Engineering a Safer World¶
Leveson, N. G. (2011). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press.
Cited by¶
7 citations across 7 artifacts.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Boundedness
This sourceBibliography-only (Tier C).
- Containment
This sourceDevelops the STAMP systems-theoretic accident model treating safety as a control problem over hazardous processes. Bibliography-only (tier C); not cited in body.
- Coupling
- Claims that coupled subsystems are "effectively one" should be accompanied by the conditions and approximation regime. Not feedback alone. Feedback is a particular coupling structure (output of A becomes input to A via B), but coupling can exist without feedback (A influences B one-way without B influencing A)
This sourceSTAMP control-structure model represents accidents as inadequate control / missing feedback, distinguishing coupling, feedback, and control structures; supports the not-feedback-alone claim (feedback is a particular coupling structure).
- Claims that coupled subsystems are "effectively one" should be accompanied by the conditions and approximation regime. Not feedback alone. Feedback is a particular coupling structure (output of A becomes input to A via B), but coupling can exist without feedback (A influences B one-way without B influencing A)
- Fail-Safe
- The identification of critical failure modes and definition of what constitutes a "safe" state for each
This sourceDevelops STAMP (Systems-Theoretic Accident Model and Processes), treating safety as an emergent control-structure property and arguing that safe-state definition and the separation of safety constraints from operational control must be intentional and system-wide.
- The identification of critical failure modes and definition of what constitutes a "safe" state for each
- Out Of Distribution Detection
- Engineering: flight envelopes, reactor safe-operating regions, and instrument calibration ranges, where a reading outside the calibrated range is reported as out-of-range rather than with false precision.
This sourceDevelops STAMP and treats safe-operating regions/constraints as engineered bounds on system behavior; supports flight-envelope-style competence bounds as deliberate design limits.
- Engineering: flight envelopes, reactor safe-operating regions, and instrument calibration ranges, where a reading outside the calibrated range is reported as out-of-range rather than with false precision.
- Responsibility Diffusion
- Listed in the references but not attached to a specific claim.
Domain-specific¶
- Fallacy of Composition
- Interface contracts, timing, resource contention, and failure propagation are properties of the configuration, not of a module in isolation
This sourceLeveson establishes the point the example turns on - accidents arise from interactions among components that each met their own specification, so safety is a system property, not a component property; the specific itemisation of timing and resource contention is not hers.
- Interface contracts, timing, resource contention, and failure propagation are properties of the configuration, not of a module in isolation
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Links previously used in the corpus¶
Before the registry existed this work was also linked 2 other ways.
- https://direct.mit.edu/books/oa-monograph/2908/Engineering-a-Safer-WorldSystems-Thinking-Applied ×2
- https://doi.org/10.7551/mitpress/8179.001.0001 ×2
Registry ID ref:95312294add9 · see in the full table