A key part of a demonstration of a system to be safe
is the identification of hazards and an analysis of what to
do about the hazard. Choices for a hazard are to 1) eliminate
it, i.e., make it impossible, 2) reduce the likelihood
of its occurrence, or 3) mitigate its effects. In some cases,
the cause of a hazard can be identified, and then it can be
controlled or even eliminated.
As with other kinds of errors in a system, it is impossible
to predict in advance of deployment and use of the
system, all possible causes of all possible hazards.