From the hazardous events identified, the full set of overall safety functions needed is developed, giving the overall safety functions requirements specification (stated in technology-independent terms at this stage). Where security threats were identified, a vulnerability analysis should be performed to set security requirements. Every overall safety function receives a target integrity requirement, quantitative or qualitative, set so that tolerable risk is achieved, expressed either as the risk reduction needed or as the tolerable hazardous event rate. If the EUC's control system is claimed to have a dangerous failure rate below 1e-5 per hour for a function, it becomes a safety-related system under the standard. Where the EUC's control system places demands on safety systems but is not to be designated safety-related, the dangerous failure rate it claims must be supported by operating experience, a recognised reliability analysis or an industry database, may not be claimed lower than 1e-5 per hour, all foreseeable dangerous failure modes must be considered, and it must be independent of the safety systems and other risk reduction measures; otherwise it is designated safety-related with its SIL taken from the claimed rate via Table 3.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.