HAZOP Analysis of Formal Models of Safety-Critical Interactive Systems

We consider methods for analysing interactive systems for operator errors leading to hazards. We model an industrial case study using formal methods and show how a HAZOP-based approach can be used to determine hazardous operator errors. The analysis can be used to motivate and guide redesign of the system to reduce the likelihood of such errors. The technique is amenable to automation, which we demonstrate using the Possum specification animation tool.