04.07.2015 Views

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

European Railway Agency<br />

Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />

supporting the <strong>CSM</strong> Regulation<br />

<br />

(d) use <strong>of</strong> a reference system [section 2.4]:<br />

The system be<strong>for</strong>e the change (loop) is judged to have an acceptable level <strong>of</strong> safety. It<br />

is thus used as "reference system" to derive the safety requirements <strong>for</strong> the radio infill<br />

sub-system.<br />

(e) explicit risk estimation and evaluation [section 2.5]:<br />

(1) the differences between the "loop" and "radio infill+GSM" sub-systems are analysed<br />

by explicit risk estimation and evaluation. The following new hazards are identified<br />

<strong>for</strong> the "radio infill + GSM" sub-system:<br />

(i) transmission by hackers <strong>of</strong> unsafe in<strong>for</strong>mation in the air gap since the "radio<br />

infill+GSM" is an open transmission sub-system;<br />

(ii) delayed transmission or transmission <strong>of</strong> memorised data packets in the air gap;<br />

(2) explicit risk estimation and use <strong>of</strong> RAC-TS <strong>for</strong> the Radio Infill Controller part;<br />

(f) use <strong>of</strong> codes <strong>of</strong> practice [section 2.3]:<br />

(1) the EN 50159-2 standard ("Railway Applications: Part 2: Safety related<br />

communication in open transmission systems") provides the safety requirements <strong>for</strong><br />

controlling the new hazards to an acceptable level, e.g.:<br />

(i) data encrypting and protection;<br />

(ii) message sequencing and time stamping;<br />

(2) use <strong>for</strong> example <strong>of</strong> EN 50 128 standard <strong>for</strong> the s<strong>of</strong>tware development <strong>of</strong> the Radio<br />

Infill Controller;<br />

(g) demonstration <strong>of</strong> the system compliance with safety requirements [section 3]:<br />

(1) follow up <strong>of</strong> the implementation <strong>of</strong> the safety requirements through the development<br />

process <strong>of</strong> the "radio infill + GSM" sub-system;<br />

(2) verification that the system, as designed and installed, is compliant with the safety<br />

requirements;<br />

(h) hazard management [section 4.1]:<br />

The identified hazards, the safety measures and the resulting safety requirements<br />

issued from the risk assessment and the application <strong>of</strong> the three risk acceptance<br />

principles are registered and managed in a hazard record.<br />

(i) independent assessment [Article 6]:<br />

An independent assessment by a third party is also carried out in order:<br />

(1) to check that the risk management and risk assessment are correctly done;<br />

(2) to check that the technical change is suitable and will maintain the same level <strong>of</strong><br />

safety as be<strong>for</strong>e the change.<br />

C.7.6.<br />

The example shows that the three risk acceptance principles required by the common safety<br />

method are used in a complementary way to define the safety requirements <strong>for</strong> the system<br />

under assessment. The risk assessment in the example fulfils all the requirements from the<br />

<strong>CSM</strong> summarised in Figure 1, including the hazard record management and independent<br />

safety assessment by a third party.<br />

<br />

Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 81 <strong>of</strong> 105<br />

File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />

European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!