Fault-tree minimal cut sets: a worked redundant-pump example
Two 1% pump-failure events, one AND gate, one order-two minimal cut set—and the assumptions required before the familiar 0.0001 result means anything.
Standards · methods · benchmarks
Worked technical notes where every conclusion can be traced to a source, checked against the diagram structure, and reproduced from text.
faulttree "Both pumps fail"
analysis: cutsets, probability
top T = AND(PA, PB)
basic PA "Pump A fails" p: 0.01
basic PB "Pump B fails" p: 0.01RESEARCH LIBRARY / 2026
Standards are named by edition. Calculations show their assumptions. Safety and clinical boundaries stay visible.
Two 1% pump-failure events, one AND gate, one order-two minimal cut set—and the assumptions required before the familiar 0.0001 result means anything.
A standards-grounded crosswalk for choosing rungs, data-flow blocks, or step-transition control—and for knowing when one PLC program should use more than one view.
An ATS is not just a labeled box: a useful one-line must expose normal and emergency sources, the switched connection, downstream bus, ratings, and the protection context reviewers need.
A worked fictional case showing divorce, remarriage, half-siblings, index-person marking, cutoff, and close sibling ties—without collapsing a family system into a pedigree.
A PRISMA figure is not correct because the boxes look familiar. The counts must reconcile from identification through screening, retrieval, eligibility, and inclusion.
Convert component MTBF inputs into mission reliability, reduce two active-parallel pump trains, and identify the shared components that remain single points of failure.
Model a three-channel voting failure, derive its three order-two minimal cut sets, and reconcile the exact 0.001184 top-event probability with the rare-event approximation.

A fictional autosomal-recessive case showing how to record affected, carrier, untested, and unknown states without turning a pattern into a diagnosis.
Work one initiating frequency through three success/failure branches, reconcile four sequence frequencies to 0.04 per year, and roll the adverse outcome up to 0.01264 per year.
Turn seven three-point activity estimates into a 19.17-day schedule, prove the A-C-D-F-G critical path, and separate deterministic PERT arithmetic from schedule risk analysis.
Trace one batch through a simultaneous heat-and-mix split and an exclusive release-or-rework decision, with scan-level invariants that expose the common branch mistakes.
Trace one purchase request through an XOR decision, an AND split, an AND join, and a final XOR decision—with token counts that expose deadlocks and accidental duplicate work.
Turn one branch-office inventory into two non-overlapping IPv4 subnets, map them to VLAN 10 and VLAN 20, and verify every boundary, host address, trunk, and access link.
Reduce a proportional controller, first-order plant, and unity sensor to one transfer function; then verify the pole, time constant, unit-step values, steady-state error, and feedback sign.
Decode the measured variable, instrument functions, shared loop number, signal paths, and fail-closed valve annotation in a worked tank-to-tank P&ID.
Calculate and check three fictional pump PFMEA rows, then see why RPN ranking cannot replace severity review, action evidence, or an approved rating rubric.
Build and check a three-state inspection model, then calculate the two-month distribution, fundamental matrix, absorption probability, and expected time to failure.
Classify two maintenance-backlog feedback loops by tracing change and multiplying link signs, then check the result against Schematex's deterministic loop analysis.
Calculate a 10 kΩ / 10 kΩ divider before and after a 10 kΩ load, then verify the 3.333 V result with KCL, a Thévenin equivalent, and a meter-loading check.
Derive Sum and Cout from all eight A/B/Cin combinations, trace 1 + 0 + 1 through five gates, and verify every row with one binary arithmetic invariant.
Follow two parts through one machine, compute every reachable marking, and use the incidence matrix plus two P-invariants to catch an illegal firing sequence.
An escalation factor is not another threat. Map it to the one barrier it can degrade, then map a separate control to that degradation mechanism.
A non-retentive TON does not add separate bursts of true time. Its input must stay true for the full preset, and one false execution resets elapsed time and the done output.
CPOL chooses the idle clock level; CPHA chooses whether data is captured on the leading or trailing edge. Map all four modes, then trace 0xA6 through an eight-clock Mode 0 transfer.
Scale 4–20 mA to engineering units with the endpoint formula, verify 13.6 mA = 150 kPa, and keep range diagnostics separate from a limited display value.
A 75 kVA, 208 V three-phase transformer with 5% impedance has about 4.16 kA of symmetrical RMS fault current at its secondary terminals under an infinite-source assumption.
Choose the ladder instruction from the input bit's truth value, not the pushbutton's mechanical contact: a healthy N.C. stop loop stored as STOP_OK = 1 needs XIC(STOP_OK).
Classify an IDEF0 arrow by what it does at one function: a requisition is transformed input, policy is control, the buyer and ERP are mechanisms, and the issued purchase order is output.
Calculate host-facing and fabric-facing bandwidth per leaf, state the ratio direction explicitly, and recompute the design after one 100G uplink fails.
Use a filled solid arrow for a synchronous call, an open solid arrow for an asynchronous message, and a dashed arrow for the reply—even when that reply is HTTP 202 Accepted.
Read each endpoint from the opposite table: a circle permits zero, a bar requires one, and the crow's foot permits many. Then check whether the DDL enforces the same minimums.
EDITORIAL METHOD / v1.0
The direct answer appears before background or product context.
Edition, model assumptions, and professional-use limits are explicit.
The diagram is rendered from readable source instead of flattened artwork.
Primary standards and methods sit beside the claim they support.