IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems
Part 3, Normative annexes A and D – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems 3-A.2: Part 3, Annex A Table A.2 Software architecture design techniques

Architecture techniques and design features selected for the SIL include fault detection, error detecting codes, failure assertion programming, diverse monitors (same or separate computer), diverse and functionally diverse redundancy, backward recovery (NR at SIL 4), stateless or limited-state design, retry recovery, graceful degradation, AI fault correction and dynamic reconfiguration (both NR from SIL 2), a modular approach (HR at all SILs), trusted or verified elements, two-way traceability linking the software safety requirements to the architecture (R at SIL 1 and 2, HR at SIL 3 and 4), structured diagrammatic, semi-formal or formal design methods, automatic software generation, computer-aided specification and design tools, cyclic execution with a guaranteed cycle time bound, time-triggered architecture, event-driven design with guaranteed maximum response time, static resource allocation and statically synchronised shared-resource access.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 6:7.4 7.4 Software architectural design

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 3, Normative annexes A and D – IEC 61508:2010 - Functional Safety of E/E/PE Safety-related Systems

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.