04.07.2015 Views

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

Guidance for Use of CSM Recommendation - ERA - Europa

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

European Railway Agency<br />

Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />

supporting the <strong>CSM</strong> Regulation<br />

<br />

(i) the evaluation <strong>of</strong> this quantitative target takes into account <strong>for</strong> redundant<br />

systems the common components (e.g. single or common inputs to all<br />

channels, common power supply, comparators, voters, etc.);<br />

(ii) the dormant or latent failure detection times are covered;<br />

(iii) a Common Cause/Mode Failure (CCF/CMF) analysis is done;<br />

(iv) an Independent Assessment is carried out;<br />

(2) <strong>for</strong> the process requirements: apply a SIL 4 process <strong>for</strong> the management <strong>of</strong> the<br />

systematic failures/errors <strong>of</strong> the on-board ETCS sub-system. This requires the<br />

application <strong>of</strong>:<br />

(i) a quality management process compliant with SIL 4;<br />

(ii) a safety management process compliant with SIL 4;<br />

(iii) the relevant standards, e.g.:<br />

<strong>for</strong> the s<strong>of</strong>tware development use the EN 50 128 standard;<br />

<strong>for</strong> the hardware development use the EN 50 121-3-2, EN 50 121-4,<br />

EN 50 124-1, EN 50 124-2, EN 50 125-1 EN 50 125-3, EN 50 50081,<br />

EN 50 155, EN 61000-6-2, etc. standards;<br />

(3) an Independent Assessment <strong>of</strong> the process(es).<br />

C.16.<br />

Examples <strong>of</strong> possible structures <strong>for</strong> the hazard record<br />

C.16.1. Introduction<br />

C.16.1.1. The minimum requirements to be registered in the hazard record are identified in<br />

section 4.1.2 <strong>of</strong> the <strong>CSM</strong> Regulation. These are indicated with a shaded background in the<br />

examples hereafter <strong>of</strong> hazard records.<br />

C.16.1.2. There may be different ways to structure a hazard record, as well as any additional<br />

in<strong>for</strong>mation that could characterise the hazards and the associated safety measures. For<br />

example, the hazards and associated safety measures can be fitted with one field per piece<br />

<strong>of</strong> in<strong>for</strong>mation. However, whatever structure is used, it is important that the hazard record<br />

provides clear links between the hazards and the associated safety measures. One possible<br />

solution is that the hazard record contains, <strong>for</strong> each hazard and <strong>for</strong> each safety measure, at<br />

least a field with:<br />

(a) a clear description including references <strong>of</strong> its origin and <strong>of</strong> the risk acceptance principle<br />

selected to control the associated hazard. This field enables to understand the hazard<br />

and the associated safety measures, as well as to know in which safety analyses they<br />

are identified.<br />

As the hazard record is used and maintained during the whole system life-cycle (i.e.<br />

during the system operation and maintenance), a clear traceability, or link, is helpful<br />

between each hazard and:<br />

(1) the associated risk;<br />

(2) the hazard causes when already identified;<br />

(3) the associated safety measures, as well as the assumptions defining the limits <strong>of</strong><br />

the system under assessment;<br />

(4) the associated safety analyses where the hazard is identified;<br />

Furthermore, the wording <strong>of</strong> safety measures (especially the ones to transfer to other<br />

actors such as to a proposer), the wording <strong>of</strong> the associated hazards and risks needs to<br />

be clear and sufficient. "Clear and sufficient" mean that the safety measures and the<br />

<br />

Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 97 <strong>of</strong> 105<br />

File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />

European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!