EN 50126 / EN 50128 / EN 50129 - Railway Applications RAMS
EN 50128 clause 9: Software deployment and maintenance – EN 50126 / EN 50128 / EN 50129 - Railway Applications RAMS

EN 50126 / EN 50128 / EN 50129 - Railway Applications RAMS 50128:9.2: Software maintenance

Maintenance ensures that software being corrected, enhanced or adapted still does what is required and keeps its required safety integrity level and dependability. Maintainability is designed in (clause 7); procedures for maintenance are established and recorded in a software maintenance plan covering how errors are reported and logged, maintenance records, authorisation of changes, configuration control, verification, validation and assessment, and the authority that approves changed software (9.2.4.1 to 9.2.4.7). A software maintenance record is opened for every software item ahead of its first release and kept up, referencing every software change record for the item, the change consequence information, the component test cases with the data for revalidation and regression and the configuration history (9.2.4.8); a software change record per maintenance activity holds the change request, the impact analysis on the whole system, taking in the hardware, the software, human interaction and the surrounding environment, the detailed specification of the change, and the revalidation, regression testing and re-assessment performed to the extent the SIL requires (9.2.4.9 to 9.2.4.12). Verification of both records addresses readability and traceability and their specific content (9.2.4.13 and 9.2.4.14); maintenance follows the plan (9.2.4.15), the techniques of Table A.10 (impact analysis, data recording and analysis) are chosen and the combination justified (9.2.4.16), maintenance is performed with at least the same expertise, tools, documentation, planning, management, configuration control, change control, document control and independence as the initial development (9.2.4.17), control of external suppliers, problem reports and corrective actions follow 6.5 (9.2.4.18), a safety impact analysis is made for each reported problem or enhancement (9.2.4.19), and mitigations scaled to the risk found are taken for software under maintenance (9.2.4.20). The standard is not retrospective: it applies to existing systems in full only on major modification, the decision major or minor resting with the contracting entities at SIL 3 and 4 and the supplier at SIL 1 and 2.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in EN 50128 clause 9: Software deployment and maintenance – EN 50126 / EN 50128 / EN 50129 - Railway Applications RAMS

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.