Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Guidance for Use of CSM Recommendation - ERA - Europa
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
European Railway Agency<br />
Collection <strong>of</strong> examples <strong>of</strong> risk assessments and <strong>of</strong> some possible tools<br />
supporting the <strong>CSM</strong> Regulation<br />
<br />
(i) the evaluation <strong>of</strong> this quantitative target takes into account <strong>for</strong> redundant<br />
systems the common components (e.g. single or common inputs to all<br />
channels, common power supply, comparators, voters, etc.);<br />
(ii) the dormant or latent failure detection times are covered;<br />
(iii) a Common Cause/Mode Failure (CCF/CMF) analysis is done;<br />
(iv) an Independent Assessment is carried out;<br />
(2) <strong>for</strong> the process requirements: apply a SIL 4 process <strong>for</strong> the management <strong>of</strong> the<br />
systematic failures/errors <strong>of</strong> the on-board ETCS sub-system. This requires the<br />
application <strong>of</strong>:<br />
(i) a quality management process compliant with SIL 4;<br />
(ii) a safety management process compliant with SIL 4;<br />
(iii) the relevant standards, e.g.:<br />
<strong>for</strong> the s<strong>of</strong>tware development use the EN 50 128 standard;<br />
<strong>for</strong> the hardware development use the EN 50 121-3-2, EN 50 121-4,<br />
EN 50 124-1, EN 50 124-2, EN 50 125-1 EN 50 125-3, EN 50 50081,<br />
EN 50 155, EN 61000-6-2, etc. standards;<br />
(3) an Independent Assessment <strong>of</strong> the process(es).<br />
C.16.<br />
Examples <strong>of</strong> possible structures <strong>for</strong> the hazard record<br />
C.16.1. Introduction<br />
C.16.1.1. The minimum requirements to be registered in the hazard record are identified in<br />
section 4.1.2 <strong>of</strong> the <strong>CSM</strong> Regulation. These are indicated with a shaded background in the<br />
examples hereafter <strong>of</strong> hazard records.<br />
C.16.1.2. There may be different ways to structure a hazard record, as well as any additional<br />
in<strong>for</strong>mation that could characterise the hazards and the associated safety measures. For<br />
example, the hazards and associated safety measures can be fitted with one field per piece<br />
<strong>of</strong> in<strong>for</strong>mation. However, whatever structure is used, it is important that the hazard record<br />
provides clear links between the hazards and the associated safety measures. One possible<br />
solution is that the hazard record contains, <strong>for</strong> each hazard and <strong>for</strong> each safety measure, at<br />
least a field with:<br />
(a) a clear description including references <strong>of</strong> its origin and <strong>of</strong> the risk acceptance principle<br />
selected to control the associated hazard. This field enables to understand the hazard<br />
and the associated safety measures, as well as to know in which safety analyses they<br />
are identified.<br />
As the hazard record is used and maintained during the whole system life-cycle (i.e.<br />
during the system operation and maintenance), a clear traceability, or link, is helpful<br />
between each hazard and:<br />
(1) the associated risk;<br />
(2) the hazard causes when already identified;<br />
(3) the associated safety measures, as well as the assumptions defining the limits <strong>of</strong><br />
the system under assessment;<br />
(4) the associated safety analyses where the hazard is identified;<br />
Furthermore, the wording <strong>of</strong> safety measures (especially the ones to transfer to other<br />
actors such as to a proposer), the wording <strong>of</strong> the associated hazards and risks needs to<br />
be clear and sufficient. "Clear and sufficient" mean that the safety measures and the<br />
<br />
Reference: <strong>ERA</strong>/GUI/02-2008/SAF Version: 1.1 Page 97 <strong>of</strong> 105<br />
File Name: Collection_<strong>of</strong>_RA_Ex_and_some_tools_<strong>for</strong>_<strong>CSM</strong>_V1.1.doc<br />
European Railway Agency ● Boulevard Harpignies, 160 ● BP 20392 ● F-59307 Valenciennes Cedex ● France ● Tel. +33 (0)3 27 09 65 00 ● Fax +33 (0)3 27 33 40 65 ● http://www.era.europa.eu