Title: Three Mile Island
1Three Mile Island
- What Happened, What Worked, What Didnt
2AGENDA
- The Situation, Events
- Analysis of Events
- Lessons for IT Security
3The Situation
Pennsylvania
4The Reactor
Relief Valve
Reactor
Steam Generators
Main Feedwater Cycle
Secondary feedwater cycle
5The Events
Nasty stuff, fortunately not a lot of it.
1. Secondary feedwater cycle was partially closed
off for maintc.2. Main feedwater pump failed3.
Pressure built up from reactor heat4. Relief
valve stuck OPEN, draining lines5. However,
indicator of high pressure was used to measure
water volume6. Operators assumed too high
volume, shut off rest of main feedwater supply7.
Result was exposed reactor core, no cooling
Relief Valve
Reactor
Steam Generators
Main Feedwater Cycle
6Analysis
- Poor maintenance procedures
- Operators not trained in emergency procedures
- Operators use one item of info as indicator of a
loosely related state - Common-Fault failure made annunciator board
useless - No PR procedures in place
- Civil institutions were not ready
- Quick analysis hindered by common fault failure
7Common Fault Failure
Many things go wrong it is not apparent that
there is a common fault some of the symptoms may
have other, more reasonable causes, crippling
diagnosis
Common Fault
Failures
Effects
8Implications for IS Security
- Maintenance procedures need to be well
documented - Operators should be trained in emergency
procedures - Operators need to know full set of indicators
- Common-Fault failure is likely
- PR procedures must be in place
- Civil institutions must be made ready
- Analysis must be helped by simulation of fault
failures