For each safety function the achieved integrity against random hardware failures (soft errors included) and from random data communication failures is estimated and must not exceed the target failure measure in the safety requirements specification. The estimate accounts for the system architecture in subsystems and the subsystem architecture in elements per function; failure rates of each subsystem and element in dangerous modes both detected and undetected by diagnostics, with justified data sources adjusted for operating conditions; susceptibility to common cause failure with justified assumptions; diagnostic coverage per Annex C, diagnostic test interval, and how often the diagnostics themselves fail undetected, with MTTR and MRT; proof test intervals and whether proof tests are fully effective; repair times; random human error where people must act on a detected failure; and the suitability of the modelling method chosen (cause consequence, fault tree, Markov, reliability block diagram, Petri net). Diagnostic credit for zero fault tolerance subsystems in high demand or continuous mode follows the process safety time or 100:1 rate rule; for fault tolerance above zero or low demand, diagnostic test interval plus repair time must be below the assumed MTTR. If the target is missed, the main contributors are identified, improvements evaluated (better components, common cause defences, more diagnostics, redundancy, shorter or staggered proof tests), implemented, and the calculation repeated.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.