IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems
Part 2, Clause 7: E/E/PE lifecycle (hardware) – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems 2-7.4.2: Part 2, 7.4.2 E/E/PE system design and development: general requirements

The design follows the design requirements specification and must meet: hardware safety integrity (architectural constraints of 7.4.4 and quantified random failure targets of 7.4.5); the Annex E architecture rules for ICs with on-chip redundancy unless equal channel independence is shown otherwise; systematic safety integrity through Route 1S (avoidance and control of systematic faults per 7.4.6 and 7.4.7 together with Part 3), Route 2S (proven in use per 7.4.10) or, for pre-existing software only, Route 3S; fault detection behaviour (7.4.8); and data communication requirements (7.4.11). Hardware and software implementing both safety and non-safety functions are all treated as safety-related unless sufficient independence is shown; requirements are set by the highest SIL unless implementations of different SILs are sufficiently independent; where independence is relied on, the method and its justification are documented. Software safety requirements are passed to the system developer, who reviews hardware and software requirements for adequacy (safety functions, integrity, interfaces). Design documentation specifies and justifies the integrated set of techniques and measures chosen for the SIL. Hardware and software interactions are identified, evaluated and documented. The design is decomposed into subsystems, each with a specified design and integration tests. After initial design, an analysis checks whether any foreseeable failure could create a hazardous situation or a demand on another risk control measure; if so the design is changed first, or the failure mode's likelihood reduced to match the target failure measure. De-rating should be considered for all hardware and running elements at their limits is justified in writing; ASIC-based safety functions use an ASIC development lifecycle.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4:6.4.3 6.4.3 System architectural design
  • 9:6 6 Criteria for coexistence of elements

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 2, Clause 7: E/E/PE lifecycle (hardware) – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.