04.07.2015 Views

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

European Railway Agency<br />

Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />

supporting the <strong>CSM</strong> Regulation<br />

<br />

(b) a function (considered as a black-box) transfers input parameters (e.g. material, energy,<br />

in<strong>for</strong>mation) into aim related output parameters (e.g. material, energy, in<strong>for</strong>mation);<br />

(c) the analysis <strong>of</strong> the function is independent <strong>of</strong> its technical realisation.<br />

A.3.5.4.<br />

The RAC-TS is applicable to the following types <strong>of</strong> functions:<br />

(a) examples <strong>for</strong> the ETCS on-board sub-system :<br />

(1) "provide the Driver with in<strong>for</strong>mation to allow him to drive the train safely and en<strong>for</strong>ce<br />

a brake application in case <strong>of</strong> over-speed". Based on in<strong>for</strong>mation received from the<br />

trackside (permitted speed) and on the train speed computation by the on-board<br />

ETCS, the Driver and the on-board ETCS are able to supervise that train does not<br />

exceed the permitted speed limit. The RAC-TS applies to the evaluation <strong>of</strong> the train<br />

speed by the on-board since:<br />

(i) there is no additional barrier (direct) as the in<strong>for</strong>mation provided to the Driver is<br />

also under evaluated;<br />

(ii) the train over speed could lead to derailment which is an accident with potential<br />

<strong>for</strong> catastrophic consequences;<br />

(2) "provide the Driver with in<strong>for</strong>mation to allow him to drive the train safely and en<strong>for</strong>ce<br />

a brake application in case <strong>of</strong> violation <strong>of</strong> the permitted movement authority";<br />

(b) example <strong>for</strong> a track circuit: "detect the occupation <strong>of</strong> the track section". The RAC-TS will<br />

be applicable as such to this function only if there is no "sequence monitoring" function<br />

implemented in the Interlocking;<br />

(c) example <strong>for</strong> a point: "control the point position";<br />

A.3.5.5. Some standards also define functions to which the RAC-TS could be applicable. For<br />

example:<br />

(a) the prEN 0015380-4 standard {Ref. 13} (ModTrain Work) defines in its normative part<br />

three hierarchical function levels (extended in in<strong>for</strong>mative annexes up to five levels). In<br />

total prEN 0015380-4 defines several hundred functions related to trains;<br />

(b) in general it is recommended to select the functions from the first three levels <strong>of</strong> prEN<br />

0015380-4 (but not below), taking also into account the product breakdown structure;<br />

(c) <strong>for</strong> functions, which are not in the scope <strong>of</strong> prEN 0015380-4, the appropriate functional<br />

level needs to be decided by comparison using an expert judgment.<br />

These examples <strong>of</strong> functions from prEN 0015380-4 need still to be worked on by the Agency<br />

in the scope <strong>of</strong> the work on broadly acceptable risks and risk acceptance criteria.<br />

A.3.5.6. The RAC-TS is applicable also <strong>for</strong> example to the following function <strong>of</strong> prEN 0015380-4:<br />

"control tilting" (code = CLB). The function could be used at the system level in the following<br />

two ways:<br />

(a) first case: the train is to tilt in curves <strong>for</strong> passenger com<strong>for</strong>t and must monitor the train<br />

gauge compliance with the trackside infrastructure;<br />

(b) second case: the train is to tilt in curves only <strong>for</strong> passenger com<strong>for</strong>t but needs not to<br />

monitor the train gauge compliance with the trackside infrastructure;<br />

In the first case the RAC-TS will be applied but not in the second case as the failure <strong>of</strong> the<br />

tilting function does not have catastrophic consequence.<br />

A.3.5.7.<br />

The example (b) in point A.3.5.4. and the examples in point A.3.5.6. in Appendix A show<br />

clearly that it will not be feasible to build a predefined list <strong>of</strong> functions on which the RAC-TS<br />

applies in all cases. This will always depend on how the system will use these sub-system<br />

functions.<br />

<br />

Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 65 <strong>of</strong> 105<br />

File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />

European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!