An organisation responsible for an E/E/PE safety system, or for lifecycle phases, appoints one or more people with overall responsibility for the system and its phases, for coordinating safety activities and interfaces with other organisations' phases, for coordinating functional safety assessments, and for ensuring functional safety is achieved and demonstrated. It must: specify the functional safety policy and strategy, how their achievement is evaluated and how they are communicated (6.2.2); identify everyone with lifecycle responsibilities, including verifiers, assessors and where relevant regulators, and tell them their responsibilities (6.2.3); set procedures for what is communicated between parties and how (6.2.4); ensure prompt follow-up and resolution of recommendations from hazard and risk analysis, assessment, verification, validation, configuration management and incident analysis (6.2.5); analyse every detected hazardous event and recommend measures against recurrence (6.2.6); specify periodic functional safety audits with their frequency, auditor independence, documentation and follow-up (6.2.7); control initiation and authorisation of modifications (6.2.8); keep hazard, hazardous event, safety function and system information accurate (6.2.9); apply configuration management, stating when formal configuration control begins, how every hardware and software constituent is uniquely identified and how unauthorised items are kept out of service (6.2.10); provide training and information for emergency services where appropriate (6.2.11). Phase owners specify the management and technical activities for their phases, including selected techniques and measures, the assessment activities and how achievement will be shown to assessors, and procedures for analysing operation and maintenance performance, recognising systematic faults and checking demand and failure rates against design assumptions (6.2.12). Everyone with defined responsibilities must be competent through training, technical knowledge, experience and qualifications, with refresher and continued assessment (6.2.13), judged against factors such as responsibility, supervision, consequence of failure, SIL, novelty, relevant experience, engineering and safety knowledge, legal and regulatory knowledge and relevance of qualifications, with rigour rising with consequence, SIL and novelty (6.2.14); competence is documented (6.2.15). These activities are implemented and monitored (6.2.16); suppliers deliver to the specification of the responsible organisation and operate a suitable quality management system (6.2.17); and management activities apply at the relevant lifecycle phases (6.2.18).
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.