In the design phase of digital instrument control system, the reactor scram subsystem is a complex system that is constructed by hardware, software, system interaction and communication. So the single analysis method such as FMEA and FTA are all have limitations. FMEA and FTA are all based in the accident model with event chain. FTA is not suitable for the discovery of software and communication failures and other problems with high coupling degree, time series association, constraints of control. Three independent basic analysis methods, FMEA, FTA and STPA, are combined to form the statistica...