After a failure within an item, normal operation is restored only when the fault is detected and negated (a safe state enforced) and then repaired and the item restored. Fault detection time equals the interval between tests for automatic periodic testing, the maintenance interval for detection by staff, the mean time between uses where detection is through operational use, and the lifetime of the system if no detection measure is specified; the negation time is the time to enforce a safe state automatically or by people; detection and negation together make the safe down time, the time allowed to detect and negate the latest fault before the output turns hazardous relative to the TFFR (in composite fail-safety the system stays safe but a further failure could be hazardous, in reactive fail-safety a transient permissive output could result); repair time can generally be neglected in the safety context because a safe state is held. Sufficient failure detection and negation mechanisms are demonstrated in the safety case.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.