That’s why I’m skeptical of people who look at some catastrophic
failure of a complex system and say, “Wow, the odds of this happening
are astronomical. Five different safety systems had to fail
simultaneously!” What they don’t realize is that one or two of those
systems are failing all the time, and it’s up to the other three
systems to prevent the failure from turning into a disaster.
Correlary: if you’re running a system for which five simultaneous failures is a disaster, monitor each safety system seperately and treat any three simultaneous failures as if it were a disaster.
-- Raymond Chen
In other words, some of the slices in one’s Swiss cheese model are actually missing entirely.
Correlary: if you’re running a system for which five simultaneous failures is a disaster, monitor each safety system seperately and treat any three simultaneous failures as if it were a disaster.
Also known as Fundamental Failure Mode. From Systemantics: