beautypg.com

The safety life-cycle – Rockwell Automation AADvance Controller Safety Manual User Manual

Page 26

background image

2-2

Document: 553630

ICSTT-RM446K-EN-P Issue: 10

_C

Safety Manual (AADvance Controller)


The Safety Life-cycle

The safety life-cycle is defined by the IEC 61508 standard. It is designed to
structure a system's development into defined stages and activities as

follows:

Scope definition

Hazard and risk analysis

Functional and safety requirements specification

System engineering

Application programming

System production

System integration

System installation and commissioning

Safety system validation

Operation and maintenance plan

System modification

Decommissioning

The definition of each life-cycle stage shall include its inputs, outputs and
verification activities. It is not necessary to have separate stages within the

lifecycle addressing each of these elements independently; but it is

important that all of these stages are covered within the lifecycle. Specific
items that need to be considered for each of these life-cycle elements are

described in the following sub-paragraphs.

Scope Definition

The scope definition is the first step in the system life-cycle. You have to
identify the boundaries of the safety-related system and provide a clear

definition of its interfaces with the process and with all third party

equipment. This stage should also establish the derived requirements
resulting from the intended installation environment, such as

environmental conditions and power sources.
In most cases, the client will provide this information. The system
integrator must review this information and gain a thorough

understanding of the intended application, the bounds of the system to be

provided, and its intended operating conditions.

Hazard and Risk Analysis

The hazard and risk analysis has three objectives:

The first objective is to determine the hazards and hazardous events

of the controlled system for all reasonably foreseeable circumstances,

including fault conditions and misuse.