The designated safety-related systems that will achieve functional safety are specified (E/E/PE safety systems, other risk reduction measures, or both), taking account of the skills and resources available across the lifecycle. Each overall safety function and its integrity requirement is allocated to one or more of them so that tolerable risk is met; allocation is iterative, and if tolerable risk is not reached the specifications are changed and allocation repeated, until every function is allocated with target failure measures. Integrity is stated as PFDavg for low demand, or as PFH (the averaged hourly rate of dangerous failure) in high demand or continuous mode, combined using suitable probability techniques. Allocation accounts for common cause failure: systems may be treated as independent only if simultaneous failure is sufficiently unlikely, they are functionally diverse, technologically diverse, share no parts, services or support systems whose failure could disable all, and share no operating, maintenance or test procedures; separation constraints (for example channels on one board) are checked; otherwise common cause failures are included in the allocation. Once allocation has progressed, each function's requirement is expressed as a SIL from Table 2 (PFDavg, low demand) or Table 3 (PFH, high demand or continuous). Where functions of different SIL share hardware or software without sufficient independence, those parts take the highest SIL. A SIL 4 allocation triggers reconsideration of risk parameters and, if kept, a quantitative risk assessment including common cause failures with demand-placing and other safety systems. No function may be allocated a target below the table limits (PFDavg 1e-5; PFH 1e-9). The allocation results, assumptions and justifications, including other risk reduction measures needing management through life, are documented.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.