Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
European Railway Agency<br />
Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />
supporting the <strong>CSM</strong> Regulation<br />
<br />
[G 5] Reciprocally, all internal hazard records are maintained throughout the whole (sub-)system<br />
life-cycle. That enables to track the progress on monitoring risks associated with the<br />
identified hazards during the (sub-)system operation and maintenance, i.e. even after its<br />
commissioning: see BOX 4 in the CENELEC V-Cycle in Figure 5.<br />
4.1.2. The hazard record shall include all hazards, together with all related safety measures<br />
and system assumptions identified during the risk assessment process. In particular, it<br />
shall contain a clear reference to the origin and to the selected risk acceptance<br />
principles and shall clearly identify the actor(s) in charge <strong>of</strong> controlling each hazard.<br />
[G 1] The in<strong>for</strong>mation on hazards and the associated safety measures that is received from other<br />
actors (see section 1.2.2) includes also all the assumptions (15) and restrictions <strong>of</strong> use (15)<br />
(also called safety related application conditions) applicable to the different sub-systems,<br />
generic application and generic product safety cases that are produced by the<br />
manufacturers, where relevant.<br />
[G 2] A possible example <strong>of</strong> structure <strong>for</strong> the hazard record is described in section C.16. <strong>of</strong><br />
Appendix C.<br />
4.2. Exchange <strong>of</strong> in<strong>for</strong>mation<br />
All hazards and related safety requirements which cannot be controlled by one actor<br />
alone shall be communicated to another relevant actor in order to find jointly an<br />
adequate solution. The hazards registered in the hazard record <strong>of</strong> the actor who<br />
transfers them shall only be “controlled” when the evaluation <strong>of</strong> the risks associated<br />
with these hazards is made by the other actor and the solution is agreed by all<br />
concerned.<br />
[G 1] For example, <strong>for</strong> the odometry sub-system <strong>of</strong> the ETCS onboard equipment, the<br />
manufacturer can validate in laboratory the algorithms by simulating the theoretical signals<br />
that could be generated by the associated odometric sensing devices. However, the<br />
complete validation <strong>of</strong> the odometry sub-system requires the help <strong>of</strong> the RU and IM <strong>for</strong><br />
carrying out the validation with the use <strong>of</strong> a real train and the real train wheel to rail contact.<br />
[G 2] Other examples could be transfers by manufacturers to railway undertakings <strong>of</strong> operational<br />
or maintenance safety measures <strong>for</strong> technical equipment. These safety measures will need<br />
to be implemented by the railway undertaking.<br />
[G 3] In order to enable these hazards, the associated safety measures and risks to be<br />
reassessed jointly by the involved organisations, it is helpful that the organisation having<br />
identified them provides all the explanations necessary to understand clearly the problem. It<br />
could be possible that the initial wording <strong>of</strong> the hazards, safety measures and risks needs to<br />
be changed to make them understandable without having to discuss them again jointly. The<br />
joint reassessment <strong>of</strong> the hazards could lead to identify new safety measures.<br />
(15) Refer to point [G 5] in section 1.1.5 and to the footnotes (9) and (10) at page 24 <strong>of</strong> this document <strong>for</strong><br />
further explanation about the terminology "generic product and generic application" safety cases,<br />
"assumptions and restrictions <strong>of</strong> use".<br />
<br />
Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 52 <strong>of</strong> 105<br />
File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />
European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu