
    • Telecommunications
    • Public-sector acquisition

    By focusing on disciplined safety thinking, evidence-based assurance, and risk management principles, the framework can support organizations operating under a wide range of regulatory and operational environments.

    Benefits for Industry Partners

    Industry participation is central to the success of the initiative.

    Partner organizations can help ensure that the credentialing framework remains practical, current, and aligned with real workforce requirements. Benefits include:

    Improved Workforce Readiness

    Employees gain foundational and applied knowledge in system safety principles, reducing training gaps and improving operational effectiveness.

    A Common Professional Language

    The program promotes alignment across safety, systems engineering, software engineering, quality assurance, human factors, compliance, and program management functions.

    Reduced Onboarding Costs

    Organizations gain access to personnel with a recognised baseline of knowledge and capability, reducing the need to repeatedly teach foundational concepts internally.

    Scalable Capability Development

    The modular structure allows organizations to support workforce development at scale while maintaining consistency across teams and locations.

    Inclusive Workforce Development

    The ISSS Credentialing Initiative is built upon Universal Design for Learning (UDL) principles.

    The program seeks to expand access to system safety careers for:

    • Students
    • Early-career professionals
    • Engineers transitioning between industries
    • Practitioners returning to the workforce

    Learning will be delivered through flexible formats, including self-paced modules, micro-learning approaches, and multiple assessment methods.

    This inclusive design helps broaden participation, improve learner confidence, and strengthen the long-term safety engineering talent pipeline across North America.

    Opportunities for Sponsorship and Partnership

    ISSS is currently seeking organizations willing to support the development and trial period through one or more of the following roles:

    Sponsors

    Provide financial support for:

    • Curriculum development
    • Pilot delivery
    • Evaluation activities
    • Accessible learning design
    • Launch preparation

    Partners

    Support the initiative by:

    • Nominating pilot participants
    • Reviewing course relevance
    • Providing structured feedback
    • Validating workforce outcomes

    Champions

    Help expand awareness by connecting ISSS with:

    • Industry networks
    • Professional societies
    • Academic institutions
    • Government stakeholders
    • Potential implementation partners

    Sponsors may also receive benefits including brand recognition, pilot course access, participation in feedback activities, and discounted access during the formal rollout phase.

    The Next Step

    The ISSS Credentialing Initiative represents an opportunity to build a sustainable and scalable system safety workforce development framework for North America.

    Organizations interested in shaping the future of system safety education and professional development are invited to:

    • Become a partner
    • Sponsor the initiative
    • Nominate pilot participants
    • Contribute subject matter expertise
    • Support long-term rollout and adoption

    By working together, industry, academia, government, and professional societies can help create a stronger pipeline of qualified professionals capable of supporting the increasingly complex and safety-critical systems upon which modern society depends.

    ISSS 2026 Summit & Training (Click on Link in Image)

    Hi, I’m Simon Di Nucci. I am a practicing system safety engineer and have been for the last 30 years. I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command-and-control systems, rail, air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

  • Sub-System Hazard Analysis with Mil-Std-882E

    Sub-System Hazard Analysis with Mil-Std-882E

    In this video lesson, I look at Sub-System Hazard Analysis with Mil-Std-882E (SSHA, which is Task 204). I teach the mechanics of the task, but not just that. I’m using my long experience with this Standard to teach a pragmatic approach to getting the work done.

    Task 204 is one of three tasks that integrate tightly in a Systems Engineering framework. (The others are System Hazard Analysis, Task 205, and System of Systems Hazard Analysis, Task 209.)

    SSHA is designed to be used where a formal Sub-System Specification (SSS) has been created. However, an SSS is not essential to perform this Task. The need for SSHA is usually driven by the complexity of the system and/or that sub-system development is contracted out.

    Together, we will explore Task 204’s aim, description, scope, and contracting requirements. There’s value-adding commentary, and I explain the issues with SSHA – how to do it well and avoid the pitfalls.

    This is the seven-minute demo, the full video is 40-minutes’ long.

    Topics: Sub-System Hazard Analysis

    • Preamble: Sub-system & System HA.
    • Task 204 Purpose:
      • Verify subsystem compliance;
      • Identify (new) hazards; and
      • Recommend necessary actions.
    • Task Description (six slides);
    • Reporting;
    • Contracting; and
    • Commentary.

    Transcript: Sub-System Hazard Analysis

    Introduction

    Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial instruction on all things system safety. I’m Simon – I’m your host for today, as always and it’s the fourth of April 22. With everything that’s going on in the world, I hope that this video finds you safe and well.

    Sub-System Hazard Analysis

    Let’s move straight on to what we’re going to be doing. We’re going to be talking today about subsystem hazard analysis and this is task 204 under the military standard 882E. Previously we’ve done 201, which was preliminary hazard identification, 202, which is preliminary hazard analysis, and 203, which is safety requirements hazard analysis. And with task 204 and task 205, which is system has analysis, we’re now moving into getting stuck into particular systems that we’re thinking about, whether they be physical systems or intangible. We’re thinking about the system under consideration and I’m really getting into that analysis.

    Topics for this Session

    So, the topics that we’re going to cover today, I’ve got a little preamble to set things in perspective. We then get into the three purposes of task 204. First, to verify compliance. Secondly, to identify new hazards. And thirdly, to recommend necessary actions. That would be recommended control measures for hazards and risks. We’ve got six slides of task description, a couple of slides on reporting, one on contracting, and then a few slides on some commentary where I put in my tuppence worth and I’ll hopefully add some value to the basic bones of the standard.

    It’s worth saying that you’ll notice that subsystem is highlighted in yellow and the reason for that is that the subsystem and system hazard analysis tasks are very, very similar. They’re identical except for certain passages and I’ve highlighted those in yellow. Normally I use a yellow highlighter to emphasize something I want to talk about. This time around, I’m using underlining for that and the yellow is showing you what these are different for subsystem analysis as opposed to system [hazard analysis]. And when you’ve watched both sessions on 204 and 205, I think you’ll see the significance of what I’ve done.

    Preamble – Sub-system & System HA

    Before we get started, we need to explain the system model that the 882 is assuming. If we look at the left-hand side of the hexagons, we’ve got our system in the center, which we’re considering. Maybe that interfaces with other systems. They work within the operating environment; hence we have the icon of the world, and the system and maybe other systems are there for a purpose. They’re performing some task; they’re doing some function and that’s indicated by the tools. We’re using the system to do something, whatever it might be.

    Then as we move to the right-hand side, the system is itself broken down into subsystems. We’ve got a couple here. We’ve got sub-systems A and B and then A further broken down into A1 and A2, for example. There’s some sort of hierarchy of subsystems that are coming together and being integrated to form the overall system. That is the overall picture that I’d like to bear in mind while we’re talking about this. The assumption in the 882, is we’re going to be looking at this subsystem hierarchy bottom upwards, largely. We’ll come on to that.

    Sub-System Hazard Analysis (T204)

    The purpose of the task, as I’ve said before, it’s threefold. We must verify subsystem compliance with requirements. Requirements to deal with risk and hazards. We must identify previously unidentified hazards that may emerge as we’re working at a lower level now. And we must recommend actions as necessary. Those are further requirements to eliminate all hazards or mitigate associated risks. We’ll keep those three things in mind and that will keep coming up.

    [Video continues…]

    End: Sub-System Hazard Analysis

    My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains, aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

    You can find a free pdf of the System Safety Engineering Standard, Mil-Std-882E, here.