NEW CENELEC STANDARDS CSMRA 2017 AGENDA New EN





























- Slides: 29
NEW CENELEC STANDARDS & CSM-RA 2017
AGENDA • New EN 501 xx Standards • What is new/changed/improved • The use of CENELEC in CSM-RA process And an e xam ple NEW CENELEC STANDARDS & CSM-RA 2017
CENELEC & CSM-RA TIMELINE EN 61508 ENV 50126 1995 EN 50126 EN 50128 1999 2000 2001 EN 61508 EN 50129 EN 50128 2003 2010 2011 EN 50126 EN 50129 2017 2018 TR 50126 -3 TR 50126 -2 2006 2007 TSI 2010 CSM-RA 352/2009 2012 2015 CSM-RA 402/2013 CSM-RA 1136/2015 NEW CENELEC STANDARDS & CSM-RA 2017
OVERVIEW OF CURRENT RAILWAY SAFETY STANDARDS System Level Guidance The Specification and Demonstration of Reliablity, Availablity, Maintainability and Safety (RAMS) EN 50129 EN 50128 Communications, signalling and processing systems Software for railway control and protection systems 2006 TR 50126 -3 Guide to the application of EN 50126 for rolling stock 2003 2007 TR 50506 -1 Communication, signalling and processing systems – Safety related electronic systems for signalling Sub. System (Product) TR 50126 -2 Guide to the application of EN 50126 for safety 1999 EN 50126 2007 2011 2001 Guide to the application of EN 50129 – Part 1: Cross Acceptance Guidance 2008 TR 50506 -2 Guide to the application of EN 50129 – Part 2: Safety Assurance NEW CENELEC STANDARDS & CSM-RA 2017
OVERVIEW OF NEW RAILWAY SAFETY STANDARDS 2017 EN 50126 System Level The Specification and Demonstration of Reliablity, Availablity, Maintainability and Safety (RAMS) EN 50129 2017 Guidance 2018 EN 50128 Communications, signalling and processing systems Software for railway control and protection systems 2011 Systems Approach to Safety 2007 TR 50506 -1 Communication, signalling and processing systems – Safety related electronic systems for signalling Sub. System (Product) EN 50126 -2 Guide to the application of EN 50129 – Part 1: Cross Acceptance Guidance 2008 TR 50506 -2 Guide to the application of EN 50129 – Part 2: Safety Assurance NEW CENELEC STANDARDS & CSM-RA 2017
SAFETY STANDARDS RELATIONSHIPS EN 50126 Entire Railway system EN 61508 ”FUNCTIONAL SAFETY OF ELECTRICAL/ELECTRONIC/PROGRAMMABLE ELECTRONIC SAFETY-RELATED SYSTEMS” General standard (generic) Railway sub-system / Product Specific sector / application EN 50129 System HW+SW EN 50128 IEC 61551 Process Sector Safety System Standard for Safety Instrumented Systems Designers, Integrators and Users IEC 62061, Safety of machinery Functional safety of electrical/ electronic/ programmable control systems Where no other sector/ application exists SW Railway signalling Railway Applications Other sectors (e. g. machinery / process control) Other NEW CENELEC STANDARDS & CSM-RA 2017 Adapted after EN 50129 / IEC WG group
RAILWAY SAFETY STANDARDS - SUBSYSTEM 2017 EN 50126 -1 & 2 SC 9 X / S-509 SC 9 XA Railway Applications The Specification and Demonstration of Reliability, Availability, Maintainability and Safety (RAMS) 2018 SC 9 XB EN 50129 EN 50155 Communication, signalling and processing systems – Safety related electronic systems for signalling Electronic equipment used on rolling stock 2017 EN 50562 2018 Process, measures and demonstration of safety for electric traction systems 2017 2011 EN 50128 EN 50657 Communications, signalling and processing systems Software for railway control and protection systems Rolling stock applications Software on board ofrolling stock, excluding railway control and protection applications Signalling SC 9 XC Rolling Stock Fixed Installation NEW CENELEC STANDARDS & CSM-RA 2017
EN 50126 OLD & NEW IN COMPARISON Similarities New/changed Improved/detailed • System approach for RAMS • More mature and consistent • Clear hazard identification and classification • Risk based approach • RAMS lifecycle • Safety demonstration principles • CSM-RA approach • Multilevel system approach (hierarchies) • Aligned risk evaluation • Safety demonstration • Safety requirements Spec. • Guidance integrated part • Clear linkage to TSI • Classification of safety requirements • Method to derive THR from statistics • Safety Case structure • Modularity • Handling of product/Generic / specific Application • Safety Apportionment methods • Key system safety roles & responsibilities NEW CENELEC STANDARDS & CSM-RA 2017
EN 50126 -1 Scope Normative reference Terms & Definition Abbreviation New 5: Railway RAMS 6: Management of Railway RAMS – general requirements Annex D Guidance on system definition 8: Safety Case Informative New 7: RAMS Life cycle Normative 1: 2: 3: 4: General New Annex B Examples of parameters for railway Annex C Risk Management Calibration and risk acceptance categories Annex A RAMS Plan Bibliography NEW CENELEC STANDARDS & CSM-RA 2017
EN 50126 -2 Scope Normative reference Terms & Definition Abbreviation 8: Risk Assessment 5: Safety Process 9: Specification of system safety requirements 7: Organisation and independence of roles 10: Apportionment of functional safety integrity requirements Normative 1: 2: 3: 4: General 11: Design & Implementation 6: Safety Demonstration Annex A ALARP, GAME, MEM Annex B Using failure and accident statistics to derive a THR Annex C Guidance on SIL Allocation Annex D Safety Target Apportionment methods NEW CENELEC STANDARDS & CSM-RA 2017 Informative Bibliography
PRODUCTS IN CENELEC PROCESS EN 50126 50129/50128 • Provide the overall process for development of products • Provide the process for development of products • Lifecycle • Tailored system/hardware/software development process • Hazard identification and management • Safety requirements identification and apportionment • Safety target (THR, TFFR, SIL) • Implementation evidence • Documentation • Detailed analysis of failure and hazard control • SIL demonstration • Product specific implementation evidence • Product specific documentation NEW CENELEC STANDARDS & CSM-RA 2017
EN 50129 General 1: Scope 2: Normative reference 3: Definition 4: Overview 6: Requirements for external elements 7: Safety Case 8: Acceptance and subsequent phases Annex C HW component failure modes Annex E SIL-based techniques Annex B Management of faults Annex F Programmable Components NEW CENELEC STANDARDS & CSM-RA 2017 Informative Bibliography Annex A Safety Integrity Level (SIL) Normative 5: Requirements for Developing electronic systems
CSM-RA VERSUS EN 50126 CSM-RA EN 50126 • Focus on a change • Can be applied for changes and products • Significance • Always applicable • Emphasis on hazard identification & control • Life cycle approach in hazard identification and control • Hazard normally controlled by well known measures • Generic control of hazards • Independent safety assessor as NSA proxy • Verification and validation process • Independent safety assessor to ensure process • Functional Safety & Safety Integrity • RAM (dependability) NEW CENELEC STANDARDS & CSM-RA 2017
CSM-RA IN SHORT Significance evaluation CSM RA relevant ? Concept Design Implementation EN 50126 System Definition The Change in short System definition EN 50126 Hazard identification What is the risk? Risk evaluation How to control risk EN 50126 Risk Acceptance Control risk Hazard Record EN 50126 EN 50129/EN 50128 EN 50126 Safety documentation Risk was in control EN 50129/EN 50128 Safety Documentation NEW CENELEC STANDARDS & CSM-RA 2017
CSM-RA SUPPORTED BY EN 50126 CSM-RA The Good Process • The Legal framework • System definition • Risk Management process • Require systematic process • Require documentation for hazard control EN 50126 • Hierarchical system definition model • Detailed risk management process & evaluation principles • The systematic process • Standard lifecycle to be tailored to project • Detailed risk management process • Engineering process requirements • Provide the principles for safety documentation • Safety Case structure • Verification & Validation process NEW CENELEC STANDARDS & CSM-RA 2017
EN 50126 LIFECYCLE COMPARED TO CSM-RA PROCESS 1 Concept 10 System definition and Operational Context 3 11 System Acceptance 12 Operation and Maintenance De-commissioning and Disposal Risk Analysis and Evaluation 4 Specification of System Requirements 5 Significant ? System Validation Design and Implementation 8 Integration 7 Manufacture CSM-RA Risk Assessment System Definition Risk Analysis Hazard Identification and classification Code of Practice Similar Reference System Explicit Risk Estimation Risk Evaluation vs risk acceptance criteria Safety Requirements Demonstration of Compliance with Safety Requirement NEW CENELEC STANDARDS & CSM-RA 2017 Hazard Management Architecture and Apportionment of System Requirements 6 Prelim. System Definition 9 Independent Safety Assessment 2
System Definition Risk analysis Risk evaluation Legal framework Contractual Arrangement Railway Duty Holder’s responsibility CSM-RA Proposer System requirements Hazard Safety Measures & Safety requirements • • • Hazard Code Of practice Reference system Functional/technical/context Additional Hazards Application Conditions CENELEC System Actor Supplier’s Responsibility Hazard analysis Demonstration of compliance Sub System Products NEW CENELEC STANDARDS & CSM-RA 2017
SYSTEM DEFINITION Contextual Requirements The operational environment Functional Requirements What the system shall do Technical Requirements Ensure the system function NEW CENELEC STANDARDS & CSM-RA 2017
HAZARD IDENTIFICATION & ACCEPTANCE Code Of Practice Interface Hazards Lack of Hazards Reference system HZ Explicit Risk Evaluation Hazard CENELEC Code of Practice (3) Code of Practice (1) f Re HZ HZ HZ Hazard ce en er Hazard Code of Practice (2) HZ Hazard HZ HZ Interface Hazards Hazard HZ Reference Hazard Interface Hazards System definition NEW CENELEC STANDARDS & CSM-RA 2017
EXAMPLE Hazards CSM RA Hazard related to Specific Appl. Trains too close - > separate EN 50126 Block sections Indicate free/occupied Specific Appl. Axle counter indicate free while occupied Hazard related to Generic Appl. Specific Generic Application SC EN 50129 EN 50128 Failures/Hazards in Product Generic Product SC NEW CENELEC STANDARDS & CSM-RA 2017
Proposer’s Hazard Record CSM RA System Defintion CLOSE CENELEC Safety Demonstration Safety Dcoumentation CSM RA CENELEC Log Register Allocation of hazards Specific Appl. Safety Case(s) EN 50126 CENELEC EN 50126 System Defintion Implementation Register Supplier Hazard Log Generic Appl. Safety Case(s) EN 50129 Specifc log EN 50129 Generic Product Safety Case(s) EN 50128 NEW CENELEC STANDARDS & CSM-RA 2017
APPLICATION OF CENELEC STANDARDS ON SYSTEM/SUBSYSTEM LEVEL Hazards identified in CSM-RA Hazard System EN 50126 systematic process System. Integration SUb Hardware Software EN 50129 System Integration EN 50128 Software development process SIL requirement EN 50129 Hardware development process NEW CENELEC STANDARDS & CSM-RA 2017
HAZARD RATES & SIL - PRINCIPLE Safety functionality Hazard not controlled by system Hazard rate Hazard not fully mitigated Hazards System Failure Functional Hazard rate Safety Integrity (SIL) Functional Safety System NEW CENELEC STANDARDS & CSM-RA 2017
SAFETY INTEGRITY SIL Qualitative Measures Defined in sector specific standard EN 50129/ EN 50128 Quality Management Conditions Safety Management Conditions SIL Quantitative Target (TFFR) Technical Safety Measures 4 Compliance to the Safety Integrity measures Tolerable Functional Failure Rate SIL 3 2 1 Demonstration of Quantitative Targets 10 -9 < TFFR < 10 -8 < TFFR < 10 -7 < TFFR < 10 -6 < TFFR < 10 -5 Compliance to Basic Integrity measures NEW CENELEC STANDARDS & CSM-RA 2017
CSM-RA & SAFETY CASE CSM-RA CENELEC What is done Executive summary System definition System description Introduction 1 QA System description Definition of System 2 QA Audit Safety Plan Quality Management Report 3 Safety Management Report Risk Management Safety Management Audit Hazard Log (activities) Hazard Record Hazard Log (register) 4 Technical Safety Report 5 Related Safety Cases Evidence of implementation Safety requirements Safety Analysis 6 Conclusion NEW CENELEC STANDARDS & CSM-RA 2017
Concept Feedback on RAMS into risk analysis 11 22 Risk Analysis and Risk evaluation Specification of of Specification System Requirements System Acceptance Design and Design Implementation 10 Safety Case 33 44 99 System Validation System Architecture & & Architecture 5 Apportionment of of Sys. Req 5 Apportionment Control of RAMS Requirements 11 1 Decommissioning 2 System Definition and System Operational Concept Operational Operation, Maintenance Performance Monitoring 88 Integration 66 Manufacture 77 NEW CENELEC STANDARDS & CSM-RA 2017
V & V INDEPENDENCE ARRANGEMENTS Independent of project Project Management SIL 4 / SIL 3 (Vital) Design Basic Integrity Validator Verifier OR Independent of project Project Management Verifier Design SIL 2 / SIL 1 Independent Safety Assessor Project Management Design Verifier Validator Independent Safety Assessor NEW CENELEC STANDARDS & CSM-RA 2017
CENELEC & CSM-RA New EN 50126 & EN 50129 • No Contradiction with CSM-RA – but a good Code of Practice for the process • CENELEC -> provide the good practice • Fill-in on products NEW CENELEC STANDARDS & CSM-RA 2017
THANK YOU QUESTIONS ? STIG MUNCK SGM@RAMBOLL. DK +45 5161 6375 New CENELEC Standard. S NEW CENELEC STANDARDS & CSM-RA 2017