The safety manual for a compliant item records everything needed to integrate it into a safety system, subsystem or element. It specifies the item's functions and their inputs and outputs, its hardware and software configuration identification, and constraints on use and assumptions behind its failure analysis. For each function it states the undetected and internally detected failure modes due to random hardware failure, failure modes of the internal diagnostics, failure rates for each, diagnostic coverage and test intervals for detected modes, outputs initiated by internal diagnostics, proof test and maintenance needs, information enabling external diagnostics, fault tolerance and type A or B classification; no claims about fault tolerance, SFF or other characteristics that depend on safe and dangerous mode assumptions may be made unless those assumptions are stated. For functions liable to systematic failure it states the systematic capability and the application instructions and constraints that must be followed for that capability to hold. Software compliant items have further requirements in Part 3 Annex D.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.