Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
European Railway Agency<br />
Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools supporting the <strong>CSM</strong> Regulation<br />
<br />
Table 7 : Example <strong>of</strong> a Manufacturer's hazard record <strong>for</strong> an onboard control command sub-system.<br />
N°<br />
HZD<br />
5 HAZOP<br />
report<br />
R X<br />
6 HAZOP<br />
report<br />
R X<br />
etc.<br />
Origin Hazard description Additional in<strong>for</strong>mation<br />
the track without the<br />
onboard sub-system<br />
active and without line<br />
side signalling<br />
Maximum speed <strong>of</strong> train<br />
set displayed to the<br />
driver too high (Vmax)<br />
Train is leaving without<br />
driver machine interface<br />
transition location. In case <strong>of</strong> absence <strong>of</strong><br />
acknowledgement, there is an automatic application <strong>of</strong><br />
the train brakes by the onboard control command subsystem.<br />
The in<strong>for</strong>mation displayed on the driver's interface is<br />
monitored by the SIL 4 onboard control command subsystem<br />
that applies the emergency brakes in case <strong>of</strong><br />
discrepancy between display and expected value.<br />
In case <strong>of</strong> non compliance <strong>of</strong> with the movement<br />
authority the onboard sub-system control command<br />
sub-system applies the emergency brakes<br />
Actor in<br />
charge<br />
Railway<br />
Undertaking<br />
Manufacturer<br />
Safety Measure<br />
sub-system do not enter the relevant<br />
track.<br />
Define a procedure <strong>for</strong> the traffic<br />
management.<br />
Ensure the driver training <strong>for</strong><br />
entering a trackside ATP fitted area<br />
Develop a SIL 4 onboard control<br />
command sub-system<br />
Loss <strong>of</strong> redundant architecture <strong>of</strong> onboard sub-system Manufacturer Develop a SIL 4 onboard control<br />
command sub-system<br />
<strong>Use</strong>d Risk<br />
Acceptance<br />
Principle<br />
Explicit Risk<br />
Estimation<br />
Explicit Risk<br />
Estimation<br />
Explicit Risk<br />
Estimation<br />
Exported<br />
Yes<br />
Yes<br />
Yes<br />
Status<br />
section C.16.4.2. in<br />
Appendix C<br />
Ccontrolled<br />
(exported to RU)<br />
Refer also to<br />
section C.16.4.2. in<br />
Appendix C<br />
Safety Case<br />
demonstrating a SIL 4<br />
sub-system assessed<br />
by an Independent<br />
Safety Assessor<br />
Safety Case<br />
demonstrating a SIL 4<br />
sub-system assessed<br />
by an Independent<br />
Safety Assessor<br />
C.16.4. Example <strong>of</strong> a hazard record <strong>for</strong> transferring in<strong>for</strong>mation to other actors<br />
C.16.4.1 This section gives in an example a hazard record <strong>for</strong> transferring to other actors the identified hazards and associated safety measures that a<br />
considered actor cannot implement. Refer to point [G 1] in section 4.1.1.<br />
This example is the same one as the example in section C.16.3. in Appendix C. The only difference is that all the internal hazards and safety measures<br />
that could be controlled by the considered actor are removed.<br />
C.16.4.2. The last column in Table 8 is used to fulfil the requirement in section 4.2 <strong>of</strong> the <strong>CSM</strong> Regulation. There are different solutions to achieve it. One way<br />
may be to refer to the evidence used by the actor receiving the exported safety in<strong>for</strong>mation. Another way could be to have a meeting between the two<br />
<br />
Reference : <strong>ERA</strong>/GUI/02-2008/SAF Version : 1.1 Page 101 <strong>of</strong> 105<br />
File Name : Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />
European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu