In this video lesson, I look at Sub-System Hazard Analysis with Mil-Std-882E (SSHA, which is Task 204). I teach the mechanics of the task, but not just that. I’m using my long experience with this Standard to teach a pragmatic approach to getting the work done.
SSHA is designed to be used where a formal Sub-System Specification (SSS) has been created. However, an SSS is not essential to perform this Task. The need for SSHA is usually driven by the complexity of the system and/or that sub-system development is contracted out.
Together, we will explore Task 204’s aim, description, scope, and contracting requirements. There’s value-adding commentary, and I explain the issues with SSHA – how to do it well and avoid the pitfalls.
This is the seven-minute demo, the full video is 40-minutes’ long.
Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial instruction on all things system safety. I’m Simon – I’m your host for today, as always and it’s the fourth of April 22. With everything that’s going on in the world, I hope that this video finds you safe and well.
Sub-System Hazard Analysis
Let’s move straight on to what we’re going to be doing. We’re going to be talking today about subsystem hazard analysis and this is task 204 under the military standard 882E. Previously we’ve done 201, which was preliminary hazard identification, 202, which is preliminary hazard analysis, and 203, which is safety requirements hazard analysis. And with task 204 and task 205, which is system has analysis, we’re now moving into getting stuck into particular systems that we’re thinking about, whether they be physical systems or intangible. We’re thinking about the system under consideration and I’m really getting into that analysis.
Topics for this Session
So, the topics that we’re going to cover today, I’ve got a little preamble to set things in perspective. We then get into the three purposes of task 204. First, to verify compliance. Secondly, to identify new hazards. And thirdly, to recommend necessary actions. That would be recommended control measures for hazards and risks. We’ve got six slides of task description, a couple of slides on reporting, one on contracting, and then a few slides on some commentary where I put in my tuppence worth and I’ll hopefully add some value to the basic bones of the standard.
It’s worth saying that you’ll notice that subsystem is highlighted in yellow and the reason for that is that the subsystem and system hazard analysis tasks are very, very similar. They’re identical except for certain passages and I’ve highlighted those in yellow. Normally I use a yellow highlighter to emphasize something I want to talk about. This time around, I’m using underlining for that and the yellow is showing you what these are different for subsystem analysis as opposed to system [hazard analysis]. And when you’ve watched both sessions on 204 and 205, I think you’ll see the significance of what I’ve done.
Preamble – Sub-system & System HA
Before we get started, we need to explain the system model that the 882 is assuming. If we look at the left-hand side of the hexagons, we’ve got our system in the center, which we’re considering. Maybe that interfaces with other systems. They work within the operating environment; hence we have the icon of the world, and the system and maybe other systems are there for a purpose. They’re performing some task; they’re doing some function and that’s indicated by the tools. We’re using the system to do something, whatever it might be.
Then as we move to the right-hand side, the system is itself broken down into subsystems. We’ve got a couple here. We’ve got sub-systems A and B and then A further broken down into A1 and A2, for example. There’s some sort of hierarchy of subsystems that are coming together and being integrated to form the overall system. That is the overall picture that I’d like to bear in mind while we’re talking about this. The assumption in the 882, is we’re going to be looking at this subsystem hierarchy bottom upwards, largely. We’ll come on to that.
Sub-System Hazard Analysis (T204)
The purpose of the task, as I’ve said before, it’s threefold. We must verify subsystem compliance with requirements. Requirements to deal with risk and hazards. We must identify previously unidentified hazards that may emerge as we’re working at a lower level now. And we must recommend actions as necessary. Those are further requirements to eliminate all hazards or mitigate associated risks. We’ll keep those three things in mind and that will keep coming up.
[Video continues…]
End: Sub-System Hazard Analysis
My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!
You can find a free PDF of the System Safety Engineering Standard, Mil-Std-882E, here.
Safety Case Lifecycle: How to Develop a Safety Case is Part 4 of a four-part series on safety cases. In it, we look at timing issues and typical content through the safety case lifecycle.
A Comprehensive Guide to Ensuring Project Safety
When embarking on any significant project, ensuring safety isn’t just a step in the process—it’s the foundation of success. A Safety Case is the bedrock of this commitment, systematically building the evidence needed to demonstrate that a system is safe for use throughout its lifecycle. Here’s a vibrant, step-by-step guide to understanding and implementing Safety Cases effectively.
Starting the Safety Journey: Initiation
The moment that Safety Management activity kicks off, the Safety Case begins to take shape. Think of it as an evolving tapestry where each thread represents a layer of safety assurance.
Milestone Checkpoints: Producing Safety Case Reports
Safety Case Reports should be produced at pivotal milestones to maintain accountability and ensure progress. These reports not only showcase progress but also serve as vital checkpoints to align all stakeholders. Common milestones include:
Approval of the Outline Business Case
Approval of the Full Business Case
Authorization to begin demonstration trials
Completion of major design phases
Commitment to production
Testing, acceptance, and user trials
System introduction to service
Design or material state updates (e.g., midlife refresh)
Operational changes
Disposal of the system
These reports should align with the Project Safety Management Plan, serving as contractual deliverables between the contractor and the project team.
Keeping it Alive: Periodic Reviews
Safety isn’t static. The Safety Case is a living document requiring ongoing updates, reviews, and configuration control. Regular reviews ensure it adapts to new challenges, emerging risks, and evolving system requirements.
Gathering Insights: Required Inputs
To build a robust Safety Case, a wealth of inputs is essential. These include data and outputs from key procedures such as hazard identification, risk estimation, risk reduction, and safety requirements. The journey is a collaborative effort where insights from all corners of the project feed into the evolving safety narrative.
The Safety Case and Safety Case Report require inputs from:
At its core, the Safety Case outputs are more than just documents—they are the backbone of confidence for all stakeholders. The primary outputs include:
Controlled documentation supporting the safety of the system
Detailed Safety Case Reports tailored to each project phase
Progress Assessment: Updates on safety activities and milestones
Risk Management: Documentation of hazards, risks, and mitigation strategies
Emergency and Contingency Plans: Preparedness for unforeseen circumstances
Operational Guidance: Practical safety insights for operators
The Lifecycle Perspective: Safety Cases at Every Stage
Concept Stage
Here, safety begins with identifying risks early, crafting strategies, and ensuring feasibility. By the Outline Business Case, the safety vision should be clear, even if some areas remain undefined.
Assessment Phase
Building on the Concept Stage, this phase involves a deeper analysis of risks and strategies for mitigation, culminating in a Safety Case Report for the Full Business Case.
Demonstration & Trials
Safety during trials ensures a controlled environment for testing and evaluation. Detailed Safety Management Plans guide this phase, ensuring all involved parties understand their responsibilities.
Introduction to Service
At this stage, safety extends to operational readiness—ensuring support facilities, training, and logistic arrangements are in place.
Disposal
Disposal planning begins early, considering risks throughout the system’s life. Safety Cases for disposal ensure proper handling, whether through recycling, scrapping, or resale, minimizing liability and environmental impact.
Conclusion
The Safety Case is more than a procedural requirement—it’s a commitment to integrity, collaboration, and responsibility. By weaving together comprehensive safety practices at every stage, projects can achieve a level of confidence that benefits all stakeholders.
Are you ready to take your Safety Case to the next level? Share your thoughts and experiences in the comments below!
Meet the Author
Learn safety engineering with me, an industry professional with 25 years of experience, I have:
•Worked on aircraft, ships, submarines, ATMS, trains, and software;
•Tiny programs to some of the biggest (Eurofighter, Future Submarine);
•In the UK and Australia, on US and European programs;
•Taught safety to hundreds of people in the classroom, and thousands online;
•Presented on safety topics at several international conferences.
In this 45-minute session, I look at System Hazard Analysis with Mil-Std-882E. SHA is Task 205 in the Standard. I explore Task 205’s aim, description, scope, and contracting requirements.
I also provide commentary, based on working with this Standard since 1996, which explains SHA. How to use it to complement Sub-System Hazard Analysis (SSHA, Task 204). How to get the maximum benefits from your System Safety Program.
Using Task 205 effectively is not just a matter of applying it in number order with the other Tasks. We need to use it within the Systems Engineering framework. That means using it top-down, to set requirements, and bottom-up to verify that they are met.
This is the seven-minute-long demo. The full video is 47 minutes long.
Transcript: System Hazard Analysis with Mil-Std-882E
Introduction
Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial safety training resources and videos. I’m Simon, your host, and I’m recording this on the 13th of April 2020. And given the circumstances when I record this, I hope this finds you all well.
System Hazard Analysis Task 205
Let’s get on to our topic for today, which is System Hazard Analysis. Now, system hazard analysis is, as you may know, Task 205 in the Mil-Std-882E system safety standard.
Topics for this Session
What we’re going to cover in this session is purpose, task description, reporting, contracting, and some commentary – although I’ll be making commentary all the way through. Going back to the top, the yellow highlighting with this (and with Task 204), I’m using the yellow highlighting to indicate differences between 205 and 204 because they are superficially quite similar. And then I’m using underlining to emphasize those things that I want to bring to your attention and emphasize.
Within Task 205, Purpose. We’ve got four purpose slides for this one. Verify subsistent compliance and recommend necessary actions – fourth one there. And then in the middle of the sandwich, we’ve got the identification of hazards, both between the subsystem interfaces and faults from the subsystem propagating upwards to the overall system and identifying hazards in the integrated system design. So, quite a different emphasis to 204, which was thinking about subsystems in isolation. We’ve got five slides of task description, a couple on reporting, one on contracting – nothing new there – and several commentaries.
System Requirements Hazard Analysis (T205)
Let’s get straight on with it. The purpose, as we’ve already said, there is a three-fold purpose here; Verify system compliance, hazard identification, and recommended actions, and then, as we can see in the yellow, the identifying previously unidentified hazards is split into two. Looking at subsystem interfaces and faults and the integration of the overall system design. And you can see the yellow bit, that’s different from 204 where we are taking this much higher-level view, taking an inter-subsystem view and then an integrated view.
Task Description (T205) #1
On to the task description. The contract has got to do it and document, as usual, looking at hazards and mitigations, or controls, in the integrated system design, including software and human interface. We must come onto that later.
All the usual stuff about we’ve got to include COTS, GOTS, GFE, and NDI. So, even if stuff is not being developed, if we’re putting together a jigsaw system from existing pieces, we’ve still got to look at the overall thing. And as with 204, we go down to the underlined text at the bottom of the slide, areas to consider. Think about performance, and degradation of performance, functional failures, timing and design errors, defects, inadvertent functioning – that classic functional failure analysis that we’ve seen before.
Again, while conducting this analysis, we’ve got to include human beings as an integral component of the system, receiving inputs, and initiating outputs. Human factors were included in this standard from long ago…
The End
You can see all the Mil-Std-882E Analysis Tasks here.
Get a free PDF of the System Safety Engineering Standard, Mil-Std-882E, here.
Learn safety engineering with me, an industry professional with 25 years of experience, I have:
•Worked on aircraft, ships, submarines, ATMS, trains, and software;
•Tiny programs to some of the biggest (Eurofighter, Future Submarine);
•In the UK and Australia, on US and European programs;
•Taught safety to hundreds of people in the classroom, and thousands online;
•Presented on safety topics at several international conferences.
The Principles of Safe Software Course – Learn how to develop safe software – and understand what the safety standards are really asking you to do.
Software is everywhere. And increasingly, safety depends on it.
Modern aircraft, vehicles, ships, railways, industrial systems and other safety-critical systems rely on software to perform functions that can affect human life.
But software safety can be difficult to understand.
Software engineers may understand software development extremely well, but have limited experience with safety engineering.
Safety engineers may understand hazards, risk and safety assurance, but not the realities of software development.
And engineers and managers who sit between the two disciplines can struggle to understand how software, safety and standards fit together.
This course bridges that gap.
Principles of Safe Software gives you a practical introduction to software safety, software development, and the major safety standards used in safety-critical industries.
3+ hours of video • 38 lessons • Quizzes • Course resources • Self-paced online learning
Software is not physically dangerous in the same way as a failed structural component, leaking pipe or broken mechanical part.
Yet software can control those things.
A software defect can cause a system to:
issue the wrong command;
fail to issue a required command;
respond at the wrong time;
enter an unsafe state;
prevent a safety function from operating;
misinterpret sensor information; or
behave correctly according to its specification while the specification itself is unsafe.
That creates a fundamental challenge:
How do we gain confidence that software will contribute to system safety throughout its lifecycle?
The answer is not simply “test the software”.
Safe software requires an understanding of system hazards, safety requirements, software development, verification and validation, independence, assurance and the relationship between software and the wider system.
This course introduces those principles and shows how they appear in major safety standards.
Principles of Safe Software Course: What you will learn
By the end of the course, you will have a practical understanding of:
Software development
Understand the fundamentals of software development and why the software lifecycle matters to safety.
Software safety
Understand what makes software safety different from conventional software engineering and why software assurance must be considered in the context of the complete system.
Safe software principles
Learn the core principles used to develop and assure safety-related software.
Safety standards
Understand why safety standards exist, what they are trying to achieve, and how different standards approach software safety.
RTCA DO-178 / ED-12
Understand the principles behind the internationally recognised software considerations used for airborne systems.
IEC 61508
Understand the role of IEC 61508 as a foundational functional-safety standard and how it addresses software within the overall safety lifecycle.
ISO 26262
Understand the principles of automotive functional safety and how ISO 26262 addresses software in safety-related road-vehicle systems.
Comparing standards
Learn to recognise the common principles shared by different safety standards — and the important differences between them.
Lessons learned
Consolidate the key ideas and consider what they mean when applying software safety in real projects.
What’s inside the Principles of Safe Software Course?
Introduction to the Principles of Safe Software Course
The course contains 38 lessons organised into ten sections.
1. Introduction
Start with an overview of the course and explore free previews from the main chapters.
2. Software Development Facts
Explore the realities of software development and the implications for safety.
3. Software Safety Facts
Understand the characteristics of software that make safety assurance challenging.
4. Safe Software Principles
Learn the fundamental principles for developing and assuring safe software.
5. Overview of Software Standards
Explore the landscape of software and functional-safety standards.
6. RTCA DO-178 / ED-12
Examine the principles behind DO-178 and its approach to airborne software.
7. IEC 61508
Explore the software-safety principles within IEC 61508 and the wider functional-safety lifecycle.
8. ISO 26262
Understand the software-safety principles applied in automotive functional safety.
9. Review of Standards
Bring the standards together and compare their approaches.
10. Lessons Learned
Consolidate the key principles and consider how to apply them in practice.
The Principles of Safe Software Course is for you if…
You’re a software engineer
You understand software development, but want to understand why safety engineers care about your software and what they need from you.
You will gain a foundation in safety concepts, hazards, safety requirements, and software assurance.
You’re a safety engineer
You understand system safety, hazard analysis and risk, but want to understand how software development affects your safety argument.
You will gain an introduction to software development and the principles used to assure safety-related software.
You’re a systems engineer
You need to understand how software fits into the overall system safety process.
This course provides the bridge between system-level safety and software-level development and assurance.
You’re an engineering or project manager
You don’t need to become a software developer or software safety specialist.
You do need to understand the issues well enough to ask the right questions, challenge assumptions and make informed decisions.
Stop treating software as a black box
A common mistake is to treat software safety as something that happens after software development.
It doesn’t.
Safety needs to influence the system lifecycle from the beginning.
That means understanding the relationship between:
When these relationships are poorly understood, safety activities can become disconnected from software development.
When they are understood properly, software safety becomes part of the engineering process rather than an additional compliance exercise.
That’s the perspective this course is designed to provide.
One Principles of Safe Software Course. Three major safety standards.
You don’t need to learn three standards independently and hope that the principles eventually make sense.
This course introduces:
RTCA DO-178 / ED-12 Airborne software
IEC 61508 Functional safety
ISO 26262 Automotive functional safety
The objective isn’t simply to memorise clauses.
It’s to understand the engineering principles behind the standards.
Once you understand those principles, it becomes much easier to understand why different standards ask for particular processes, activities, evidence and assurance.
What makes this Principles of Safe Software Course different?
It focuses on principles, not clause memorisation.
The underlying engineering principles are much more durable.
It connects software engineering with system safety.
Software cannot be considered safely in isolation from the system in which it operates.
It is industry-aware.
The course draws on approaches used across safety-critical industries rather than presenting software safety as an exclusively software-development problem.
It is practical and accessible.
You don’t need to be a software specialist to understand the course.
And you don’t need to be a safety specialist.
The course is designed to help people from both disciplines understand each other.
It is self-paced.
Work through the material when it suits you, revisit difficult topics, and learn at your own pace.
Learn from decades of safety-critical engineering experience
The Safety Artisan was created to make practical system safety and safety engineering knowledge accessible to engineers and professionals.
The course material is informed by more than 30 years of experience working with safety-critical systems across aerospace, defence and other complex engineering environments.
The objective is simple:
Give engineers the knowledge they need to do better safety engineering.
Not just understand the terminology.
Not just pass an assessment.
But understand what the principles mean when applied to real systems.
What you’ll get
Your course enrolment includes:
38 lessons
More than 3 hours of video instruction
Software development lessons
Software safety lessons
Safe software principles
Coverage of major software safety standards
RTCA DO-178 / ED-12
IEC 61508
ISO 26262
Quizzes to reinforce learning
Course transcripts
Course slides
Lessons learned
Self-paced online access
Don’t just learn the standards. Understand the engineering.
A safety standard can tell you what activities and evidence are expected.
It doesn’t automatically tell you how to think about the underlying engineering problem.
That’s why understanding the principles matters.
If you understand:
why software can contribute to hazards,
how safety requirements relate to software requirements,
why verification and validation matter,
how assurance provides confidence,
and
how different standards address these problems,
you have a much stronger foundation for applying any particular software safety standard.
Start learning Principles of Safe Software today
Whether you’re a software engineer moving into safety, a safety engineer moving into software, a systems engineer working across both disciplines, or a manager responsible for safety-critical development, this course will give you a practical foundation in software safety.
38 lessons.
3+ hours of instruction.
Three major safety standards.
One practical introduction to the principles of safe software.
Learn at your own pace. Build your understanding. Apply the principles to your own safety-critical systems.
Frequently Asked Questions
Do I need to be a software engineer?
No.
The course is designed for both software and non-software specialists. A basic understanding of engineering and software concepts will help, but the course introduces the relevant principles as it progresses.
Do I need to be a safety engineer?
No.
If you are a software engineer, systems engineer or engineering manager who needs to understand software safety, this course provides a structured introduction.
Does the course teach me how to comply with DO-178, IEC 61508 or ISO 26262?
The course introduces the principles and approaches contained in these standards. It is not a clause-by-clause compliance course and should not be treated as a substitute for the applicable standard or your organisation’s compliance process.
Is this course suitable for beginners?
Yes.
The course starts with the fundamentals and progressively introduces software safety concepts and standards.
Is the course self-paced?
Yes. The course is delivered online and can be completed at your own pace.
How much video content is included?
The course currently contains more than three hours of video content across 38 lessons.
What standards are covered?
The course covers the principles of RTCA DO-178 / ED-12, IEC 61508 and ISO 26262, together with an overview of software standards and a review comparing their approaches.
What does the course cost?
The current listed price is $495.
Ready to understand safe software?
Software safety doesn’t have to be a black box.
Learn the principles. Understand the standards. Build better safety-critical software.
Enrol in Principles of Safe Software
$495
38 lessons • 3+ hours of video • Self-paced online learning
Students wishing to become Certified Information Systems Security Professionals.
Are there any Prerequisites?
I designed this course to help students prepare for the current (2021-2024) version of the CISSP Exam. It does not replace the official ISC2 course materials, but it will help you get the most out of them.
CISSP 2021: What’s New?
I’ve just passed the new version of the CISSP Exam, and I created this Course to help you pass as well!
This course describes the changes to the Certified Information Systems Security Professional Exam Outline. Now, CISSP has been around for quite some time and the previous version of the course syllabus was established in April 2018. In 2021, ISC2 updated the Exam Outline significantly. In this course, I’m going to go through all of that material for you and show you what has changed, in detail, to help you with your revision.
Here, I give you an overview of what’s changed and how this material has been developed for you.
In the course, we’re going to cover all eight domains from ‘Security and Risk Management’ all the way through to ‘Software Development Security. The CISSP is a very broad course and it covers all sorts of things like physical security and fire prevention right through to some more detailed technical stuff on the workings of the Internet, software development, and security testing as well.
There have been significant changes to all of those domains except one. (There’s a small change to number one, as we will see, but it’s not huge.) However, Domains 2 to 8 have all gone undergone significant changes. (Some of those changes were already in the official course material, in the study guide and some were already in the official practice tests; we will cover that too.)
Course Creation
Also, I wanted to let you know what I’ve done to create this course.
I went on the official five-day course, which cost about $2,500 (US), where we went through hundreds of slides per day. You get a course guide with it, which is 800-pages long. There is a lot of good material in there, an awful lot to learn. In addition, I’ve also been through the official study guide, which is 1,000 pages and contains quite a lot of material that wasn’t in the official course.
Then there is the CISSP glossary, which is about 50 pages and that’s got over 400 definitions in. (The glossary is not so much use. It seems to be quite out of date to me. There are a lot of definitions that you don’t need and quite a few that you do need that are missing.)
The bibliography lists 50+ references for you to read. You shouldn’t have to read 50+ books and standards!
Just the first two are 1,800 pages long. So it’s an enormous hill to climb without some guidance to help you where to look. I’ve included page numbers for the Official Study Guide – where it covers the material we’re going to talk about. However, even the Study Guide doesn’t cover everything – as you will see. So, I’ve been online and looked up the information to get you started.
Master the Complete System Safety Assessment Process. Learn how to design, tailor, and execute a comprehensive system safety assessment programme — from Preliminary Hazard Identification through to Environmental Hazard Analysis.
Mil-Std-882E Tasks 201–210 · 69 lessons · 10.5 hours of video · Self-paced online training
Learn the process. Master the analyses. Build a defensible safety assessment.
Can you design a complete System Safety Assessment Programme?
System safety is more than identifying a few hazards and putting them into a spreadsheet.
A credible safety programme needs to establish:
what can go wrong;
how and why it can happen;
who or what can be harmed;
how hazards are controlled;
whether safety requirements are adequate;
whether controls have been implemented;
whether residual risk is acceptable; and
whether the evidence supports your safety assessment.
And different stages of the system lifecycle require different forms of analysis.
That’s where this course comes in.
System Safety Assessment takes you through the complete suite of Mil-Std-882E Tasks 201–210, showing you how the analyses fit together and, importantly, how to put them together into a coherent safety assessment programme.
From Hazard Identification to a Complete Safety Assessment
The course takes you through the complete sequence:
System Safety Process
↓
Tailor the Safety Assessment Programme
↓
Identify Hazards
↓
Analyse Hazards
↓
Derive and Assess Safety Requirements
↓
Analyse Subsystems and the Complete System
↓
Analyse Operations, Human Health and Functions
↓
Analyse System-of-Systems and Environmental Hazards
↓
Build the Safety Assessment
This is not a collection of disconnected hazard-analysis techniques.
It is a system safety process.
What You’ll Learn
By completing this course, you will develop the knowledge and practical understanding to:
Design a System Safety Assessment Programme
Understand the overall Mil-Std-882E system safety process and determine which analyses are appropriate for your system.
Tailor the Process
Learn how to tailor your safety assessment activities to the characteristics, lifecycle, complexity and risk profile of your system.
Identify Hazards Early
Use Preliminary Hazard Identification to establish an initial understanding of the system’s hazard environment.
Analyse Hazards Systematically
Apply the appropriate hazard-analysis techniques at different levels of the system lifecycle and architecture.
Assess Safety Requirements
Understand how system requirements can introduce, control or fail to adequately address hazards.
Analyse System and Subsystem Hazards
Follow hazards through the system architecture and examine how subsystem design contributes to system-level risk.
Analyse Operations and Support
Consider hazards arising from operation, maintenance, logistics, servicing and other support activities.
Assess Health Hazards
Identify and analyse hazards that can affect personnel health.
Analyse System Functions
Apply Functional Hazard Analysis to understand how failures or abnormal functional behaviour can contribute to hazards.
Analyse Systems of Systems
Understand the additional challenges created when multiple systems interact to create a larger operational capability.
Analyse Environmental Hazards
Assess hazards associated with the operating environment and environmental conditions.
The Complete Mil-Std-882E Task 201–210 Programme
Task 201 — Preliminary Hazard Identification
Start by identifying the hazards associated with the system, its intended use and its operating environment.
Learn how to establish the foundation for subsequent safety analyses.
Task 202 — Preliminary Hazard Analysis
Move from initial hazard identification to structured analysis.
Understand how hazards, causes, effects, controls and risk can be examined early enough to influence system design.
Task 203 — System Requirements Hazard Analysis
Examine system requirements from a safety perspective.
Identify requirements that may introduce hazards, fail to control hazards adequately, or require additional safety provisions.
Task 204 — Subsystem Hazard Analysis
Take the analysis down into the subsystem level.
Understand how subsystem design and implementation can contribute to hazards identified at the system level.
Task 205 — System Hazard Analysis
Bring the analysis back to the complete system.
Examine interactions between components and subsystems and assess how the integrated system can produce hazardous outcomes.
Task 206 — Operating and Support Hazard Analysis
Safety doesn’t stop when the system is designed.
Analyse hazards associated with:
operation;
maintenance;
servicing;
logistics;
support equipment;
personnel activities; and
other operating and support activities.
Task 207 — Health Hazard Analysis
Examine hazards that may affect personnel health.
Consider the relationship between system design, operating conditions, human exposure and health effects.
Task 208 — Functional Hazard Analysis
Analyse system functions and determine how functional failures, degraded performance or abnormal behaviour can contribute to hazardous conditions.
Task 209 — System-of-Systems Hazard Analysis
Modern capabilities rarely operate in isolation.
Learn how to consider hazards arising from the interactions between multiple systems that collectively deliver an operational capability.
Task 210 — Environmental Hazard Analysis
Consider the effects of the operating environment on system safety.
Analyse environmental conditions that can contribute to hazards or affect the effectiveness of safety controls.
Understand How the Analyses Fit Together
One of the biggest challenges in system safety is knowing which analysis to perform, when to perform it, and how the results connect.
The course therefore begins with the overall system safety process before working through the individual analyses.
You will see how:
Hazard Identification
leads to
Hazard Analysis
which leads to
Safety Requirements
which lead to
Design Controls
which lead to
Verification and Validation
which ultimately contribute to
Residual Risk Assessment and Safety Acceptance.
The objective is not simply to complete ten Mil-Std-882E tasks.
The objective is to create a coherent safety argument.
Learn the Principle Behind the Task
Mil-Std-882E provides a framework.
But knowing the task number is not the same as knowing how to perform the analysis effectively.
This course focuses on understanding:
what each analysis is intended to achieve;
what information you need before starting;
how to structure the analysis;
what questions the analyst needs to ask;
how the analysis relates to other safety activities;
what outputs should be produced;
how results should inform system design;
and how the individual analyses contribute to the overall safety assessment.
The result?
You develop a systems-thinking approach to safety assessment, rather than simply learning a collection of templates.
Who Is This Course For?
System Safety Engineers
If system safety is your profession, this course provides a structured way to develop or refresh your understanding of the complete Mil-Std-882E analysis suite.
Safety Engineers Moving Into a New Industry
The principles of system safety are widely applicable.
Use the course to understand how the Mil-Std-882E task structure can be applied across different types of complex and safety-critical systems.
Systems Engineers
Systems engineering and system safety are closely connected.
This course helps you understand how hazards, requirements, architecture, design and verification interact.
Engineering Managers and Technical Leads
You don’t need to perform every analysis yourself.
But you do need to understand what a good analysis looks like, what questions to ask, and whether the resulting safety evidence is credible.
Defence and Aerospace Professionals
Mil-Std-882E is widely associated with defence system safety.
If you work on defence acquisition, development, integration, modification or sustainment programmes, this course provides a comprehensive foundation in the standard’s hazard-analysis framework.
What Makes This Course Different?
One Complete Programme
Rather than taking isolated courses on individual hazard-analysis techniques, you can learn how the full Task 201–210 suite fits together.
Practical System Safety
The emphasis is on understanding how to perform the analyses, not simply reading the standard.
Lifecycle Perspective
The analyses are considered in the context of the system lifecycle and the decisions they are intended to support.
Tailoring
Not every system needs exactly the same safety programme.
Learn how to tailor your assessment activities rather than applying a one-size-fits-all process.
Safety Engineering Thinking
Develop the ability to ask the right questions about hazards, causes, consequences, controls, requirements and evidence.
What You Get
Your enrolment provides access to:
69 lessons
A comprehensive programme covering the system safety process and Tasks 201–210.
10.5 hours of video
More than ten hours of structured instruction that you can work through at your own pace.
Course transcripts
Use transcripts to review and search the material.
Course slides
Downloadable supporting material for reference and revision.
Quizzes
Knowledge checks to reinforce your understanding.
Free previews
Preview lessons from each major section before enrolling. (The Safety Artisan)
Course Structure
Section 1
The System Safety Process
Understand the overall Mil-Std-882E system safety process.
Section 2
Tailoring Your System Safety Assessment Programme
Determine how to structure an assessment programme appropriate to your system.
Section 3
Preliminary Hazard Identification — Task 201
Identify the initial hazard set.
Section 4
Preliminary Hazard Analysis — Task 202
Analyse hazards and establish the foundations for risk control.
Section 5
System Requirements Hazard Analysis — Task 203
Examine requirements from a system safety perspective.
Section 6
Subsystem Hazard Analysis — Task 204
Analyse subsystem-level hazards and controls.
Section 7
System Hazard Analysis — Task 205
Analyse hazards at the integrated system level.
Section 8
Operating and Support Hazard Analysis — Task 206
Analyse hazards associated with operation and support.
Section 9
Health Hazard Analysis — Task 207
Assess hazards affecting personnel health.
Section 10
Functional Hazard Analysis — Task 208
Analyse hazardous consequences of functional failures and abnormal behaviour.
Section 11
System-of-Systems Hazard Analysis — Task 209
Analyse interactions between systems within a larger capability.
Section 12
Environmental Hazard Analysis — Task 210
Assess hazards associated with environmental conditions.
The current course contains all of these sections and associated lesson resources. (The Safety Artisan)
From a List of Hazards to a Defensible Safety Assessment
A safety assessment should answer more than:
“What are the hazards?”
It should help answer:
What can go wrong?
Why can it go wrong?
What are the consequences?
What controls prevent or mitigate the hazard?
How do we know those controls are effective?
What requirements implement the controls?
What evidence demonstrates that the controls have been implemented?
What risk remains?
This is the thinking that turns hazard analysis into system safety engineering.
Learn From More Than 30 Years of Safety-Critical Engineering
The Safety Artisan was created to make practical system safety and safety engineering knowledge accessible to engineers and professionals.
The training draws on more than 30 years of experience working with safety-critical systems across aerospace, defence and other complex engineering environments.
The focus is deliberately practical:
Understand the problem.
Apply the engineering method.
Produce useful safety evidence.
Your Investment
System Safety Assessment
$995
69 lessons · 10.5 hours of video · Self-paced online training
Build the knowledge you need to design and execute a comprehensive system safety assessment programme.
Frequently Asked Questions
Is this course only for defence engineers?
No.
Although the course is based on the Mil-Std-882E framework, the underlying system safety principles and hazard-analysis techniques can be applied to many types of complex and safety-critical systems.
Do I need to be an experienced safety engineer?
No.
The course is designed to provide a structured progression from the overall system safety process through the individual analyses.
A basic understanding of systems engineering and engineering risk will be useful.
Does the course cover all Mil-Std-882E Tasks 201–210?
Yes.
The current course covers the system safety process and Tasks 201 through 210, including Preliminary Hazard Identification, Preliminary Hazard Analysis, System Requirements Hazard Analysis, Subsystem Hazard Analysis, System Hazard Analysis, Operating and Support Hazard Analysis, Health Hazard Analysis, Functional Hazard Analysis, System-of-Systems Hazard Analysis and Environmental Hazard Analysis. (The Safety Artisan)
Does the course teach me how to use a particular software tool?
The focus is on system safety engineering methods and analysis, rather than training in a particular software package.
The principles can therefore be applied using the tools and processes used by your organisation.
Is this a clause-by-clause explanation of Mil-Std-882E?
No.
The objective is to help you understand and apply the system safety process and associated analyses, rather than simply memorising the wording of the standard.
Can I work through the course at my own pace?
Yes.
The course is delivered online and is designed for self-paced learning.
You can work through the lessons when it suits you and revisit material as required.
How much material is included?
The course currently contains 69 lessons and approximately 10.5 hours of video content, together with supporting transcripts, slides and quizzes. (The Safety Artisan)
Ready to Build Your System Safety Assessment Skills?
You don’t need another collection of disconnected hazard-analysis techniques.
You need to understand how the analyses fit together into a system safety programme.
System Safety Assessment gives you a structured path through the complete Mil-Std-882E Task 201–210 analysis suite.
The Safety Artisan’s Resume, or Curriculum Vitae (CV), if you prefer, is quite long. Why should you listen to me? If you want to know how I know what I know, read on…
Simon Di Nucci – Principal Safety Consultant
BEng, MSc, CPEng, FIE(Aust), NER, Cert CMi, CISSP
Key Skills
Implementing System and Software Safety in Agile programs,
MSc in Safety Critical Systems Engineering (SCSE), University of York BEng (Hons) in Aerospace Systems Engineering, University of Southampton Certificate of Management, Chartered Management Institute. Certified Information Systems Security Professional
Membership of Professional Institutions: Chartered Engineer & Fellow, Engineers Australia National Engineering Register Professional Training Principles of Systems Engineering Ship Safety Management Office (SSMO) Ship Safety Management Course
Since 2012, he has worked in Australia, and before that he worked on major UK, US, and European programs in different regulatory risk frameworks. Simon’s experience includes work on aviation (fast jets, large aircraft, helicopters, ISTAR/EW platforms), submarines, surface vessels, rail, Air Traffic Management, air battle management systems and systems-of-systems.
His wide experience of projects varies from the small, through to some of the largest multi-national defence programs ever undertaken. Simon has more than 20 years’ experience in managing and advising organizations on safety-and-software-related engineering. Simon has been a Chartered Engineer since 1997 and has presented to international conferences in Australia, the US, UK and Canada on seaworthiness, system safety, ship-air integration, and software support. He has designed several safety and airworthiness courses and taught thousands of students.
Work Experience
Career Roles and Responsibilities
System Safety ConsultantAustal Landing Craft Heavy (LC-H) | Jan 26 – present Key Responsibilities: Technical Safety Lead for the Procurement System Safety Program for LC-H: Rewriting the System Safety Program Plan; Conducting System Requirements and Preliminary Hazard Identification & Analyses (SRHA and PHI&A); Writing the Safety Case Report; Leading O&SHA workshops; and Planning and supervising System, Operating & Support, and Zone/Compartment Hazard Analyses. Leidos Sea Archer USV | Sep 25 – Dec 25 Safety assessment of prototype, experimental USV: Using EMSA Risk-Based Assessment Tool (RBAT); and Certification to DNV Autonomous and Remotely Operated Ships (AROS) framework. Australian Nuclear Science & Technology Organisation | Mar 25 – Aug 25 Key Responsibilities: Periodic Safety & Security Review of Nuclear Medicine Facility: In accordance with ARPANSA guidance; Conducting Safety Factor 6, Deterministic Safety Assessment.Intermediate Liquid Waste Capacity Increase Procurement Program: Review and screening of HAZOP results (1,000+ pages); Level Of Protection Analysis for radiological safety. Actinide Suite Laboratory – Quantitative Risk Analysis of legacy research facility. System Safety Discipline LeadRaytheon Australia | Jan 22 – Feb 25 Key Responsibilities: Lead system safety engineer for Raytheon Australia (1,500 staff)Curating the system safety process guidanceRecruiting and competency assessment of safety engineersCreating & providing training to staffFor major programs: Leading safety teams Setting up System Safety Programs & Management SystemsConducting hazard analyses & creating safety casesMajor programs: SEA5011 Maritime EW System of SystemsAIR6500-1 Joint Air Battle Management SystemMobile Threat Training Emitter SystemSpace Surveillance TelescopeLAND 555-6 FLEWS. Contributing to major bids and creating bid estimates.
Frazer-Nash Consultancy | Jan 12 – Dec 21 Key Responsibilities: Business development – aerospace and submarines campaignsSystem Safety Engineering for major programs: Setting up System Safety Programs & Management SystemsConducting hazard analyses & creating safety casesMajor Programs: Collins Life of Type Extension cybersecurity and Integrated Ship Control, Management & Monitoring System safetySEA 1180 Offshore Patrol Vessel, SEA1000 Future Submarine Program (FSP) SCADA systems for explosives & countermeasures productionCybersecurity of rail management systemSafety and Human Factors assessment of Long-Range Air Traffic Flow Management system for Airservices AustraliaPuma HC2 helicopter upgradeAlso, FSP System Integration Laboratory assessment, safety course creation and delivery.
Principal Safety ConsultantQinetiQ Safety Aviation Team | May 06 – Dec 11 Key Responsibilities: Member of business development team, bringing in $24M of repeat and new business, personally achieving $3M of orders in final year System Safety Engineering for major programs: Setting up System Safety Programs & Management SystemsConducting hazard analyses & creating safety casesMajor Programs: Ship Approach and Recovery AidsFast jets – Tornado, Harrier II, Typhoon, and F-35 JSFISTAR platforms – R1 Sentinel (ASTOR), Nimrod MRA4 & RC-135Chinook and Puma HC3Safety/airworthiness course development and presentation:Presenter: UK MoD Safety Management & Safety Tools & Techniques coursesLed course development for EuroFighter Typhoon, R1 Sentinel (ASTOR) system, BAES Harrier II, and Duty Holder Air Safety for UK Military Aviation Authority.
Engineering Manager, UK Royal Air Force | Sep 1986 – July 2006 Key Responsibilities: Senior engineering Authority and Delegation holder on EuroFighter Typhoon; during introduction to service Software Support Consultancy Team Leader, Software and Systems Specialist Officer on EuroFighter Typhoon; Junior engineering manager on Software Integration Laboratory for Tornado F3; Junior engineering manager on Tornado GR1 Squadron; Junior engineering manager on Ground Equipment Bay
Summary of Experience
SEA5011 Maritime EW System of Systems,
AIR6500-1 Joint Air Battle Management System,
Mobile Threat Training Emitter System,
Space Surveillance Telescope,
Collins Life of Type Extension cybersecurity and Integrated Ship Control, Management & Monitoring System safety,
SEA 1180 Offshore Patrol Vessel,
SEA1000 Future Submarine (FSM) Program:
Developed the Program response to the Defence Seaworthiness Management System initiative, and
Part of the team conducting the Competitive Evaluation Program (CEP) on the French, German, and Japanese design submissions, including review of the design, Integrated Logistic Support, risk management and program management elements.
Safety of SCADA systems for explosives and countermeasures production,
Cybersecurity of rail management system; and
Safety and Human Factors assessment of Long-Range Air Traffic Flow Management system for Airservices Australia
Systems and Software Safety in Multiple Regulatory/Risk Frameworks
Development of the safety strategy, SFARP process/statements and the Safety Case Report for multiple systems, and
Wrote the Operating Safety Case report for the Ship Approach and Recovery Aids, including an aircraft carrier and aircraft, including human factors/workload analysis and ship/air integration into the System of Systems.
Airworthiness and Aircraft Safety
Fast jets, including Tornado, Harrier, Typhoon, and the F-35 JSF,
ISTAR platforms including R1 Sentinel (ASTOR), Nimrod MRA4 and RC-135 Rivet Joint,
Chinook and Puma HC3,
Typhoon Engineering Authority and LOD holder:
Managed engineering, logistic support, and airworthiness on a major safety-critical aircraft system, sustaining air operations and bringing needed modifications into service, and
UK delegation leader to international meetings, managing Systems Integration and Software issues for the Typhoon PT.
Combat aircraft operational engineering officer authorised to defer maintenance and accept defects to clear aircraft for flight. Unit Certifying Officer for the Aircraft Nuclear Weapon Armament Electrical Installation. Qualified Weapon Loading Supervisor for tactical nuclear weapons.
Tools and Techniques
Safety Management Systems & Plans,
Goal Structuring Notation,
Safety Cases & Reports,
Functional and Physical hazard identification and analysis,
August 1992 – January 1994 Engineering Operations Manager, 27/12 Squadron
October 1990 – February 1992 Engineering Manager, Ground Support Equipment
Publications
“Risk Based Marine Certification,” 5th Submarine Science, Technology and Engineering Conference (SubSTEC5), November 2019.
“Aircraft Software Certification Strategy,” Aircraft Airworthiness and Sustainment Conference, Brisbane, July 2015.
“Weapon Effects Modelling for Safety Applications,” H. Gordon-Wright, S. Di Nucci*, G. Anderson, A. Keddie, and A Kwong* (*presenters), PARARI, Canberra, 2013.
“Integrated Munition Health Management (IMHM),” on behalf of Dr Steven Wagstaff, PARARI, Canberra, 2013.
“Assuring the Safety of Future Submarines,” Submarine Institute of Australia’s 2nd Technology Conference Science, Technology & Engineering, Adelaide SA, 2013.
“Assuring Operational Systems – a Safety Case Study,” presented to the Systems Software Technology Conference, Salt Lake City, 2008.
“Software Supportability in the Royal Air Force,” Major Willis Jacobs & Flight Lieutenant Simon Di Nucci, Canadian Department of National Defence Software Conference, Ottawa, Feb 2002.
“Software Safety and Supportability Analysis,” Simon Di Nucci, University of York, Sep 2000.
“Airborne Collision Avoidance Systems, Past, Present and Future,” S. Di Nucci, University of Southampton, May 1989.
You can see my profile on LinkedIn, or go back to the Home Page. Subscribe to get a free course with a third-party accredited Certificate and Digital Badge!
At The Safety Artisan, we recently received a Certificate of Appreciation from The Fred Hollows Foundation in recognition of our support. We are genuinely honoured to receive this acknowledgement. More importantly, we are proud to support an organisation whose work has transformed millions of lives around the world.
Our Business is Improving Safety
Our business is improving safety. Every day, we help organisations identify hazards, manage risk, and design systems that protect people. Although our work is focused on engineering, defence, transportation, and other safety-critical industries, our aim is always the same: use knowledge and expertise to improve people’s lives.
The Fred Hollows Foundation embodies that same principle in a different but equally important field.
The Fred Hollows Foundation
Founded on the vision of Professor Fred Hollows, the Foundation works to eliminate avoidable blindness and vision impairment by providing high-quality eye care where it is needed most. Its work extends far beyond performing sight-restoring operations. The Foundation trains local doctors, nurses, and health workers, strengthens healthcare systems, improves access to affordable treatments, and works with communities to create sustainable eye-care services that continue long after individual projects have finished.
The impact is extraordinary. Restoring someone’s sight does much more than improve their health. It enables children to return to school, adults to work and support their families, older people to regain their independence, and entire communities to benefit from increased opportunity and wellbeing. Few medical interventions have such an immediate and life-changing effect.
One aspect of the Foundation’s work that particularly resonates with us is its emphasis on creating sustainable capability. Rather than simply providing short-term assistance, the Foundation invests in local people, local healthcare systems, and long-term solutions. This philosophy mirrors many of the principles we value in systems engineering and system safety. We create solutions that continue to deliver benefits well into the future.
Supporting a Vision Worth Sharing
Businesses of every size have an opportunity to contribute to causes that extend beyond their immediate commercial activities. Supporting organisations such as The Fred Hollows Foundation is one way that companies can help improve lives while contributing to stronger, healthier communities worldwide.
We are therefore delighted to receive this Certificate of Appreciation. Our contribution is small, but we are pleased to play a role in supporting Fred’s remarkable mission.
We would like to thank everyone at The Fred Hollows Foundation for their dedication, compassion, and tireless work. Their commitment has restored sight to millions of people and continues to create opportunities for countless others.
We look forward to continuing our support. We humbly encourage others to learn more about the Foundation’s work and the difference it is making around the world.
If you would like to know more about our work, please click here to receive regular email updates. You can find our suite of Courses here, now with Digital Certificates. Our free blog articles on System Safety are here.
The ISSS Credentialing Initiative: System Safety Professionals. Where is the Next Generation of System Safety Professionals? We need a Workforce Development Program for Safety-Critical Industries.
The International System Safety Society (ISSS) is launching a major credentialing initiative designed to strengthen and expand system safety capability across Canada and the United States.
Developed as a three-year industry partnership and sponsorship program, the initiative will create a structured pathway for professionals working with complex and safety-critical systems. The program combines modular learning, stackable micro-credentials, and verifiable digital certifications to help organizations build a stronger and more resilient safety workforce.
The initiative is being led by an ISSS sub-committee including Jenn Downing, ISSS Director of Education and Professional Development, and Carol-Ann Haggarty.
Why This Initiative Matters
Organizations operating in safety-critical environments face increasing challenges in recruiting, developing, and retaining personnel with the skills required to manage system safety throughout the lifecycle of complex systems.
Whether in defence, aerospace, transportation, energy, healthcare technology, telecommunications, or critical infrastructure, employers require practitioners who understand:
Hazard identification and analysis
Risk assessment and acceptance
Safety assurance and evidence generation
Lifecycle safety management
Safety-informed decision making
The ISSS Credentialing Initiative addresses these challenges by creating a common, industry-recognized framework for developing and validating system safety competencies.
A Three-Year Development and Trial Program
The initiative will be delivered through a structured three-year model.
Year 1 – Build
The first year focuses on developing:
The credentialing framework
Course architecture and learning pathways
Pilot training materials
Instructor guidance
Digital credentialing mechanisms
Evaluation and assessment strategies
Year 2 – Pilot
Pilot courses will be delivered with industry, academic, and professional partners. Feedback will be collected to evaluate:
Learning effectiveness
Practical relevance
User experience
Workforce applicability
Year 3 – Refine and Scale
Following the pilot phase, the program will be refined and prepared for wider deployment across Canada and the United States. The goal is to establish a sustainable and scalable credentialing model that meets long-term workforce needs.
Creating a Workforce Pipeline
The credentialing pathway is designed to support professional development from entry into the workforce through to advanced practice.
The model provides a clear progression:
Students and Early-Career Professionals → ISSS Micro-Credentials → Verified Skills → Industry Deployment → Career Progression
This approach helps organizations identify talent, validate competencies, and accelerate workforce readiness.
Cross-Industry Applicability
A key strength of the program is its portability across industries.
The credentialing model is intended to be standards-aware while remaining industry-neutral, making it applicable to sectors including:
Defence and aerospace
Space systems
Nuclear and energy
Rail and public transit
Automotive and autonomous systems
Medical technology
Mining and industrial operations
Critical infrastructure
Software-intensive systems
Manufacturing and robotics
Telecommunications
Public-sector acquisition
By focusing on disciplined safety thinking, evidence-based assurance, and risk management principles, the framework can support organizations operating under a wide range of regulatory and operational environments.
Benefits for Industry Partners
Industry participation is central to the success of the initiative.
Partner organizations can help ensure that the credentialing framework remains practical, current, and aligned with real workforce requirements. Benefits include:
Improved Workforce Readiness
Employees gain foundational and applied knowledge in system safety principles, reducing training gaps and improving operational effectiveness.
A Common Professional Language
The program promotes alignment across safety, systems engineering, software engineering, quality assurance, human factors, compliance, and program management functions.
Reduced Onboarding Costs
Organizations gain access to personnel with a recognised baseline of knowledge and capability, reducing the need to repeatedly teach foundational concepts internally.
Scalable Capability Development
The modular structure allows organizations to support workforce development at scale while maintaining consistency across teams and locations.
Inclusive Workforce Development
The ISSS Credentialing Initiative is built upon Universal Design for Learning (UDL) principles.
The program seeks to expand access to system safety careers for:
Students
Early-career professionals
Engineers transitioning between industries
Practitioners returning to the workforce
Learning will be delivered through flexible formats, including self-paced modules, micro-learning approaches, and multiple assessment methods.
This inclusive design helps broaden participation, improve learner confidence, and strengthen the long-term safety engineering talent pipeline across North America.
Opportunities for Sponsorship and Partnership
ISSS is currently seeking organizations willing to support the development and trial period through one or more of the following roles:
Sponsors
Provide financial support for:
Curriculum development
Pilot delivery
Evaluation activities
Accessible learning design
Launch preparation
Partners
Support the initiative by:
Nominating pilot participants
Reviewing course relevance
Providing structured feedback
Validating workforce outcomes
Champions
Help expand awareness by connecting ISSS with:
Industry networks
Professional societies
Academic institutions
Government stakeholders
Potential implementation partners
Sponsors may also receive benefits including brand recognition, pilot course access, participation in feedback activities, and discounted access during the formal rollout phase.
The Next Step
The ISSS Credentialing Initiative represents an opportunity to build a sustainable and scalable system safety workforce development framework for North America.
Organizations interested in shaping the future of system safety education and professional development are invited to:
Become a partner
Sponsor the initiative
Nominate pilot participants
Contribute subject matter expertise
Support long-term rollout and adoption
By working together, industry, academia, government, and professional societies can help create a stronger pipeline of qualified professionals capable of supporting the increasingly complex and safety-critical systems upon which modern society depends.
ISSS 2026 Summit & Training (Click on Link in Image)
Hi, I’m Simon Di Nucci. I am a practicing system safety engineer and have been for the last 30 years. I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command-and-control systems, rail, air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!
In this video lesson, I look at Sub-System Hazard Analysis with Mil-Std-882E (SSHA, which is Task 204). I teach the mechanics of the task, but not just that. I’m using my long experience with this Standard to teach a pragmatic approach to getting the work done.
SSHA is designed to be used where a formal Sub-System Specification (SSS) has been created. However, an SSS is not essential to perform this Task. The need for SSHA is usually driven by the complexity of the system and/or that sub-system development is contracted out.
Together, we will explore Task 204’s aim, description, scope, and contracting requirements. There’s value-adding commentary, and I explain the issues with SSHA – how to do it well and avoid the pitfalls.
This is the seven-minute demo, the full video is 40-minutes’ long.
Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial instruction on all things system safety. I’m Simon – I’m your host for today, as always and it’s the fourth of April 22. With everything that’s going on in the world, I hope that this video finds you safe and well.
Sub-System Hazard Analysis
Let’s move straight on to what we’re going to be doing. We’re going to be talking today about subsystem hazard analysis and this is task 204 under the military standard 882E. Previously we’ve done 201, which was preliminary hazard identification, 202, which is preliminary hazard analysis, and 203, which is safety requirements hazard analysis. And with task 204 and task 205, which is system has analysis, we’re now moving into getting stuck into particular systems that we’re thinking about, whether they be physical systems or intangible. We’re thinking about the system under consideration and I’m really getting into that analysis.
Topics for this Session
So, the topics that we’re going to cover today, I’ve got a little preamble to set things in perspective. We then get into the three purposes of task 204. First, to verify compliance. Secondly, to identify new hazards. And thirdly, to recommend necessary actions. That would be recommended control measures for hazards and risks. We’ve got six slides of task description, a couple of slides on reporting, one on contracting, and then a few slides on some commentary where I put in my tuppence worth and I’ll hopefully add some value to the basic bones of the standard.
It’s worth saying that you’ll notice that subsystem is highlighted in yellow and the reason for that is that the subsystem and system hazard analysis tasks are very, very similar. They’re identical except for certain passages and I’ve highlighted those in yellow. Normally I use a yellow highlighter to emphasize something I want to talk about. This time around, I’m using underlining for that and the yellow is showing you what these are different for subsystem analysis as opposed to system [hazard analysis]. And when you’ve watched both sessions on 204 and 205, I think you’ll see the significance of what I’ve done.
Preamble – Sub-system & System HA
Before we get started, we need to explain the system model that the 882 is assuming. If we look at the left-hand side of the hexagons, we’ve got our system in the center, which we’re considering. Maybe that interfaces with other systems. They work within the operating environment; hence we have the icon of the world, and the system and maybe other systems are there for a purpose. They’re performing some task; they’re doing some function and that’s indicated by the tools. We’re using the system to do something, whatever it might be.
Then as we move to the right-hand side, the system is itself broken down into subsystems. We’ve got a couple here. We’ve got sub-systems A and B and then A further broken down into A1 and A2, for example. There’s some sort of hierarchy of subsystems that are coming together and being integrated to form the overall system. That is the overall picture that I’d like to bear in mind while we’re talking about this. The assumption in the 882, is we’re going to be looking at this subsystem hierarchy bottom upwards, largely. We’ll come on to that.
Sub-System Hazard Analysis (T204)
The purpose of the task, as I’ve said before, it’s threefold. We must verify subsystem compliance with requirements. Requirements to deal with risk and hazards. We must identify previously unidentified hazards that may emerge as we’re working at a lower level now. And we must recommend actions as necessary. Those are further requirements to eliminate all hazards or mitigate associated risks. We’ll keep those three things in mind and that will keep coming up.
[Video continues…]
End: Sub-System Hazard Analysis
My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains, aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!
You can find a free pdf of the System Safety Engineering Standard, Mil-Std-882E, here.