IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems
Part 2, Clause 7: E/E/PE lifecycle (hardware) – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems 2-7.4.8: Part 2, 7.4.8 Requirements for system behaviour on detection of a fault

Detection of a dangerous fault (by diagnostics, proof test or other means) in a subsystem with fault tolerance above zero leads to a specified action to reach or hold a safe state, or isolation of the faulty part so the EUC can keep running safely during repair; if repair exceeds the MRT assumed in the random failure calculation, the safe-state action follows. In a zero fault tolerance subsystem used only by low demand functions, detection leads to the safe-state action or repair within the assumed MRT, with additional measures and constraints, documented in the operation and maintenance procedures, giving at least equal integrity meanwhile. In a zero fault tolerance subsystem serving any high demand or continuous function, detection leads to the specified safe-state action.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 2, Clause 7: E/E/PE lifecycle (hardware) – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.