ISO 26262, titled "Road vehicles – Functional safety", is an international standard for functional safety of electrical and/or electronic systems that are installed in serial production road vehicles (excluding mopeds), defined by the International Organization for Standardization (ISO) in 2011, and revised in 2018.
Overview of the standard Functional safety features form an integral part of each automotive product development phase, ranging from the specification, to design, implementation, integration, verification, validation, and production release. The standard ISO 26262 is an adaptation of the functional safety standard IEC 61508 for automotive electric/electronic systems. ISO 26262 defines functional safety for automotive equipment applicable throughout the lifecycle of all automotive electronic and electrical safety-related systems. The first edition (ISO 26262:2011), published on 11 November 2011, was limited to electrical and/or electronic systems installed in "series production passenger cars" with a maximum gross weight of 3,500 kilograms (7,700 lb). The second edition (ISO 26262:2018), published in December 2018, extended the scope from passenger cars to all road vehicles except mopeds. The standard aims to address possible hazards caused by the malfunctioning behaviour of electronic and electrical systems in vehicles. Although entitled "Road vehicles – Functional safety" the standard relates to the functional safety of electrical and electronic systems as well as that of systems as a whole or of their mechanical subsystems. Like its parent standard, IEC 61508, ISO 26262 is a risk-based safety standard, where the risk of hazardous operational situations is qualitatively assessed and safety measures are defined to avoid or control systematic failures and to detect or control random hardware failures, or mitigate their effects. Goals of ISO 26262:
Provides an automotive safety lifecycle (management, development, production, operation, service, decommissioning) and supports tailoring the necessary activities during these lifecycle phases. Covers functional safety aspects of the entire development process (including such activities as requirements specification, design, implementation, integration, verification, validation, and configuration). Provides an automotive-specific risk-based approach for determining risk classes (automotive safety integrity levels, ASILs). Uses ASILs for specifying the items' necessary safety requirements for achieving an acceptable residual risk. Provides requirements for validation and confirmation measures to ensure a sufficient and acceptable level of safety is being achieved.
Parts of ISO 26262 ISO 26262:2018 consists of twelve parts, ten normative parts (parts 1 to 9 and 12) and two guidelines (parts 10 and 11):
Vocabulary Management of functional safety Concept phase Product development at the system level Product development at the hardware level Product development at the software level Production, operation, service and decommissioning Supporting processes Automotive safety integrity level (ASIL)-oriented and safety-oriented analysis Guidelines on ISO 26262 Guidelines on application of ISO 26262 to semiconductors Adaptation of ISO 26262 for motorcycles In comparison, ISO 26262:2011 consisted of just 10 parts, with slightly different naming:
Part 7 was named just Production and operation Part 10 was named Guideline ... instead of Guidelines ... Parts 11 and 12 did not exist.
Part 1: Vocabulary ISO 26262 specifies a vocabulary (a project glossary) of terms, definitions, and abbreviations for application in all parts of the standard. Of particular importance is the careful definition of fault, error, and failure as these terms are key to the standard’s definitions of functional safety processes, particularly in the consideration that "A fault can manifest itself as an error ... and the error can ultimately cause a failure". A resulting malfunction that has a hazardous effect represents a loss of functional safety.
Item Within this standard, item is a key term. Item is used to refer to a specific system (or combination of systems) to which the ISO 26262 safety life cycle is applied, that implements a function (or part of a function) at the vehicle level. That is, the item is the highest identified object in the process and is thereby the starting point for product-specific safety development under this standard. Element Either a system, a component (consisting of hardware parts and/or software units), a single hardware part or a single software unit — effectively, anything in a system that can be distinctly identified and manipulated. Fault Abnormal condition that can cause an element or an item to fail. Error Discrepancy between a computed, observed or measured value or condition, and the true, specified or theoretically correct value or condition. Failure Termination of an intended behaviour of an element or an item due to a fault manifestation. Fault tolerance Ability to deliver a specified functionality in the presence of one or more specified faults. Malfunctioning behaviour Failure or unintended behaviour of an item with respect to its design intent. Hazard Potential source of harm (physical injury or health damage) caused by malfunctioning behaviour of the item. Functional safety Absence of unreasonable risk due to hazards caused by malfunctioning behaviour of electrical/electronic systems.
Note: In contrast to other functional safety standards and the updated ISO 26262:2018, fault tolerance was not explicitly defined in ISO 26262:2011 – since it was assumed impossible to comprehend all possible faults in a system. Note: ISO 26262 does not use the IEC 61508 term safe failure fraction (SFF). The terms single point faults metric and latent faults metric are used instead.
Part 2: Management of functional safety ISO 26262 provides a standard for functional safety management for automotive applications, defining standards for overall organizational safety management as well as standards for a safety life cycle for the development and production of individual automotive products. The ISO 26262 safety life cycle described in the next section operates on the following safety management concepts:
… excerpt ends here. Continue reading the full article.
