EDMG611Wk7

profileRawono1
BusinessProcessReengineeringofemergencymanagementprocedures_Acasestudy.pdf

Safety Science 50 (2012) 1368–1376

Contents lists available at SciVerse ScienceDirect

Safety Science

journal homepage: www.elsevier .com/locate /ssc i

Business Process Reengineering of emergency management procedures: A case study

M. Bevilacqua a, F.E. Ciarapica b,⇑, C. Paciarotti a

a Dipartimento di Energetica, Università di Ancona, via Brecce Bianche, 60131 Ancona, Italy b Facoltà di Scienze e Tecnologie, Libera Università di Bolzano, Piazza Università 5, Bolzano, Italy

a r t i c l e i n f o a b s t r a c t

Article history: Received 16 February 2011 Received in revised form 9 November 2011 Accepted 4 January 2012 Available online 9 February 2012

Keywords: Emergency management IDEF0 Information system Information supply Risk information Public Safety management

0925-7535/$ - see front matter � 2012 Elsevier Ltd. A doi:10.1016/j.ssci.2012.01.002

⇑ Corresponding author. Address: Free University Science and Technology, Piazza Universitá 5, Bolzano, fax: +39 0471 017009.

E-mail addresses: [email protected], filippo (F.E. Ciarapica).

The production and storage of dangerous substances in an industrial establishment creates risks for man, environment and properties in the surrounding area. Safety regulations require the establishment of a preventive information campaign regarding industrial risks and self-defence measures to adopt in an emergency situation. In the case of a major accident, people must be promptly made aware of the appro- priate self-defence actions and behaviours to adopt. This strategic activity can reduce the panic effect, make citizens more cooperative and guarantee the effectiveness of any emergency plan. In this paper, the information chain is studied as an industrial process modelled by the IDEF0 language. Through this method, each link in the chain has been deeply analysed. For each function of the process, the inputs, out- puts and necessary controls and resources have been identified. Starting from a clear view of the current state, the process of re-engineering has been implemented to minimise or eliminate downtime, deficien- cies and illnesses and, thus, consequent time losses. The main contribution of the IDEF0 application in emergency management is to provide a clear view of the whole system, a communication system between emergency actors, a rich information source and a structured base for the re-engineering process.

� 2012 Elsevier Ltd. All rights reserved.

1. Introduction

Despite the remarkable technical and scientific progress in the safety field, there is inherent risk in industrial establishments where dangerous substances are produced or stored. Even if risk cannot be avoided, however, it is possible to manage it to contain and minimise the consequences of accidental events.

In Italy, there are 1096 industrial plants classified as highly dan- gerous (i.e., at high risk of a major accident) (Ministry for Environ- ment and Territory and Sea, 2010).

An accident can cause

� a fire, if flammable substances are involved, � an explosion, if propelling substances are involved, � a toxic cloud, if toxic and gaseous substances are involved.

These effects can lead to damage to human health and the surrounding environment. Consequences of an accident may be

ll rights reserved.

of Bolzano-Bozen, Faculty of Italy. Tel.: +39 0471 017220;

[email protected]

observed both inside and outside the industrial plant. An accident may have an impact on firm employees and local residents; real estate and personal property; and land, water and air in the area surrounding the firm. An accident may cause various kinds of damage: death, injuries and burns to man; collapse or damage to assets; and toxic pollution to the environment.

On 10 July 1976, at the ICMESA chemical plant in Seveso, Italy, a bursting disc on a chemical reactor used for the production of tri- chlorophenol failed, causing an uncontrolled exothermic reaction. A dense vapour cloud containing tetrachlorodibenzoparadioxin (TCDD), commonly known as dioxin, was released from the reactor. Although no immediate fatalities were attributed to TCCD, many people fell ill, a number of pregnant women who had been exposed to the release had spontaneous abortions, many animals died, about 10 square miles of land and vegetation were contaminated and 2000 people were treated for poisoning. The Seveso accident was one of the most serious accidents to occur worldwide in the chemical industry, and it has been attributed to a lack of commu- nication between the company and the authorities who were han- dling the situation (Hakkinen, 2005).

The Seveso accident ignited an international debate about safety and environmental protection, and it persuaded the European Community to adopt new regulations aimed at the prevention and control of such accidents:

M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376 1369

� In 1982, Council Directive 82/501/EEC on the major-accident hazards of certain industrial activities (Seveso Directive) was adopted; � On 9 December 1996, Council Directive 96/82/EC on the control

of major-accident hazards (Seveso II Directive) was adopted; � In 2003, the Seveso II Directive was extended by Directive 2003/

105/EC of the European Parliament and the Council of 16 December 2003 amending Council Directive 96/82/EC; � On 21 December 2010, the Commission adopted a proposal for a

new directive that would replace the current directive by 1 June 2015 (European Commission, 2010).

National and International laws introduced a very important innovation in the accident prevention field: they stated that com- petent authorities must inform people living in the areas surround- ing industrial plants about the existence of industrial risk. Furthermore, in the case of an accident, the population must be able to adopt measures of self-protection.

In Italy, a legislative decree requires public and private subjects to perform activities intended to contain and control accidents due to dangerous substances. The drafting of specific emergency plans is required to minimise the effects of an accident and to limit dam- age to man, environment and property:

– The internal emergency plan (IEP) dictates the measures to be taken inside the establishment by the manager and employees in the case of an emergency;

– The external emergency plan (EEP) dictates the measures to be taken outside the establishment. It organises and coordinates the actions of all the subjects involved in the management of a major accident according to the IEP.

2. The external emergency plan (EEP) and the emergency information system

Guidelines aimed at regulating the drafting of EEPs are provided by The National Department of Civil Protection (NDCP); Ministry for the Environment and Territory and Sea; Ministry of the Interior (Firefighters); Ministry of Infrastructure and Transport; Institute for Environmental Protection and Research (ISPRA); Unified Con- ference, Regions and Autonomous Regions; and the Italian Union Province (UPI). The guidelines are intended for prefectures, regions, local governments and establishment operators. Their scope is to provide an operational guide for the drawing and updating of EEPs. Additionally, the NDCP publishes a guide on the emergency infor- mation system for industrial risks.

Drafting an EEP is a complex process because of the security goals that it must address and the variety of institutions involved. The EEP must be re-examined, tested, and, if necessary, reviewed and updated at least every three years. The EEP applies strictly to a specific territory. It must describe the following features:

– territorial displacement, – information on the site with particular focus on the dangerous

substances that are used and stored, – vulnerable territorial and environmental elements.

During the planning phase the following need to be defined:

� alert levels, � correspondence between an alert level and the connected pro-

cedure to follow, � communication flow between emergency managers, � communication flow between emergency managers and exter-

nal people.

Information technologies improve the emergency system’s ability to rapidly deliver disaster information (Chia-Hung et al., 2010).

Tools and materials that could be necessary to handle a specific kind of hazard have to be defined prior to an emergency to facili- tate the response and minimise the intervention time. Thus, it can be useful to arrange contracts and agreements with private companies and public authorities able to provide human resources and services suitable for each type of accident.

The activation of the EEP implies the following communication flows:

– communication about the accident from the firm manager to the fire department,

– communication between the information room (working 24 h/ day) and the actors specified by the EEP,

– communication from the mayor to the local population to inform them about the accident in progress and, if necessary, to spread the order to seek refuge indoors or to evacuate the zone,

– communication between the public administration and the cen- tral administration.

The methods of communications must make use of all the avail- able technological tools.

The efficiency of an EEP is assessed by its ability to promptly ad- dress the industrial emergency and to avoid or reduce the negative consequences on the population and environment. The minimum requirements to make the external plan efficient are:

– alarm system – it is essential to warn rescuers and the popula- tion about the potential oncoming hazard,

– public information – the mayor makes known all information about dangerous substances and potential accidents and their effects on health as well as what kind of self-defence actions and behaviours to adopt,

– territorial vulnerability – the map of vulnerable elements and areas to be promptly rescued.

All of these elements must be present in the planning document.

Periodic drills verify the EEP protection level. A drill must in- volve the population and test the arranged procedures.

The EEP must contain a specific section entitled ‘‘Public Infor- mation in an Emergency’’. The aim of this section is to describe the plan for public authority actions for the prevention of hazards and the minimisation of the consequences of an industrial emergency.

The information distributed to the population about the industrial hazard is aimed at making citizens aware of the exis- tence of the industrial hazard and the possibility of major acci- dent mitigation through self-defence actions and behaviours in compliance with EEP safety measurements. Citizens must learn the correct behavioural response in case of an industrial accident. This knowledge makes territory management easier in an emergency.

During the notification process, it is also important to remem- ber the following:

� do not give alarming messages, � do not underestimate the risks to the population.

Citizens need to understand that various public and private entities manage the risk at different levels but with a coordinated action. Citizens also need to understand that they can cooperate with the organisation by adopting the recommended measures.

Activit

Control

Output

Mechanism

Inputs Activit

Fig. 1. IDEF0 representation of a function and related data and objects.

1370 M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376

The main ideas to transmit are:

� the hazard can be managed, � the hazard consequences can be contained and minimised by

adopting a plan of actions to be performed by different levels of responsibility.

The information recipients are an inhomogeneous group of peo- ple living in the areas potentially affected by the consequences of a major accident. During the planning of the information dissemina- tion, it is necessary to take into account the age, education level and socioeconomic condition of the population; the different vul- nerability levels of some groups (e.g., the elderly, the disabled, the strangers); and the location of vulnerable buildings (e.g., schools, hospitals, shopping centres and other highly attended places).

In the emergency phase, the information is disseminated by

� a warning signal to alert the populace of an accident occurrence; � information about the type of accident and appropriate self-

defence actions to adopt.

In this phase, the information must be concise and instanta- neous and remind people of the recommended behaviour.

A deep understanding of behavioural norms and awareness of the danger sources can reduce the panic effect, make citizens more cooperative and guarantee the effectiveness of the emergency plan. For these reasons, informing the population is a strategic activity. Koehler et al. (2009) emphasised the importance of the informa- tion supply in their research on the risk information gap.

Current standards identify who needs to receive information and provide guidelines for what information to communicate to them. The municipality has to determine how to communicate the information. It requires the development of specific techniques, methods and instruments to make the information transmission efficient. Effective information flow requires the availability of the necessary equipment and effective logistics support (Ikeda et al., 1998). This is a dynamic need subject to continuous develop- ment and improvement.

The present study examines the procedure to be followed to in- form the population of major accident hazards (MAHs) and the behaviours to adopt in the case of a major accident with possible consequences for man and environment outside the establishment. The API petrochemical plant located in the Falconara Marittima Municipality serves as an example for the study. The emergency management logistics chain designed to provide information to the population on MAH is analysed. All the steps and processes necessary to transmit information from the site of the accident to the people living in, and in transit through, the potentially affected area surrounding the accident site are emphasised. This aspect has been analysed because of the great importance given by national and European authorities to major accident prevention and to containment of the consequences for man and environment.

The study of the information system as an industrial process is of great importance. The logistics of information flow are analysed to remove, or at least minimise, downtime, deficiencies and ill- nesses. While these elements usually cause economic losses, in an emergency condition they also result in lost time.

The aim of the study is to clearly and schematically represent the logistics chain for providing information to the population on MAH in emergency management. This representation of the logis- tics needs to be comprehensible also for nonprofessionals, and it must provide a basis for process simulations. The Integration DEF- inition language 0 (IDEF0) technique is used to model the system.

IDEF0 requires the identification of functions inside the logistic process to be analysed. These separate functions are complex

activities which, together, comprise the complete process. A long period of study was necessary to produce the model. It is very important to understand what the result of each function is, how it is realised, who is involved and by whom or what it is influenced. The IDEF0 technique is implemented to achieve improvement in the five critical success factors of emergency management identi- fied by Zhou et al. (2011):

– reasonable organisational structure and clear awareness of responsibilities,

– an effective emergency information system, – unity of government leadership to plan and coordinate as a

whole, – application of modern logistics technology, – continuous improvement of the operational system of emer-

gency management.

3. Method

IDEF0 is a modelling language with graphical and text capabil- ities that provides a standard model for the decisions, functions and activities of a company, process or system. It is based on the Structured Analysis and Design Technique (SADT) developed in 1972 by Douglas T. Ross and SofTech, Inc. (Marca and McGowan, 1988). IDEF0 is now an IEEE Standard (KBSI, 1998).

In each diagram, activities, processes and transformations are represented by boxes that describe their function. Data and objects related to the functions are represented by arrows.

As shown in Fig. 1, the role of an arrow is determined by its rela- tionship to a function box:

– Inputs that are transformed or consumed by the function to pro- duce outputs are represented by arrows entering the left side of the box;

– Controls that specify the conditions required for the function to produce correct outputs are represented by arrows entering the box on the top;

– Outputs that are the data or objects produced by the function are represented by arrows leaving a box on the right side;

– Mechanisms that are the necessary means to execute a function (i.e., human or material resources) are represented by arrows connected to the bottom of the box.

IDEF0 models are created by a bottom-up analysis process, but they have a top-down representation and interpretation.

A model comprises a series of hierarchical diagrams and associ- ated materials. A top-level context diagram, called the A-0 dia- gram, defines the model context and sets the model purpose and viewpoint. The A-0 diagram can be decomposed into sub-functions represented in a child diagram, and each sub-function can be again

M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376 1371

decomposed into low-level child diagrams. The decomposition structure is shown in Fig. 2.

The hierarchical structure allows the representation of any por- tion in detail while also giving an overall view of the system.

The IDEF0 structured analysis method is one of the favoured tools used by industry to understand complex manufacturing situations (Baines and Colquhoun, 1990). IDEF0 can help companies to imple- ment Business Process Reengineering programs (Maull and Childe, 1994). It has been applied to many different sectors. For example, IDEF0 has been used to describe and analyse the business processes of a bank to find critical processes and improve them (Climent et al., 2009). In the agricultural sector, the IDEF0 language has been used to understand and formalise the sugar beet production activity on a French farm (Papajorgji and Pardalos, 2009). In the healthcare sec- tor, IDEF0 has been used to identify vulnerabilities to human error in surgical processes (Kenneth et al., 2010). This paper demonstrates the application of IDEF0 to a new field: emergency management.

Most authors studying emergency plans and emergency handling analyse the robustness of emergency plans and attempt to detect the failures in the plans (e.g., Kanno and Furuta, 2006; Flaus, 2008; Karagiannis et al., 2010). To assist the work of emer- gency planners and reviewers, national emergency management and civil protection authorities of many countries publish emer- gency planning guides. These guides do not suggest specific model- ling tools; instead, they provide only a description of the steps to follow to apply preventive actions in the case of an emergency. This approach is followed by Ramabrahmam et al. (1996) and Ramabrah- mam and Mallikarjunan (1995). Additionally, emergency plans are often outlined by flow diagrams with the purpose of aiding the com- prehension of the plan by an inexpert user (Ramsay, 1999; Tseng et al., 2008). As suggested by Karagiannis et al. (2010), this represen- tation is didactic because it illustrates the sequence of the functions but does not provide an adequate level of detail. In summary, it is useful to introduce to emergency management a tool that is power- ful and easily used by all of the actors in the information logistics chain both before and during an emergency. For this reason, both the complex and powerful models to perform a full risk analysis and the overly simple descriptive guidelines and flow diagrams have been replaced in this paper by the IDEF0 tool. In the information logistics chain, the IDEF0 application has three major uses. First, it

A-0

A0

A24

A2

2 1

3 4

2 1

3

2 1

3

4

A-0

A0A0

A24A24

A2A2

2 1

3 4

2 1

3

2 1

3

4

Fig. 2. Decomposition structure.

may be used during the design stage to facilitate planning by provid- ing a complete overview of the system. Second, this structured anal- ysis can be used for the re-engineering of existing plans by identifying potential pitfalls in the emergency response mechanism. Third, it can be used during the emergency phase to provide complete knowledge of the processes that were implemented.

4. Emergency management in Falconara Marittima Municipality using IDEF0

The municipality of Falconara Marittima is a highly populated area of about 25 square km. The present study examines the procedure to be used to inform people of MAH in case of a major accident in the API petrochemical plant in the municipality with possible consequences for man and environment outside the plant.

The analysis consists of the following steps:

– current state analysis, – design of the ‘‘as-is’’ model using IDEF0, – identification of critical situations and areas for improvement, – development of solutions, beginning with a thorough under-

standing of strategy and goals and consequent Process Reengineering,

– design of the ‘‘to-be’’ model using IDEF0.

The data necessary for the study come from analysis of the API EEP and information from the environmental office of the Falconara Marittima Municipality. An IDEF0 expert coordinated the drafting of the model with the collaboration of a multidisciplin- ary team. Each member of the team provided a partial view of the system; their knowledge was collected together and merged to provide a complete overview of the system. Detailed data collec- tion and an excellent knowledge of the entire system, coming from many different contributions and points of view, are the basic elements necessary to draft a complete and correct model.

The automated function modelling tool AI0 WIN (Knowledge Based Systems, Inc.) was used to support IDEF0.

4.1. The ‘‘as-is’’ model

The input of the information flow chain is the accidental event. The Emergency Coordinator (E.C.) at API must properly and promptly activate the emergency plan. When he receives an emer- gency signal, he evaluates the category of the emergency and acti- vates the internal emergency plan (IEP) and, if necessary, the external emergency plan (EEP).

Accidents can be classified on the basis of their seriousness as follows:

Minor accident – The plant operators manage the accident and no alert is activated. First category accident – The accident is easily managed by the company’s human and material resources. Second category accident – The accident can evolve outward. Intervention from outside responders is required because inter- nal resources could be insufficient. Third category accident (major accident) – The accident causes an emergency situation with effects outside the API refinery. The EEP must be activated.

This study models the third category accident because it is the only one that requires the emergency activation of all of the enti- ties involved in the EEP. This category requires the activation of all of the emergency operating procedures necessary to protect people and provide emergency management.

1372 M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376

The refinery E.C. activates the horn to alert all workers and pop- ulations inside the coverage area of the acoustic alarm. Then he phones the municipality to confirm the EEP activation and to com- municate the accident category and other technical information useful to determine the appropriate activation of operating proce- dures necessary for emergency management.

At the A0 level (Fig. 3), seven connected and cooperating func- tions produce the information flow:

� Environmental office. This office receives the alert call from the refinery E.C. and, based on the technical information and the acci- dent category, launches the emergency plan. Using the plan, the office activates the information room, alerts the mayor and vul- nerable building elements and assigns some of the staff to toll- free number management. The office diffuses information both inside and outside the system. This is a core function, with a large amount of work; its failure causes information flow to halt. � Information room. This room represents the heart of the operat-

ing system; it manages the population alert system. It is not permanently active. Instead, it is managed by an external com- pany that must arrive within 15 min of the alert call to activate the service. � Vulnerable elements. These elements are the most affected by

the direct and indirect risks of an accident. For example, schools, hospitals and centres for people with disabilities are vulnerable elements. � Mayor and town operations centre (T.O.C.). The mayor is respon-

sible for people information and for the activation and manage- ment of the available resources. The T.O.C. supports the mayor in the direction and coordination of emergency services and the assistance to the population.

Fig. 3. A0 level – diagram of p

� Local police and technical office. These are activated by the mayor in the case of an emergency and represent an interface between the administration and the population. When the T.O.C. is active, they play a supportive role for matters relating to road conditions, damage census and materials and tools. The techni- cal office provides the local police with equipment and labour to install roadblocks. Local police give information to drivers about traffic bans and are the contact point for the population. Local police provide information to the population about the proper behaviour to adopt to avoid risks and to not hinder rescue parties. � Press release. Periodically, the mayor issues press releases

through the media to update people about the emergency and any actions they should adopt for self-protection. � Toll-free number. This service is managed by the staff of the

environmental office, and it is the only direct information source. The service operates 24 h a day, does not need setup time and is managed by dedicated staff.

The description of the activities of the system can be easily re- fined into greater detail until the model is as descriptive as neces- sary. In the A0 diagram, some of the functions are complex and composed of sub-functions that may be decomposed, each creating another lower-level child diagram. The second level map divides the previous processes into increasingly fine sub-processes until the appropriate level of detail is reached.

As an example, the decomposition of the information room and mayor/T.O.C. functions are described.

The environmental office activates the information room as sta- ted by the emergency plan. The information room operator is an employee of an external company that manages and performs

ublic information chain.

M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376 1373

maintenance for all the equipment in the room. After the alert call, he has 15 min to put the system into effect. This action has a setup time, and consequently it is a logistical stop that temporarily inter- rupts the information flow. The operator is continuously connected with the environmental office and receives from that office the up- dated operative information. The automated population warning system consists of a transmitting station and an informatics centre that manages the receiving stations and the pre-recorded auto- matic messages. Six fixed receiving stations have been located in

Fig. 4. Information roo

Fig. 5. Mayor/T.O.C.

strategic positions inside the administrative area. They are equipped with an outdoor public warning system that can be used in siren or voice modalities. Additionally, the messages can be directly transmitted by local radio transmitters without the involvement of commercial broadcasters.

To develop an effective emergency warning system, proper equipment maintenance and careful location of the public address system are required. The transmission of information to people about the proper response behaviour for the specific accident is

m decomposition.

decomposition.

Table 1 Influence range of the risk areas.

Event Radius of high- impact area (m)

Radius of medium- impact area (m)

Radius of low- impact area (m)

A 157 273 367 B – 53 81 C 126 152 Not evaluated D 70–150 190 240 E No risk No risk 1860

1374 M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376

the output of this function. Fig. 4 shows the decomposition of the information room function.

After the emergency occurs, the T.O.C., whose composition is determined by the EEP, is convened by the mayor in the local po- lice station. The T.O.C. holds a coordinating role of great impor- tance, as it is in the centre of the system. It receives feedback from all the other functions, constantly updates the provincial civil protection committee about situational developments (e.g., inju- ries, deaths and accident developments), cooperates with the rescue party and disseminates the operating directives. Fig. 5 shows the decomposition of the mayor/T.O.C. function.

5. The ‘‘to-be’’ model/results

Before the re-engineering process, the existing information sys- tem had to be tested.

The EEP provides a list of possible accidental events that could happen in the plant and cause injury and damage in surrounding areas. They have been classified into five groups:

A. explosion or fire causing a cloud of hydrocarbon fumes to be released from the high-pressure plant,

Fig. 6. Risk areas and

B. fire in a tank of a flammable liquid and the resulting emis- sion of combustion products,

C. emission of gas containing sulphate compounds, D. release of liquid or gaseous GPL, E. spread of combustion products resulting from a tank fire.

For each event it is possible to identify the following risk areas:

– High-impact area: high probability of grievous bodily harm and death,

– Medium-impact area: possibility of injuries that could be serious and non-reversible,

– Low-impact area: possibility of non-serious injuries and bodily reactions that could produce a condition of confusion and agitation,

The influence ranges for each of the events and risk areas are shown in Table 1.

A test was performed to verify whether the alarm system was able to effectively cover the urban territory. First, the risk areas were traced on the town map for each possible accident event. Next, the alarms installed in the town were tested to measure the coverage zones reached by the sound emitted by each alarm. Fig. 6 shows an example of the risk areas and coverage zones overlaid on the town map for one of the possible accidental events (an explosion caused by a petrol loss from a T-26-30 column).

Using the maps, a visual comparison can be performed between the risk areas and the coverage zones. The high/medium impact areas are mainly localised inside the plant area; the only external area overlapped by the high/medium impact area is well covered by the alarm system. From this analysis, it is possible to infer that inside the high/medium impact area the alarm system is well dimensioned and no more alarms are necessary.

coverage zones.

M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376 1375

Inside the low impact area, it is very important to avoid the panic effect and to make the presence and activity of the adminis- tration and other officials involved clearly visible to all people. This

Fig. 7. Mayor/T.O.C. decom

Fig. 8. Information room deco

goal is achieved by enhancing the secondary communication chan- nel. To enhance the secondary communication channel, the public information system was reengineered. First, the work team

position: to-be model.

mposition: to-be model.

1376 M. Bevilacqua et al. / Safety Science 50 (2012) 1368–1376

provided some ideas and solutions. Next, these suggestions were collected and enriched by the expert coordinator. Together with the work team, the coordinator proposed the two innovations, which are described below. The new system is represented in the ‘‘to-be’’ model using IDEF0.

In the ‘‘to-be’’ model, the toll-free number becomes a function of the mayor and T.O.C. (Fig. 7). The T.O.C. receives feedback from on-field operators and disseminates the operating directives; thus, providing it with a clearer vision of the whole system. For this rea- son, the T.O.C. is best suited for the function of determining the information and directives to be communicated. Consequently, it was given the toll-free number management authority. The T.O.C. is located in the local police station, which is guarded by police officers 24 h a day. At the beginning of the emergency, the local po- lice officers can immediately answer phones. After the EEP activa- tion, the phone service is placed in the care of trained volunteers in the local civil protection group.

With this change, the environmental office requires fewer hu- man resources, and it can focus on its core business: activating the alert process promptly and efficiently. This leads to an impor- tant improvement in the logistics of the system: the time optimi- sation of the information flow.

Additionally, in the ‘‘to-be’’ model, the public warning system is enriched by the introduction of electronic information panels. It is possible to easily edit a text with a computer or an alphanumeric keyboard and send it to the panels, which are located on major access roads. In the case of a major accident, drivers can be promptly informed. This action prevents driver entry into the un- safe territory and consequent contact with toxic substances. Thus, the risk for this group is reduced to a very low level.

Fig. 8 shows the change to the information room decomposition (A22 diagram) with the introduction of this second re-engineering. Electronic information panels require an ADSL line and an electri- cal supply connection; these are the only mechanisms in the IDEF0 representation. The controls are equipment maintenance and cor- rect placement of the panels for visibility.

However, the actual economic resources available from the municipality limited the introduction of the most advanced equip- ment and technology and the use of additional workforce.

6. Conclusions

The application of the IDEF0 method in the field of safety, espe- cially in emergency management, provides great advantages and potential for the improvement of public safety.

The IDEF0 model is incredibly rich in information. It provides a complete and consistent model for the functions (i.e., activities, ac- tions, processes and operations) required by a public information chain in an emergency and the relationships and data that support the integration of those functions. The system description is sys- tematic and sequential, thus it is easy to understand.

The hierarchical structure allows the representation of any por- tion of the information flow chain in detail and also provides an overall view of the system.

The use of such a representation enhances communication be- tween emergency system analysts, developers and users. It permits all the actors involved, each with different competencies and responsibilities in the emergency, to work on different aspects of the total system and yet produce a consistent result in the final system integration. Thereby, the IDEF0 modelling technique pro- vides an efficient communication vehicle between diverse actors.

The model provides an aid in process analysis and design for the purposes of reimplementation or reengineering. In the safety field,

it is very important that the system analysts and developers can see and manage a model of the processes before they are imple- mented. The analysis of the to-be model allows the prediction of the critical points of the new processes and their eventual elimina- tion before the implementation of changes. The model provides an overall view of the system, and a great deal of information (e.g., in- puts, outputs, controls and mechanisms) is summarised and dis- played in a single model. This model completeness allows one to directly see the effect of a change on all the system components.

The rigorousness and precision of the method can lead to a learning period for new modellers. This learning period is first spent in understanding IDEF0 itself and then in learning to use the computer applications supporting it.

In conclusion, the IDEF0 technique applied to the modelling of the public information chain in an emergency, and in the general management of risk by a civil protection department and local and national administrations, is a very efficient instrument for the improvement of human safety.

References

Baines, R.W., Colquhoun, G.J., 1990. An integration and analysis tool for engineers. Assembly Automation 10 (3), 141–145.

Chia-Hung, S., Yamamura, S., Chen, C.Y., 2010. Analysis of control structure for turning maneuvers. Hindawi Publishing Corporation. Mathematical Problems in Engineering 2010 (2010), 11 pages, doi:10.1155/2010/481438.

Climent, C., Mula, J., Hernández, J.E., 2009. Improving the business processes of a bank. Business Process Management Journal 15 (2), 201–224.

European Commission, 2010. Proposal for a ‘‘Directive Of The European Parliament And Of The Council’’ on control of major-accident hazards involving dangerous substances. Brussels, 21.12.2010.

Flaus, J.M., 2008. A model-based approach for systematic risk analysis. Journal of Risk and Reliability 222 (1), 79–93.

Hakkinen, P.J., 2005. Seveso Disaster, and the Seveso and Seveso II Directives Encyclopedia of Toxicology. Elsevier, pp. 1–4.

Ikeda, Y., Beroggi, G.E.G., Wallace, W.A., 1998. Supporting multi-group emergency management with multimedia. Safety Science 30, 223–234.

Kanno, T., Furuta, K., 2006. Resilience of Emergency Response Systems, 2nd Symposium on Resilience Engineering, Juan-les-Pins, France.

Karagiannis, G.M., Piatyszek, E., Jean-Marie Flausb, J.M., 2010. Industrial emergency planning modeling: a first step toward a robustness analysis tool. Journal of Hazardous Materials 181 (1–3), 324–334.

KBSI, 1998. IEEE Standard for Functional Modeling Language—Syntax and Semantics for IDEF0. IEEE Std 1320.1-1998. IEEE.

Kenneth, B., Horvat, J., Starkey, M., Kim, R., Phipps, S., Gibson, P., 2010. Early-life chlamydial lung infection enhances allergic airways disease through age- dependent differences in immunopathology. Journal of Allergy and Clinical Immunology 125 (3), 617–625.

Koehler, J., Dreijerink, L., Van Poll, R., 2009. Exploring the risk information gap. Research into information supply and information demand of different parties concerned. Safety Science 47, 554–560.

Marca, D.A., McGowan, C.L., 1988. SADT: Structured Analysis and Design Technique. McGraw-Hill Book Co., Inc., New York, NY.

Maull, R., Childe, S., 1994. Business process re-engineering: an example from the banking sector. International Journal of Service Industry Management 5 (3), 26– 34.

Ministry for Environment and Territory and Sea, 2010. Inventario nazionale degli stabilimenti suscettibili di causare incidenti rilevanti ai sensi dell’art. 15, comma 4 del decreto legislativo 17 agosto 1999, n, 334 e s.m.i.

Papajorgji, P.J., Pardalos, P.M., 2009. Advances in Modeling Agricultural Systems, vol. 25. Springer Optimization and its Applications. X, 522, p. 172.

Ramabrahmam, B.V., Mallikarjunan, M.M., 1995. Model off-site emergency plan. Case study: toxic gas release from a fertilizer unit. Journal of Loss Prevention in the Process Industries 8 (6), 343–348.

Ramabrahmam, B.V., Sreenivasulu, B., Mallikarjunan, M.M., 1996. Model on-site emergency plan. Case study: toxic gas release from an ammonia storage terminal. Journal of Loss Prevention in the Process Industries 9 (4), 259–265.

Ramsay, C., 1999. Protecting your business: from emergency planning to crisis management. Journal of Hazardous Materialsr 65, 131–149.

Tseng, J.M., Liu, M.Y., Chang, R.H., Su, J.L., Shu, C.M., 2008. Emergency response plan of chlorine gas for process plants in Taiwan. Journal of Loss Prevention in the Process Industries 21, 393–399.

Zhou, Q., Huang, W., Zhang, Y., 2011. Identifying critical success factors in emergency management using a fuzzy DEMATEL method. Safety Science 49 (2), 243–252.