code_of_practice_V3_2019
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
6.7 ELECTRICAL SYSTEMS<br />
6.7.1 The electrical system should be designed with a level <strong>of</strong> integrity sufficient to enable the MASS to be operated<br />
and maintained safely as and when required within its design or imposed limitations in all RFOC.<br />
6.7.2 Sufficient electrical power should be provided to supply the required services <strong>of</strong> the MASS during all RFOC.<br />
6.7.3 Sufficient power should be provided to supply for MASS to conduct its mission with an appropriate level <strong>of</strong><br />
redundancy. It is acknowledged that for some smaller Classes <strong>of</strong> MASS there may be little, or no redundancy<br />
required.<br />
6.8 FIRE SAFETY<br />
5.8.1 Where fire safety systems are required, they should be designed to detect and extinguish a fire with a level <strong>of</strong><br />
integrity sufficient to enable the MASS to be operated and maintained safely and to protect the MASS in all RFOC.<br />
6.9 AUXILIARY SYSTEMS<br />
6.9.1 The auxiliary systems should be designed to support mission equipment and mission functions.<br />
6.9.2 If the MASS is to have a payload or carry cargo, it is not to have a detrimental effect on the MASS for the duration<br />
<strong>of</strong> its mission.<br />
6.9.3 The MASS is to have sufficient systems to support the embarkation <strong>of</strong> cargo and equipment for the duration <strong>of</strong><br />
its mission.<br />
6.9.4 If seamanship systems are fitted to the MASS, they are to ensure that the MASS can be recovered safely and<br />
undertake any seamanship operations as required (e.g. anchoring, mooring, towing etc).<br />
6.10 SOFTWARE INTEGRITY<br />
6.10.1 Functional Objective. For any activity that relies on the integrated use <strong>of</strong> equipment or sub-systems that include<br />
s<strong>of</strong>tware, the risks associated with s<strong>of</strong>tware and its integration into the equipment or sub-system are properly<br />
managed and that the s<strong>of</strong>tware is safe to use. A failure or unspecified behaviour <strong>of</strong> the s<strong>of</strong>tware shall not result in:<br />
n an event that escalates to a hazard; or<br />
n impairment <strong>of</strong> the mitigation <strong>of</strong> a hazard; and<br />
n impairment <strong>of</strong> recovery from a hazard.<br />
6.10.2 Performance Requirements. The way s<strong>of</strong>tware could be a stimulus event to a hazard, or impair the mitigation<br />
<strong>of</strong> a hazard, or impair recovery following such a hazardous event, shall be communicated to the appropriate<br />
parties.<br />
6.10.3 The production <strong>of</strong> s<strong>of</strong>tware shall be managed so that the safety risks arising from the s<strong>of</strong>tware production are<br />
reduced to an acceptable level.<br />
MASS UK Industry Conduct Principles and Code <strong>of</strong> Practice Version 3 45