13.07.2015 Views

Report on certificate - Tuv-fs.com

Report on certificate - Tuv-fs.com

Report on certificate - Tuv-fs.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5 Implementati<strong>on</strong> C<strong>on</strong>diti<strong>on</strong>s and Restricti<strong>on</strong>sUse of the Fail-Safe C<strong>on</strong>troller System Family FSC Versi<strong>on</strong> 710.x shall <strong>com</strong>ply with the currentversi<strong>on</strong> of the "Fail Safe C<strong>on</strong>trol (FSC) System Safety Manual" and the "Fail Safe C<strong>on</strong>trol (FSC)System Hardware Manual" and the "Fail Safe C<strong>on</strong>trol (FSC) Software Manual" and the “Fire andGas Applicati<strong>on</strong> Manual” and the “Fire and Gas Field Devices Interface Manual” and the “FailSafe C<strong>on</strong>trol Machine Safety Manual” of the <strong>com</strong>pany H<strong>on</strong>eywell Safety Management Systems.The following implementati<strong>on</strong> and installati<strong>on</strong> requirements have to be followed if the FSCVersi<strong>on</strong> 710.x is used in safety-related installati<strong>on</strong>s. The c<strong>on</strong>diti<strong>on</strong>s are arranged according to themajor stages of engineering a programmable electr<strong>on</strong>ic system for safety-related instrumentati<strong>on</strong>and protective equipment. The c<strong>on</strong>diti<strong>on</strong>s are further subdivided into n<strong>on</strong>-product-related c<strong>on</strong>diti<strong>on</strong>s which are not determined by the characteristics of the certifiedsystem but by the fundamental nature of safety-related programmable electr<strong>on</strong>ic systems, and product-related c<strong>on</strong>diti<strong>on</strong>s which arise from the characteristics of the certified system.5.1 Planning; N<strong>on</strong>-Product-Related C<strong>on</strong>diti<strong>on</strong>s5.1.1. The FSC Versi<strong>on</strong> 710.x can be used in applicati<strong>on</strong>s up to SIL 1-3 according to EN 61508and IEC61511.5.1.2. Only approved fail-safe hardware modules may be used for safety-related operati<strong>on</strong>. Theapproved hardware modules are listed in chapter 2.1.5.1.3. Checking of operating mode (RAM, FLASH or EPROM operati<strong>on</strong>), Safety Integrity Level,versi<strong>on</strong> number for the safety related software <strong>com</strong>p<strong>on</strong>ents defined in chapter 2.12"Release identificati<strong>on</strong>" and important system times such as test cycle time, sec<strong>on</strong>d faultoccurrence time, minimum and maximum program running time shall be performed bymeans of the "View FSC System and process status" program <strong>on</strong> the FSC Navigator(opti<strong>on</strong> parameters).In general, correct parameterisati<strong>on</strong> of system characteristics affecting safety should bechecked for all safety-related applicati<strong>on</strong>s (e.g. with the aid of the FSC diagnostic systemand fault simulati<strong>on</strong>).5.1.4. The safety system resp<strong>on</strong>se to faults and resp<strong>on</strong>se times shall be taken into c<strong>on</strong>siderati<strong>on</strong>and checked as detailed in chapter 4, “Results“, of this report.5.1.5. Safety-related resp<strong>on</strong>ses to faults which <strong>on</strong>ly result in an alarm are <strong>on</strong>ly permissible in thecase of operati<strong>on</strong> with permanent supervisi<strong>on</strong>.5.1.6. Except for fire detecti<strong>on</strong> and alarm applicati<strong>on</strong>s, the closed circuit principle shall be appliedto all external electrical safety circuits c<strong>on</strong>nected to the system. This means that for bothdigital and analog signals, the safe c<strong>on</strong>diti<strong>on</strong> is defined as the “zero c<strong>on</strong>diti<strong>on</strong>”.5.1.7. N<strong>on</strong>-fail-safe but n<strong>on</strong>-interacting modules may be used for processing n<strong>on</strong>-safety-relatedsignals but not for processing safety-related functi<strong>on</strong>s.5.1.8. Planning should include measures for provisi<strong>on</strong> of adequate overvoltage protecti<strong>on</strong> for the<strong>com</strong>plete system.TÜV SÜD Rail GmbH 717506225Generic Safety Systems HH84623C_Rev1.0.docx / Rev. 1.0Barthstraße 16 • D-80339 Munich • GermanyAuthor: Martin BraunPh<strong>on</strong>e: +49 (89) 5190 -2899, Fax: -2933 05.02.2013E-Mail: martin.braun@tuev-sued.de Page 29 of 33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!