Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
European Railway Agency<br />
Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />
supporting the <strong>CSM</strong> Regulation<br />
<br />
(b) a function (considered as a black-box) transfers input parameters (e.g. material, energy,<br />
in<strong>for</strong>mation) into aim related output parameters (e.g. material, energy, in<strong>for</strong>mation);<br />
(c) the analysis <strong>of</strong> the function is independent <strong>of</strong> its technical realisation.<br />
A.3.5.4.<br />
The RAC-TS is applicable to the following types <strong>of</strong> functions:<br />
(a) examples <strong>for</strong> the ETCS on-board sub-system :<br />
(1) "provide the Driver with in<strong>for</strong>mation to allow him to drive the train safely and en<strong>for</strong>ce<br />
a brake application in case <strong>of</strong> over-speed". Based on in<strong>for</strong>mation received from the<br />
trackside (permitted speed) and on the train speed computation by the on-board<br />
ETCS, the Driver and the on-board ETCS are able to supervise that train does not<br />
exceed the permitted speed limit. The RAC-TS applies to the evaluation <strong>of</strong> the train<br />
speed by the on-board since:<br />
(i) there is no additional barrier (direct) as the in<strong>for</strong>mation provided to the Driver is<br />
also under evaluated;<br />
(ii) the train over speed could lead to derailment which is an accident with potential<br />
<strong>for</strong> catastrophic consequences;<br />
(2) "provide the Driver with in<strong>for</strong>mation to allow him to drive the train safely and en<strong>for</strong>ce<br />
a brake application in case <strong>of</strong> violation <strong>of</strong> the permitted movement authority";<br />
(b) example <strong>for</strong> a track circuit: "detect the occupation <strong>of</strong> the track section". The RAC-TS will<br />
be applicable as such to this function only if there is no "sequence monitoring" function<br />
implemented in the Interlocking;<br />
(c) example <strong>for</strong> a point: "control the point position";<br />
A.3.5.5. Some standards also define functions to which the RAC-TS could be applicable. For<br />
example:<br />
(a) the prEN 0015380-4 standard {Ref. 13} (ModTrain Work) defines in its normative part<br />
three hierarchical function levels (extended in in<strong>for</strong>mative annexes up to five levels). In<br />
total prEN 0015380-4 defines several hundred functions related to trains;<br />
(b) in general it is recommended to select the functions from the first three levels <strong>of</strong> prEN<br />
0015380-4 (but not below), taking also into account the product breakdown structure;<br />
(c) <strong>for</strong> functions, which are not in the scope <strong>of</strong> prEN 0015380-4, the appropriate functional<br />
level needs to be decided by comparison using an expert judgment.<br />
These examples <strong>of</strong> functions from prEN 0015380-4 need still to be worked on by the Agency<br />
in the scope <strong>of</strong> the work on broadly acceptable risks and risk acceptance criteria.<br />
A.3.5.6. The RAC-TS is applicable also <strong>for</strong> example to the following function <strong>of</strong> prEN 0015380-4:<br />
"control tilting" (code = CLB). The function could be used at the system level in the following<br />
two ways:<br />
(a) first case: the train is to tilt in curves <strong>for</strong> passenger com<strong>for</strong>t and must monitor the train<br />
gauge compliance with the trackside infrastructure;<br />
(b) second case: the train is to tilt in curves only <strong>for</strong> passenger com<strong>for</strong>t but needs not to<br />
monitor the train gauge compliance with the trackside infrastructure;<br />
In the first case the RAC-TS will be applied but not in the second case as the failure <strong>of</strong> the<br />
tilting function does not have catastrophic consequence.<br />
A.3.5.7.<br />
The example (b) in point A.3.5.4. and the examples in point A.3.5.6. in Appendix A show<br />
clearly that it will not be feasible to build a predefined list <strong>of</strong> functions on which the RAC-TS<br />
applies in all cases. This will always depend on how the system will use these sub-system<br />
functions.<br />
<br />
Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 65 <strong>of</strong> 105<br />
File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />
European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu