FSD501: Safety Manual Requirements

Header

Title

FSD501: Safety Manual Requirements

Version

V1

Products

Safety Simplifier

Requirements

61508-2 annex D, 61508-3 annex D

Purpose

Define the requirements for the safety manual.

Input

N/A

Output

N/A

Table of contents

Description

This document specifies the safety manual requirements identified from the output of phase 10.3 and during the development of the product, as well as the applicable requirements from EN 61508-2 Annex D and EN61508-3 Annex D.

ID

Title

Status

EN_61508_2_D_2_1_a

61508-2 Annex D.2.1 a)

PASS

EN_61508_2_D_2_1_b

61508-2 Annex D.2.1 b)

PASS

EN_61508_2_D_2_1_c

61508-2 Annex D.2.1 c)

PASS

EN_61508_2_D_2_2_a

61508-2 Annex D.2.2 a)

PASS

EN_61508_2_D_2_2_b

61508-2 Annex D.2.2 b)

PASS

EN_61508_2_D_2_2_c

61508-2 Annex D.2.2 c)

PASS

EN_61508_2_D_2_2_d

61508-2 Annex D.2.2 d)

PASS

EN_61508_2_D_2_2_e

61508-2 Annex D.2.2 e)

PASS

EN_61508_2_D_2_2_f

61508-2 Annex D.2.2 f)

PASS

EN_61508_2_D_2_2_g

61508-2 Annex D.2.2 g)

PASS

EN_61508_2_D_2_2_h

61508-2 Annex D.2.2 h)

PASS

EN_61508_2_D_2_2_i

61508-2 Annex D.2.2 i)

PASS

EN_61508_2_D_2_2_j

61508-2 Annex D.2.2 j)

PASS

EN_61508_2_D_2_2_k

61508-2 Annex D.2.2 k)

PASS

EN_61508_3_D_1_1

61508-3 Annex D.1.1

PASS

EN_61508_3_D_1_2

61508-3 Annex D.1.2

PASS

EN_61508_3_D_1_3

61508-3 Annex D.1.3

PASS

EN_61508_3_D_2_1

61508-3 Annex D.2.1

PASS

EN_61508_3_D_2_2

61508-3 Annex D.2.2

PASS

EN_61508_3_D_2_3_a

61508-3 Annex D.2.3 a)

PASS

EN_61508_3_D_2_3_b

61508-3 Annex D.2.3 b)

PASS

EN_61508_3_D_2_3_c

61508-3 Annex D.2.3 c)

PASS

EN_61508_3_D_2_4_a

61508-3 Annex D.2.4 a)

PASS

EN_61508_3_D_2_4_b

61508-3 Annex D.2.4 b)

PASS

EN_61508_3_D_2_4_c

61508-3 Annex D.2.4 c)

PASS

EN_61508_3_D_2_4_d

61508-3 Annex D.2.4 d)

PASS

EN_61508_3_D_2_4_e

61508-3 Annex D.2.4 e)

PASS

EN_61508_3_D_2_4_f

61508-3 Annex D.2.4 f)

PASS

EN_61508_3_D_2_4_g

61508-3 Annex D.2.4 g)

PASS

EN_61508_3_D_2_4_h

61508-3 Annex D.2.4 h)

PASS

EN_61508_3_D_2_4_i

61508-3 Annex D.2.4 i)

PASS

EN_61508_3_D_2_4_j

61508-3 Annex D.2.4 j)

PASS

EN_61508_3_D_2_4_k

61508-3 Annex D.2.4 k)

PASS

EN_61508_3_D_2_4_l

61508-3 Annex D.2.4 l)

PASS

EN_61508_3_D_2_4_m

61508-3 Annex D.2.4 m)

PASS

EN_61508_3_D_2_4_n

61508-3 Annex D.2.4 n)

PASS

EN_61508_3_D_3_1

61508-3 Annex D.3.1

PASS

EN_61508_3_D_3_2

61508-3 Annex D.3.2

PASS

EN_61508_3_D_3_3

61508-3 Annex D.3.3

PASS

Motivations 61508-2 chapter 7.6.2

Motivation: EN-61508-2 clause 7.6.2.1 MOTIVATION_501_001
status: PASS

a) No parts with pre-defined life in the Safety Simplifier. See manual section 1.6. Replacement of a Safety Simplifier unit is done by replacement of the entire unit.

b) Throughout the manual. See mainly manual chapter 3.

c) Formulas for PFH-d values are in chapter 9 and calculating reaction time chapter 10. See also chapter 4.1

d) See RISE test report in manual.

e) See section 1.6.

f) See section 1.6.

g) See section 1.6 and chapter 13.

Motivation: EN-61508-2 clause 7.6.2.2 MOTIVATION_501_002
status: PASS

The manual is continuously updated. Every work package (FSWPxxxx) specifies the necessary changes to the manual under “Manuals/Documentation”. The procedure for developing new function blocks include specifying the necessary changes to the manual. The latest version of the manual is always available from SSP North and directly in the PC configuration tool (Simplifier Manager).

Motivation: EN-61508-2 clause 7.6.2.3 MOTIVATION_501_003
status: PASS

The manual adds requirement to restart the product at least once per year. This is due to some internal tests are only made at startup.

Besides this:

  1. The Hardware evaluation report shows that lifetime of the product is maximum (10 years).

  2. We have continuous internal checking of the subsystem (DC>99%), thus, errors are found automatically (by entering safe state).

Motivation: EN-61508-2 clause 7.6.2.4 MOTIVATION_501_004
status: PASS

The only maintenance requirement for a working system is to restart it at least once per year. As the Simplifier works in high-/continuous mode of operation and all outputs fall (turn off) for fatal error, an EUC cannot be designed to have a dangerous situation due to restart.

Motivation: EN-61508-2 clause 7.6.2.5 MOTIVATION_501_005
status: PASS

See FSD303: Techniques and measures.

Motivation: Voltages in manual MOTIVATION_501_100
status: PASS

Chapter 4 technical data contains the minimum and maximum voltages for the power supply.

Motivation: Restart once per year MOTIVATION_501_101
status: PASS
Source: DREQ_112A

Chapter 3.

Motivation: Storage and operating environment MOTIVATION_501_102
status: PASS

Chapter 4 technical data contains the storage and operating temperature requirements for the Safety Simplifier.

Motivation: USB programming MOTIVATION_501_103
status: PASS

Chapter 13.8.2

Motivation: Radio programming MOTIVATION_501_104
status: PASS

Chapter 13.8.3

Motivation: USB programming and configuration MOTIVATION_501_105
status: PASS

Chapter 13.8.2

Motivation: CAN programming and configuration MOTIVATION_501_106
status: PASS

SimpleCAN manual.

Motivation: User qualification MOTIVATION_501_107
status: PASS

Chapter 1.4.

Motivation: Incident reporting MOTIVATION_501_108
status: PASS

Chapter 1.3.

Motivation: Fatal error codes MOTIVATION_501_109
status: PASS

PC software displays error codes in the event of a fatal error. Manual lists all fatal error codes in chapter 11.9.3.16.

Requirements

Requirement: Hazard information MANUALREQ_501_001
status: PASS
tags: manual

The user manual shall contain information and warnings for potential hazards. Customers are responsible for reporting hazardous incidents to SSP North AB, and this shall be documented in the user manual.

RESULT: Hazard information RESULT_501_001
status: PASS

Hazards are clearly noted with symbols in separate sections in the manual. See 1.1.2. Details of how to contact SSP North AB are provided in the manual, see 1.3.

Requirements from 61508-2 Annex D

Requirement: 61508-2 Annex D.2.1 a) EN_61508_2_D_2_1_a
status: PASS
tags: manual-61508

The safety manual shall include a functional specification of the functions capable of being performed.

Requirement: 61508-2 Annex D.2.1 b) EN_61508_2_D_2_1_b
status: PASS
tags: manual-61508

The safety manual shall include identification of the hardware and/or software configuration of the compliant item to enable configuration management of the E/E/PE safety-related system in accordance with 6.2.1 of IEC 61508-1.

Requirement: 61508-2 Annex D.2.1 c) EN_61508_2_D_2_1_c
status: PASS
tags: manual-61508

The safety manual shall include constraints on the use of the compliant item and/or assumptions on which analysis of the behaviour or failure rates of the item are based.

Requirement: 61508-2 Annex D.2.2 a) EN_61508_2_D_2_2_a
status: PASS
tags: manual-61508

The safety manual shall include the failure modes of the compliant item (in terms of the behaviour of its outputs), due to random hardware failures, that result in a failure of the function and that are not detected by diagnostics internal to the compliant item.

Requirement: 61508-2 Annex D.2.2 b) EN_61508_2_D_2_2_b
status: PASS
tags: manual-61508

The safety manual shall include for every failure mode in a), an estimated failure rate.

Requirement: 61508-2 Annex D.2.2 c) EN_61508_2_D_2_2_c
status: PASS
tags: manual-61508

The safety manual shall include the failure modes of the compliant item (in terms of the behaviour of its outputs), due to random hardware failures, that result in a failure of the function and that are detected by diagnostics internal to the compliant item.

Requirement: 61508-2 Annex D.2.2 d) EN_61508_2_D_2_2_d
status: PASS
tags: manual-61508

The safety manual shall include the failure modes of the diagnostics, internal to the compliant item (in terms of the behaviour of its outputs), due to random hardware failures, that result in a failure of the diagnostics to detect failures of the function.

Requirement: 61508-2 Annex D.2.2 e) EN_61508_2_D_2_2_e
status: PASS
tags: manual-61508

The safety manual shall include for every failure mode in c) and d), the estimated failure rate.

Requirement: 61508-2 Annex D.2.2 f) EN_61508_2_D_2_2_f
status: PASS
tags: manual-61508

The safety manual shall include for every failure mode in c) that is detected by diagnostics internal to the compliant item, the diagnostic test interval.

Requirement: 61508-2 Annex D.2.2 g) EN_61508_2_D_2_2_g
status: PASS
tags: manual-61508

The safety manual shall include for every failure mode in c) the outputs of the compliant item initiated by the internal diagnostics.

Requirement: 61508-2 Annex D.2.2 h) EN_61508_2_D_2_2_h
status: PASS
tags: manual-61508

The safety manual shall include any periodic proof test and/or maintenance requirements.

Requirement: 61508-2 Annex D.2.2 i) EN_61508_2_D_2_2_i
status: PASS
tags: manual-61508

The safety manual shall include for those failure modes, in respect of a specified function, that are capable of being detected by external diagnostics, sufficient information shall be provided to facilitate the development of an external diagnostic capability. The information shall include details of failure modes and for those failure modes the failure rates.

Requirement: 61508-2 Annex D.2.2 j) EN_61508_2_D_2_2_j
status: PASS
tags: manual-61508

The safety manual shall include the hardware fault tolerance.

Requirement: 61508-2 Annex D.2.2 k) EN_61508_2_D_2_2_k
status: PASS
tags: manual-61508

The safety manual shall include the classification as type A or type B of that part of the compliant item that provides the function (see 7.4.4.1.2 and 7.4.4.1.3).

1. Requirements from 61508-3 Annex D

Requirement: 61508-3 Annex D.1.1 EN_61508_3_D_1_1
status: PASS
tags: manual-61508

When an element is re-used or is intended to be re-used in one or more other system developments, it is necessary to ensure that the element is accompanied by a sufficiently precise and complete description (i.e. functions, constraints and evidence), to make possible an assessment of the integrity of a specific safety function that depends wholly or partly on the element. This shall be implemented by means of a safety manual.

Requirement: 61508-3 Annex D.1.2 EN_61508_3_D_1_2
status: PASS
tags: manual-61508

The safety manual may consist of the element supplier’s documentation if this is adequate to meet the requirements of Annexe D of IEC 61508-2 and of this annex. Otherwise it should be created as part of the design of the safety related system.

Requirement: 61508-3 Annex D.1.3 EN_61508_3_D_1_3
status: PASS
tags: manual-61508

The safety manual shall define the attributes of an element, which may comprise hardware constraints and/or software of which the integrator shall be aware and take into consideration during application. In particular it forms the vehicle for informing the integrator of its properties and what the element was designed for, its behaviour and characteristics.

Requirement: 61508-3 Annex D.2.1 EN_61508_3_D_2_1
status: PASS
tags: manual-61508

The safety manual shall contain all the information required by IEC 61508-2 Annex D, that is relevant to the element. E.g. the hardware-related items of IEC 61508-2 Annex D are not relevant to a purely software element.

Requirement: 61508-3 Annex D.2.2 EN_61508_3_D_2_2
status: PASS
tags: manual-61508

The element shall be identified and all necessary instructions for its use shall be available to the integrator.

Requirement: 61508-3 Annex D.2.3 a) EN_61508_3_D_2_3_a
status: PASS
tags: manual-61508

The configuration of the software element, the software and hardware run-time environment and if necessary the configuration of the compilation / link system shall be documented in the safety manual.

Requirement: 61508-3 Annex D.2.3 b) EN_61508_3_D_2_3_b
status: PASS
tags: manual-61508

The recommended configuration of the software element shall be documented in the safety manual and that configuration shall be used in safety application.

Requirement: 61508-3 Annex D.2.3 c) EN_61508_3_D_2_3_c
status: PASS
tags: manual-61508

The safety manual shall include all the assumptions made on which the justification for use of the element depends.

Requirement: 61508-3 Annex D.2.4 a) EN_61508_3_D_2_4_a
status: PASS
tags: manual-61508

Competence: The minimum degree of knowledge expected of the integrator of the element should be specified, i.e. knowledge of specific application tools.

Requirement: 61508-3 Annex D.2.4 b) EN_61508_3_D_2_4_b
status: PASS
tags: manual-61508

Degree of reliance placed on the element: Details of any certification of the element, independent assessment performed, integrity to which the integrator may place on the pre-existing element. This should include the integrity to which the element was designed, the standards that were followed during the design process, and any constraints passed to the integrator which shall be implemented in support of the systematic capability claimed. (depending on the functionality of the element, it is conceivable that some requirements may only be met at the integration phase of a system. In such circumstances, these requirements shall be identified for further progression by the integrator. Requirements pertaining to response times and performance are two such examples).

Requirement: 61508-3 Annex D.2.4 c) EN_61508_3_D_2_4_c
status: PASS
tags: manual-61508

Installation instructions: Details of, or reference to, how to install the pre-existing element into the integrated system.

Requirement: 61508-3 Annex D.2.4 d) EN_61508_3_D_2_4_d
status: PASS
tags: manual-61508

The reason for release of the element: Details of whether the pre-existing element has been subject to release to clear outstanding anomalies, or inclusion of additional functionality.

Requirement: 61508-3 Annex D.2.4 e) EN_61508_3_D_2_4_e
status: PASS
tags: manual-61508

Outstanding anomalies: Details of all outstanding anomalies should be given, with explanation of the anomaly, how it occurs and the mechanisms that the integrator shall take to mitigate the anomaly should the particular functions be used.

Requirement: 61508-3 Annex D.2.4 f) EN_61508_3_D_2_4_f
status: PASS
tags: manual-61508

Backward compatibility: Details of whether the element is compatible with previous releases of the sub-system, and if not, details of the process providing the upgrade path to be followed.

Requirement: 61508-3 Annex D.2.4 g) EN_61508_3_D_2_4_g
status: PASS
tags: manual-61508

Compatibility with other systems: A pre-existing element may be dependent upon a specially developed operating system. In such circumstances, details of the version of the specially developed operating system should be detailed. The build standard should also be specified incorporating compiler identification and version, tools used in creation of the pre-existing element (identification and version), and test pre-existing element used (again identification and version).

Requirement: 61508-3 Annex D.2.4 h) EN_61508_3_D_2_4_h
status: PASS
tags: manual-61508

Element configuration: Details of the pre-existing element name(s) and description(s) should be given, including the version / issue / modification state.

Requirement: 61508-3 Annex D.2.4 i) EN_61508_3_D_2_4_i
status: PASS
tags: manual-61508

Change control: The mechanism by which the integrator can initiate a change request to the producer of the software.

Requirement: 61508-3 Annex D.2.4 j) EN_61508_3_D_2_4_j
status: PASS
tags: manual-61508

Requirements not met: It is conceivable that there may exist specific requirements that have been specified, but have not been met in the current revision of the element. In such circumstances, these requirements should be identified for the integrator to consider.

Requirement: 61508-3 Annex D.2.4 k) EN_61508_3_D_2_4_k
status: PASS
tags: manual-61508

Design safe state: In certain circumstances, upon controlled failure of the system application, the element may revert to a design safe state. In such circumstances, the precise definition of design safe state should be specified for consideration by the integrator.

Requirement: 61508-3 Annex D.2.4 l) EN_61508_3_D_2_4_l
status: PASS
tags: manual-61508

Interface constraints: Details of any specific constraints, in particular user interface requirements shall be identified.

Requirement: 61508-3 Annex D.2.4 m) EN_61508_3_D_2_4_m
status: PASS
tags: manual-61508

Details of any security measures that may have been implemented against listed threats and vulnerabilities.

Requirement: 61508-3 Annex D.2.4 n) EN_61508_3_D_2_4_n
status: PASS
tags: manual-61508

Configurable elements: details of the configuration method or methods available for the element, their use and any constraints on their use shall be provided.

Requirement: 61508-3 Annex D.3.1 EN_61508_3_D_3_1
status: PASS
tags: manual-61508

All claims in the safety manual for compliant items shall be justified by adequate supporting evidence. See 7.4.9.7 of IEC 61508-2.

Requirement: 61508-3 Annex D.3.2 EN_61508_3_D_3_2
status: PASS
tags: manual-61508

The supporting evidence that justifies the claims in the safety manual for compliant items is distinct from the element safety manual.

Requirement: 61508-3 Annex D.3.3 EN_61508_3_D_3_3
status: PASS
tags: manual-61508

Where the evidence cannot be made available to facilitate functional safety assessment, then the element is not suitable for use in E/E/PE safety-related systems.

5. Motivations

Motivation: 61508-2 Annex D.2.1 a) MOTIVATION_EN_61508_2_D_2_1_a
status: PASS

Manual ref: The whole manual, especially: 2, 14

Motivation: 61508-2 Annex D.2.1 b) MOTIVATION_EN_61508_2_D_2_1_b
status: PASS

Manual ref: 1, 2, 3

Motivation: 61508-2 Annex D.2.1 c) MOTIVATION_EN_61508_2_D_2_1_c
status: PASS

Manual ref: 3

Motivation: 61508-2 Annex D.2.2 a) MOTIVATION_EN_61508_2_D_2_2_a
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 b) MOTIVATION_EN_61508_2_D_2_2_b
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 c) MOTIVATION_EN_61508_2_D_2_2_c
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 d) MOTIVATION_EN_61508_2_D_2_2_d
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 e) MOTIVATION_EN_61508_2_D_2_2_e
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 f) MOTIVATION_EN_61508_2_D_2_2_f
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 g) MOTIVATION_EN_61508_2_D_2_2_g
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 h) MOTIVATION_EN_61508_2_D_2_2_h
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 i) MOTIVATION_EN_61508_2_D_2_2_i
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 j) MOTIVATION_EN_61508_2_D_2_2_j
status: PASS

Manual ref: 4.1

Motivation: 61508-2 Annex D.2.2 k) MOTIVATION_EN_61508_2_D_2_2_k
status: PASS

Manual ref: 4.1

Motivation: 61508-3 Annex D.1.1 MOTIVATION_EN_61508_3_D_1_1
status: PASS

Manual ref: all

Motivation: 61508-3 Annex D.1.2 MOTIVATION_EN_61508_3_D_1_2
status: PASS

Manual ref: (N/A)

Motivation: 61508-3 Annex D.1.3 MOTIVATION_EN_61508_3_D_1_3
status: PASS

Manual ref: all

Motivation: 61508-3 Annex D.2.1 MOTIVATION_EN_61508_3_D_2_1
status: PASS

Manual ref: all

Motivation: 61508-3 Annex D.2.2 MOTIVATION_EN_61508_3_D_2_2
status: PASS

Manual ref: all

Motivation: 61508-3 Annex D.2.3 a) MOTIVATION_EN_61508_3_D_2_3_a
status: PASS

Manual ref: 13, 14

Motivation: 61508-3 Annex D.2.3 b) MOTIVATION_EN_61508_3_D_2_3_b
status: PASS

Manual ref: 13, 14

Motivation: 61508-3 Annex D.2.3 c) MOTIVATION_EN_61508_3_D_2_3_c
status: PASS

Manual ref: 13, 14

Motivation: 61508-3 Annex D.2.4 a) MOTIVATION_EN_61508_3_D_2_4_a
status: PASS

Manual ref: 1.4

Motivation: 61508-3 Annex D.2.4 b) MOTIVATION_EN_61508_3_D_2_4_b
status: PASS

Manual ref: 4.1, 9, 10

Motivation: 61508-3 Annex D.2.4 c) MOTIVATION_EN_61508_3_D_2_4_c
status: PASS

Manual ref: 13, 14

Motivation: 61508-3 Annex D.2.4 d) MOTIVATION_EN_61508_3_D_2_4_d
status: PASS

Manual ref: (N/A Change log for firmware and compiler shall be kept when more than one version of the software is released.)

Motivation: 61508-3 Annex D.2.4 e) MOTIVATION_EN_61508_3_D_2_4_e
status: PASS

Manual ref: all

Motivation: 61508-3 Annex D.2.4 f) MOTIVATION_EN_61508_3_D_2_4_f
status: PASS

Manual ref: (N/A No software backwards compatibility is required for any software element. All elements are released together.)

Motivation: 61508-3 Annex D.2.4 g) MOTIVATION_EN_61508_3_D_2_4_g
status: PASS

Manual ref: (N/A No compatibility with other systems.)

Motivation: 61508-3 Annex D.2.4 h) MOTIVATION_EN_61508_3_D_2_4_h
status: PASS

Manual ref: 14

Motivation: 61508-3 Annex D.2.4 i) MOTIVATION_EN_61508_3_D_2_4_i
status: PASS

Manual ref: 1.3

Motivation: 61508-3 Annex D.2.4 j) MOTIVATION_EN_61508_3_D_2_4_j
status: PASS

Manual ref: 14

Motivation: 61508-3 Annex D.2.4 k) MOTIVATION_EN_61508_3_D_2_4_k
status: PASS

Manual ref: 3

Motivation: 61508-3 Annex D.2.4 l) MOTIVATION_EN_61508_3_D_2_4_l
status: PASS

Manual ref: 2, 3, 11.9

Motivation: 61508-3 Annex D.2.4 m) MOTIVATION_EN_61508_3_D_2_4_m
status: PASS

Manual ref: 13.9

Motivation: 61508-3 Annex D.2.4 n) MOTIVATION_EN_61508_3_D_2_4_n
status: PASS

Manual ref: 14

Motivation: 61508-3 Annex D.3.1 MOTIVATION_EN_61508_3_D_3_1
status: PASS

Manual ref: (N/A Certificates supporting claims shall be available to the integrator.)

Motivation: 61508-3 Annex D.3.2 MOTIVATION_EN_61508_3_D_3_2
status: PASS

Manual ref: (N/A)

Motivation: 61508-3 Annex D.3.3 MOTIVATION_EN_61508_3_D_3_3
status: PASS

Manual ref: (N/A)

Motivations other requirements

Motivation: xx MOTIVATION_xx
status: PASS