IEC 61508 is an international standard published by the International Electrotechnical Commission (IEC) consisting of methods on how to apply, design, deploy and maintain automatic protection systems called safety-related systems. It is titled Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems (E/E/PE, or E/E/PES). IEC 61508 is a basic functional safety standard applicable to all industries. It defines functional safety as: "part of the overall safety relating to the EUC (Equipment Under Control) and the EUC control system which depends on the correct functioning of the E/E/PE safety-related systems, other technology safety-related systems and external risk reduction facilities." The fundamental concept is that any safety-related system must work correctly or fail in a predictable (safe) way. The standard has two fundamental principles:
An engineering process called the safety life cycle is defined based on best practices in order to discover and eliminate design errors and omissions. A probabilistic failure approach to account for the safety impact of device failures. The safety life cycle has 16 phases which roughly can be divided into three groups as follows:
Phases 1–5 address analysis Phases 6–13 address realisation Phases 14–16 address operation. All phases are concerned with the safety function of the system. The standard has seven parts:
Parts 1–3 contain the requirements of the standard (normative) Part 4 contains definitions Parts 5–7 are guidelines and examples for development and thus informative. Central to the standard are the concepts of probabilistic risk for each safety function. The risk is a function of frequency (or likelihood) of the hazardous event and the event consequence severity. The risk is reduced to a tolerable level by applying safety functions which may consist of E/E/PES, associated mechanical devices, or other technologies. Many requirements apply to all technologies but there is strong emphasis on programmable electronics especially in Part 3. IEC 61508 has the following views on risks:
Zero risk can never be reached, only probabilities can be reduced Non-tolerable risks must be reduced (ALARP) Optimal, cost effective safety is achieved when addressed in the entire safety lifecycle Specific techniques ensure that mistakes and errors are avoided across the entire life-cycle. Errors introduced anywhere from the initial concept, risk analysis, specification, design, installation, maintenance and through to disposal could undermine even the most reliable protection. IEC 61508 specifies techniques that should be used for each phase of the life-cycle. The seven parts of the first edition of IEC 61508 were published in 1998 and 2000. The second edition was published in 2010.
Hazard and risk analysis The standard requires that hazard and risk assessment be carried out for bespoke systems: 'The EUC (equipment under control) risk shall be evaluated, or estimated, for each determined hazardous event'. The standard advises that 'Either qualitative or quantitative hazard and risk analysis techniques may be used' and offers guidance on a number of approaches. One of these, for the qualitative analysis of hazards, is a framework based on 6 categories of likelihood of occurrence and 4 of consequence. Categories of likelihood of occurrence
Consequence categories
These are typically combined into a risk class matrix
Where:
Class I: Unacceptable in any circumstance; Class II: Undesirable: tolerable only if risk reduction is impracticable or if the costs are grossly disproportionate to the improvement gained; Class III: Tolerable if the cost of risk reduction would exceed the improvement; Class IV: Acceptable as it stands, though it may need to be monitored.
Safety integrity level
The safety integrity level (SIL) provides a target to attain for each safety function. A risk assessment effort yields a target SIL for each safety function. For any given design the achieved SIL is evaluated by three measures: 1. Systematic Capability (SC) which is a measure of design quality. Each device in the design has an SC rating. The SIL of the safety function is limited to smallest SC rating of the devices used. Requirement for SC are presented in a series of tables in Part 2 and Part 3. The requirements include appropriate quality control, management processes, validation and verification techniques, failure analysis etc. so that one can reasonably justify that the final system attains the required SIL. 2. Architecture Constraints which are minimum levels of safety redundancy presented via two alternative methods - Route 1h and Route 2h. 3. Probability of Dangerous Failure Analysis
Probabilistic analysis The probability metric used in step 3 above depends on whether the functional component will be exposed to high or low demand:
high demand is defined as more than once per year and low demand is defined as less than or equal to once per year (IEC-61508-4). For functions that operate continuously (continuous mode) or functions that operate frequently (high demand mode), SIL specifies an allowable frequency of dangerous failure. For functions that operate intermittently (low demand mode), SIL specifies an allowable probability that the function will fail to respond on demand. Note the difference between function and system. The system implementing the function might be in operation frequently (like an ECU for deploying an air-bag), but the function (like air-bag deployment) might be in demand intermittently.
… excerpt ends here. Continue reading the full article.
