Research Article

Safety Assessment of the Reconfigurable Integrated Modular Avionics Based on STPA

Table 2

Unsafe control actions.

TypeUCA descriptionPossible hazardsPossible accident

Not providing causes hazard(UCA-01) the IMA system was not reconfigured after CFM2 failedH-1, H-2, H-3A-1, A-2, A-3
Providing causes hazard(UCA-02) the IMA system was incorrectly reconfigured after CFM2 failedH-1, H-2, H-3A-1, A-2, A-3
Provided too late or too early(UCA-03) the IMA system was not reconfigured in time after the failure of CFM2H-1, H-2, H-3A-1, A-2, A-3
Stop too late or too early(UCA-04) the IMA system reconfiguration took too long after CFM2 failedH-1, H-2, H-3A-1, A-2, A-3