04.07.2015 Views

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

European Railway Agency<br />

Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />

supporting the <strong>CSM</strong> Regulation<br />

<br />

2.1.5. The proposer shall demonstrate in the risk evaluation that the selected risk acceptance<br />

principle is adequately applied. The proposer shall also check that the selected risk<br />

acceptance principles are used consistently.<br />

[G 1] For example, if <strong>for</strong> the s<strong>of</strong>tware <strong>of</strong> a component the application <strong>of</strong> the SIL 4 development<br />

process <strong>of</strong> the EN 50 128 standard is specified as the safety requirement, the demonstration<br />

will need to prove that the process recommended by the standard is fulfilled. This includes<br />

<strong>for</strong> example the demonstration that:<br />

(a) the requirements <strong>for</strong> independence in the organisation <strong>of</strong> the design, verification and<br />

validation <strong>of</strong> the s<strong>of</strong>tware are fulfilled;<br />

(b) the correct methods <strong>of</strong> the EN 50 128 standard <strong>for</strong> the SIL 4 safety integrity level are<br />

applied;<br />

(c) etc.<br />

[G 2] For example, if a dedicated code <strong>of</strong> practice is to be used <strong>for</strong> manufacturing emergency<br />

brake electro valves, the demonstration will need to prove that all requirements from the<br />

code <strong>of</strong> practice are fulfilled during the manufacturing process.<br />

2.1.6. The application <strong>of</strong> these risk acceptance principles shall identify possible safety<br />

measures which make the risk(s) <strong>of</strong> the system under assessment acceptable. Among<br />

these safety measures, the ones selected to control the risk(s) shall become the safety<br />

requirements to be fulfilled by the system. Compliance with these safety requirements<br />

shall be demonstrated in accordance with section 3.<br />

[G 1] Two types <strong>of</strong> safety measures can be identified:<br />

(a) "preventive safety measures" preventing the occurrence <strong>of</strong> hazards or their causes, and;<br />

(b) "mitigation safety measures" preventing hazards to evolve into accidents or reducing the<br />

consequences <strong>of</strong> accidents after their occurrence (protection measures)<br />

For the benefit <strong>of</strong> operability, prevention <strong>of</strong> causes is generally more efficient<br />

[G 2] The proposer will consider as the most appropriate the safety measures that give the best<br />

compromise between the cost to achieve the risk reduction and the level <strong>of</strong> the residual risk.<br />

The chosen safety measures become the safety requirements <strong>for</strong> the system under<br />

assessment.<br />

[G 3] It is important to check that the safety measures selected to control one hazard are not in<br />

conflict with other hazards. As represented in Figure 6, the following two cases may happen<br />

<strong>for</strong> example (13) :<br />

(a) CASE 1: if the same safety measure (measure A on Figure 6) can control different<br />

hazards without creating conflicts between them, and if economically justified, the<br />

related safety measure could be chosen alone as the associated "safety requirement".<br />

The total number <strong>of</strong> safety requirements to fulfil is smaller than implementing both the<br />

measures B and C;<br />

(13 ) It must be noted that the guide does not list all the situations where safety measures could be in<br />

conflict with other identified hazards. Only a few illustrative examples are provided.<br />

<br />

Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 37 <strong>of</strong> 105<br />

File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />

European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!