TGViewer
TechLead Bits TechLead Bits @techleadbits · 518 subscribers
Post #236 225
STAMP Framework

As I wrote previously I think that the STAMP framework deserves its own overview.

The framework was introduced by MIT professor Nancy Levenson in the book "Engineering a Safer World" in 2011.

STAMP (The System Theoretic Accident Model and Processes) is a functional model of controllers which interact with each other through control actions and feedback:
- A system is considered as a control system.
- The control system consists of hierarchical control-feedback loops.
- Control system enforces safety constraints and prevents accidents.

STAMP is based on 2 main methodologies: Systems-Theoretic Process Analysis (STPA) and Causal Analysis Using System Theory (CAST).

Systems-Theoretic Process Analysis (STPA) - a hazard analysis technique performed at the design stage of the development (proactive analysis):
🔸 Define the purpose. For example, meet RPO\RTO requirements, prevent data loss, meet GDPR requirements, etc.
🔸 Model control structure. Describe and document interactions between key components for this type of hazard.
🔸 Identify unsafe control actions. For example, deploying a new version before testing, failing to scale up during high load, routing traffic to unhealthy backend, etc.
🔸 Identify loss scenarios. Find scenarios that could lead to unsafe actions. For example, failed update causes service outage, broken autoscaling leads to dropped users, etc.
🔸 Define safety constraints. Create controls and design changes to prevent unsafe control actions. For example, any deployment must have rollback strategy, service load must be monitored and alarms must be sent if resources usage exceeds 80%, etc.

Causal Analysis Using System Theory (CAST) - an accident investigation method performed after the incident is occurred (reactive analysis):
🔸 Collect information about the incident.
🔸 Model control structure.
🔸 Analyze each component in loss. Define the reason why the component didn't prevent the incident.
🔸 Identify control structure flaws: communication and coordination, safety management, culture, environment, etc.
🔸 Create improvement program. Prepare recommendations for changes to prevent similar loss in the future.

To sum up, the STAMP framework suggests to enforce safety constraints instead of just trying to prevent system failures. What I really like about this approach is that it allows to incorporate reliability into the system design itself.

P.S. If the topic sounds interesting for you, "Engineering a Safer World" book is available for free at MIT Press.

#engineering #reliability #systemdesign
  • 🔥 2
  • ❤‍🔥 1
More from @techleadbits
  1. Oct 1, 2026Tracer Bullets Continuing the topic from the previous post, let's talk in more detail abou…
  2. Sep 28, 2026Why Software Factories Fail "Read the Code!" is one of the key ideas from Dex Horthy's tal…
  3. Sep 21, 2026Illustrations from The Culture Map showing how different cultures compare on the scales. #…
  4. Sep 21, 2026The Culture Map Have you ever worked in international distributed teams? Or collaborated w…
  5. Sep 10, 2026Loop Engineering from First Principles Continuing the topic of Loop Engineering, I'd like…
  6. Sep 7, 2026Loop Engineering Over the past year, AI has been constantly bringing new terms and practic…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →