Causal Analysis based on System Theory (CAST) is an accident analysis technique that maximizes learning from accidents and incidents. It is based on the System Theoretic Accident Model and Processes (STAMP) and System Theoretic Process Analysis (STPA).
Cast Handbook: How to Learn More from Incidents and Accidents - By Nancy G. Leveson, MIT
The purpose of CAST can be summarized in four points:
Causal: Don't assume accidents are due to one "root cause" or a few "probable causes", because it turns out that most accidents are actually due to many interacting causes.
Analysis: Don't blame people, because it turns out you learn more by doing a blame-free examinations of why a loss occurred, and how it occurred i.e. "ask why and how, not who".
System: Don't fix just the one thing that broke, because it turns out it's smarter to discover multiple causes, then consider multiple ways to improve the whole system.
Theory: Don't wait until something breaks, because it turns out it's wiser to plan ahead by using scientific control theory and process model theory.
This document is a summary of the CAST Handbook.
Accidents create learning opportunities to look closely at the operation of a system in times of stress, and identify areas for improvement. Examining individual system components can help yet is not enough-- it is necessary to examine the operation of the system as whole.
Include all causes and optimize all learning, in order to improve the system as a whole; do not focus on merely a few “probable causes” or one “root cause”, and do not focus on fixing merely a few areas or one area.
Reduce hindsight bias. A clue that hindsight bias is involved is when you see the words “should have”, “could have”, or “if only”.
Take a system’s view of human behavior. Usually the actions of the operators will be found to be understandable when the reasons for their behaviors are examined.
Provide a blame-free explanation of why the loss occurred; consider “why” and “how” rather than “who.”
Use a comprehensive accident causality model that emphasizes why the controls that were created to prevent the particular type of loss were not effective in the case at hand and how to strengthen the safety control structure to prevent similar losses in the future.
The goal of analysis is to identify the limitations of the safety control structure that allowed the loss and identify how to strengthen the structure in the future.
Control is interpreted broadly and, therefore, includes everything that is currently done in safety engineering, plus more.
Component controls e.g. interlocks, barriers, fail-safes, redundancy, and intentional design.
Process controls e.g. development and training processes, manufacturing processes and procedures, maintenance processes, and general system operating processes.
Social controls e.g. shared value systems, societal and organizational culture and incentive structures, government regulation, insurance, and individual self-interest.
STAMP is the accident causality model that underlies CAST.
STAMP treats accidents as caused by complex interactions among physical systems, humans, and social systems. Safety is treated as a dynamic control problem rather than a failure prevention problem. No causes are omitted from the STAMP model. STAMP changes the emphasis from preventing failures to enforcing constraints on system behavior.
Key advantages:
STAMP applies to very complex systems because it works top-down from a high level of abstraction rather than bottom up.
STAMP includes software, humans, organizations, safety culture, etc. as causal factors in accidents and other types of losses without having to treat them differently or separately.
If STPA was used for designing the system, there will be an explicit listing of the scenarios leading to an accident that were identified and the controls created during system development.
If an STPA analysis for the system already exists, then it will provide a lot of information about what might have gone wrong. Theoretically, the STPA analysis should contain the scenario that occurred. If not, then there was a disconnect between the analysis during development and the operation of the system.
STPA disconnects may include:
The original STPA did not completely specify all the potential scenarios.
The scenario that occurred was identified, but an effective control was not implemented.
The system and its environment may have changed over time after the system went into operation, negating the effectiveness of the designed controls and introducing new causal scenarios that were not analyzed originally.
The values and assumptions in the industry and organization used to make safety-related decisions.
The safety culture in any organization is set by the top management. A sincere commitment by management to safety is often cited as the most important factor in achieving it. Management needs to support employees when they exhibit a reasonable concern for safety in their work and when they put safety ahead of other goals such as schedule and cost.
Negative examples of safety culture are e.g. culture of risk acceptance, culture of denial, culture of compliance, culture of documentation, culture of swagger.
Assumptions are made during system development that are used to design safety into a system. When, over time, those assumptions no longer hold, then the organization is likely to migrate to a state of higher risk.
Systems will always change and evolve over time, as will the environment in which the system operates. Changes may evolve slowly over time and their impact may not be obvious. Because changes are necessary and inevitable, processes must be created to ensure that safety is not degrading.
Leading indicators are commonly used in some industries to identify when the system is migrating toward a state of higher risk. Assumption-based leading indicators, then, can be identified by checking the original assumptions during operations to make sure that they are still true.
CAST involves a paradigm change in the way people think about and identify accident causes. Introducing CAST into an organization may require effort.
Advice:
Grab the opportunity to make changes after a major loss.
Demonstrate that this provides results that are significant improvements, while also being time efficient and cost effective.
Achieve buy-in at the top.
Make the investigation team independent of the management of the group in which the events occurred, and report to a higher level of management.
Starters:
Practicals:
The Evolution of SRE at Google: Using STAMP to improve resilience in Google production systems
What do STAMP-based Analysts Expect from Safety Investigations? - By John Stoop and Ludwig Benner Jr
Books:
Opinions:
27 commits
Causal Analysis based on System Theory (CAST) is an accident analysis technique that maximizes learning from accidents and incidents. It is based on the System Theoretic Accident Model and Processes (STAMP) and System Theoretic Process Analysis (STPA).
Cast Handbook: How to Learn More from Incidents and Accidents - By Nancy G. Leveson, MIT
The purpose of CAST can be summarized in four points:
Causal: Don't assume accidents are due to one "root cause" or a few "probable causes", because it turns out that most accidents are actually due to many interacting causes.
Analysis: Don't blame people, because it turns out you learn more by doing a blame-free examinations of why a loss occurred, and how it occurred i.e. "ask why and how, not who".
System: Don't fix just the one thing that broke, because it turns out it's smarter to discover multiple causes, then consider multiple ways to improve the whole system.
Theory: Don't wait until something breaks, because it turns out it's wiser to plan ahead by using scientific control theory and process model theory.
This document is a summary of the CAST Handbook.
Accidents create learning opportunities to look closely at the operation of a system in times of stress, and identify areas for improvement. Examining individual system components can help yet is not enough-- it is necessary to examine the operation of the system as whole.
Include all causes and optimize all learning, in order to improve the system as a whole; do not focus on merely a few “probable causes” or one “root cause”, and do not focus on fixing merely a few areas or one area.
Reduce hindsight bias. A clue that hindsight bias is involved is when you see the words “should have”, “could have”, or “if only”.
Take a system’s view of human behavior. Usually the actions of the operators will be found to be understandable when the reasons for their behaviors are examined.
Provide a blame-free explanation of why the loss occurred; consider “why” and “how” rather than “who.”
Use a comprehensive accident causality model that emphasizes why the controls that were created to prevent the particular type of loss were not effective in the case at hand and how to strengthen the safety control structure to prevent similar losses in the future.
The goal of analysis is to identify the limitations of the safety control structure that allowed the loss and identify how to strengthen the structure in the future.
Control is interpreted broadly and, therefore, includes everything that is currently done in safety engineering, plus more.
Component controls e.g. interlocks, barriers, fail-safes, redundancy, and intentional design.
Process controls e.g. development and training processes, manufacturing processes and procedures, maintenance processes, and general system operating processes.
Social controls e.g. shared value systems, societal and organizational culture and incentive structures, government regulation, insurance, and individual self-interest.
STAMP is the accident causality model that underlies CAST.
STAMP treats accidents as caused by complex interactions among physical systems, humans, and social systems. Safety is treated as a dynamic control problem rather than a failure prevention problem. No causes are omitted from the STAMP model. STAMP changes the emphasis from preventing failures to enforcing constraints on system behavior.
Key advantages:
STAMP applies to very complex systems because it works top-down from a high level of abstraction rather than bottom up.
STAMP includes software, humans, organizations, safety culture, etc. as causal factors in accidents and other types of losses without having to treat them differently or separately.
If STPA was used for designing the system, there will be an explicit listing of the scenarios leading to an accident that were identified and the controls created during system development.
If an STPA analysis for the system already exists, then it will provide a lot of information about what might have gone wrong. Theoretically, the STPA analysis should contain the scenario that occurred. If not, then there was a disconnect between the analysis during development and the operation of the system.
STPA disconnects may include:
The original STPA did not completely specify all the potential scenarios.
The scenario that occurred was identified, but an effective control was not implemented.
The system and its environment may have changed over time after the system went into operation, negating the effectiveness of the designed controls and introducing new causal scenarios that were not analyzed originally.
The values and assumptions in the industry and organization used to make safety-related decisions.
The safety culture in any organization is set by the top management. A sincere commitment by management to safety is often cited as the most important factor in achieving it. Management needs to support employees when they exhibit a reasonable concern for safety in their work and when they put safety ahead of other goals such as schedule and cost.
Negative examples of safety culture are e.g. culture of risk acceptance, culture of denial, culture of compliance, culture of documentation, culture of swagger.
Assumptions are made during system development that are used to design safety into a system. When, over time, those assumptions no longer hold, then the organization is likely to migrate to a state of higher risk.
Systems will always change and evolve over time, as will the environment in which the system operates. Changes may evolve slowly over time and their impact may not be obvious. Because changes are necessary and inevitable, processes must be created to ensure that safety is not degrading.
Leading indicators are commonly used in some industries to identify when the system is migrating toward a state of higher risk. Assumption-based leading indicators, then, can be identified by checking the original assumptions during operations to make sure that they are still true.
CAST involves a paradigm change in the way people think about and identify accident causes. Introducing CAST into an organization may require effort.
Advice:
Grab the opportunity to make changes after a major loss.
Demonstrate that this provides results that are significant improvements, while also being time efficient and cost effective.
Achieve buy-in at the top.
Make the investigation team independent of the management of the group in which the events occurred, and report to a higher level of management.
Starters:
Practicals:
The Evolution of SRE at Google: Using STAMP to improve resilience in Google production systems
What do STAMP-based Analysts Expect from Safety Investigations? - By John Stoop and Ludwig Benner Jr
Books:
Opinions:
27 commits