STAMP/STPA analysis is an excellent way to find the risk of the systems. However, the STAMP/STPA method doesn't include how to design to prevent/mitigate the risk. The quality of the analysis depends on the analyst's skill. Therefore, I considered how to avoid/reduce the risk using the 4STEP/M method. This presentation reports how to prevent/mitigate the risk using the 4STEP/M method which I analyzed to identify the UCA using the STAMP/STPA analysis for typical web system's development, and this way's usefulness.