Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
European Railway Agency<br />
Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools supporting the <strong>CSM</strong> Regulation<br />
<br />
C.16.3. Example <strong>of</strong> a complete hazard record <strong>for</strong> an onboard control command sub-system<br />
C.16.3.1. This section gives in an example a single hazard record (refer to point [G 3] in section 4.1.1) <strong>for</strong> managing both:<br />
(a) all the internal safety requirements applicable to the sub-system the actor is responsible <strong>for</strong>; and,<br />
(b) all identified hazards and associated safety measures that the actor cannot implement and that must be transferred to other actors.<br />
Table 7 : Example <strong>of</strong> a Manufacturer's hazard record <strong>for</strong> an onboard control command sub-system.<br />
N°<br />
HZD<br />
1 HAZOP<br />
report<br />
R X<br />
2 HAZOP<br />
report<br />
R X<br />
3 HAZOP<br />
report<br />
R X<br />
4 HAZOP<br />
report<br />
R X<br />
Origin Hazard description Additional in<strong>for</strong>mation<br />
Maximum speed <strong>of</strong> train<br />
set too high (Vmax)<br />
Braking curves (i.e.<br />
Movement Authority) in<br />
onboard sub-system<br />
configuration data too<br />
permissive<br />
●<br />
●<br />
Maximum speed <strong>of</strong><br />
train set too high<br />
(Vmax)<br />
Braking curves (i.e.<br />
Movement Authority)<br />
in onboard subsystem<br />
configuration<br />
data too permissive<br />
Entry <strong>of</strong> the train at a<br />
high speed (160 km/h if<br />
line side signal free) on<br />
Wrong specific configuration <strong>of</strong> the onboard subsystem<br />
(maintenance staff).<br />
Wrong Data Entry onboard (driver)<br />
The procedure <strong>for</strong> the specific configuration <strong>of</strong> the<br />
onboard sub-system depends on:<br />
● the safety margins taken <strong>for</strong> the train braking<br />
system;<br />
● the reaction delay <strong>of</strong> the train braking system (this<br />
one is directly dependent on the train length,<br />
especially <strong>for</strong> fret trains)<br />
Failure to update the train wheel diameter in the<br />
specific configuration <strong>of</strong> the onboard sub-system<br />
(maintenance staff).<br />
Failure in manufacturer procedure <strong>for</strong> the preparation<br />
and the upload <strong>of</strong> the configuration data into the<br />
onboard sub-system<br />
Could be controlled only by the driver's vigilance.<br />
The entry into a trackside ATP fitted area relies on an<br />
acknowledgment procedure by the driver be<strong>for</strong>e the<br />
Actor in<br />
charge<br />
Railway<br />
Undertaking<br />
Railway<br />
Undertaking<br />
Railway<br />
Undertaking<br />
Manufacturer<br />
Infrastructure<br />
Manager<br />
Safety Measure<br />
●<br />
●<br />
●<br />
●<br />
●<br />
●<br />
Define a procedure <strong>for</strong> the<br />
approval <strong>of</strong> the onboard subsystem<br />
configuration data;<br />
Define an operational procedure<br />
<strong>for</strong> the Data Entry Process by<br />
the Driver;<br />
Specify correctly the system<br />
requirements in the System<br />
Definition;<br />
Take sufficient safety margins <strong>for</strong><br />
the braking system <strong>of</strong> the<br />
specific train;<br />
Define a procedure <strong>for</strong> the<br />
measure <strong>of</strong> the train wheel<br />
diameter by the maintenance<br />
staff;<br />
Define a procedure <strong>for</strong> the<br />
regular update <strong>of</strong> the train wheel<br />
diameter in the onboard subsystem;<br />
Define a procedure <strong>for</strong> updating the<br />
train wheel diameter in the onboard<br />
configuration data<br />
Infrastructure Manager to ensure<br />
that trains that are not fitted with an<br />
active onboard control command<br />
<strong>Use</strong>d Risk<br />
Acceptance<br />
Principle<br />
Explicit Risk<br />
Estimation<br />
Explicit Risk<br />
Estimation<br />
Explicit Risk<br />
Estimation<br />
Explicit Risk<br />
Estimation<br />
Explicit Risk<br />
Estimation<br />
Exported<br />
Yes<br />
Yes<br />
Yes<br />
Yes<br />
Yes<br />
Status<br />
Controlled<br />
(exported to RU)<br />
Refer also to<br />
section C.16.4.2. in<br />
Appendix C<br />
Controlled<br />
(exported to RU)<br />
Refer also to<br />
section C.16.4.2. in<br />
Appendix C<br />
Controlled<br />
(exported to RU)<br />
Refer also to<br />
section C.16.4.2. in<br />
Appendix C<br />
Controlled<br />
by Procedure P X<br />
Controlled<br />
(exported to IM)<br />
Refer also to<br />
<br />
Reference : <strong>ERA</strong>/GUI/02-2008/SAF Version : 1.1 Page 100 <strong>of</strong> 105<br />
File Name : Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />
European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu