IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems
Part 3, Clause 7: Software safety lifecycle – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems 3-7.4.4: Part 3, 7.4.4 Requirements for support tools, including programming languages

An online support tool counts as a software element of the safety system. Offline support tools are selected as a coherent part of development and their selection justified. Class T2 and T3 tools have a specification or product documentation defining their behaviour and constraints on use, and are assessed for how much reliance is placed on them and how they could fail in ways affecting the executable software, with mitigations where needed. Each T3 tool has evidence of conformance to its specification, from successful use in similar settings and/or tool validation, whose records give a chronology, manual version, functions validated, tools and equipment, results, test cases and discrepancies; without such evidence, effective measures must control failures caused by the tool. Integrated toolset compatibility is verified. To the extent the SIL requires, the language or design representation has an assessed translator, uses only defined features, suits the application, helps detect mistakes and supports the design method; shortfalls are justified with added measures. All safety-related code follows a coding standard that sets good practice, bans unsafe features, aids understanding, verification and testing, and governs source documentation (where practicable: legal entity, description, inputs and outputs, configuration history). Automatic code generators are assessed when tools are selected. Where T2 or T3 tools produce baseline items, configuration management records tool identity and version, the items affected and how the tool was used (parameters, options, scripts); only qualified, mutually compatible tool versions are used; each new tool version is qualified, possibly on prior-version evidence if differences will not affect compatibility and no significant new faults are likely. Responsibility splits are documented in safety planning.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 8:11.4.5 11.4.5 Evaluation of a software tool by analysis

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 3, Clause 7: Software safety lifecycle – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.