A hazardous random fault in one item is found before it can turn hazardous in combination with a fault in another item or, in reactive fail-safety, before the single item's output becomes hazardous: the detection mechanism (self-test, comparison, encoding, monitoring, or detection by maintenance or operational use) is identified per fault class, its detection time established and shown consistent with the safe down time the TFFR requires, and the detection function itself is shown independent of the item it checks; for SIL 3 and 4 composite fail-safety functions with a dual electronic structure specific provisions apply to how the two channels are compared and how a discrepancy is treated.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.