Abstract:
For the reactor scram subsystem, the failure and fault coverage statistics form for the instrument control system design phase is deduced by the combined use of three independent basic analysis methods FMEA, FTA, and STPA. STPA method can effectively make up for the inadequacy of FMEA and FTA method. At the same time, in the instrument control system design phase, STPA method is very suitable for finding the fault and safety issues in software, system interaction and communication for the reactor scram subsystems.