Similar fault trees can be developed for estimating P(I5) and
P(I6). The loss of communication (I5) can be divided into two
categories: failure in the communication between the substation
levels (internal) and in the communication with the rest of the
system (external). The former includes the failure of the Ethernet
switches and of the ring buses, while the latter includes the
failure of the gateways. The workstation failure (I6) consists of
the failures in the operator and engineering workstations, which
are fully redundant.
However, the contribution of non-ICT failures to the probability
of operator errors (events I7 and I8) is difficult to estimate
as it depends on the GUI design and on the operators’
performance. Therefore, determining P(I7) and P(I8) requires
the input from electrical utilities on what can result in operators
errors based on their operational experiences.