Practice

 

It is important for us speaking the common language of IEC 61508 and IEC 60 511 with our partners that is why we show the interpretation of some (not total) expression.

Short form expressions:

ESD      Emergancy Shut Down system
SIL       Safety Integrity Level
SIF       Safety Instrumented Function
SIS       Safety Instrumented System
BPCS    Basic Process Control System
MTBF    Main Time Between Failure
MTTF    Main Time To Repair
PFD      Probabilty of Failure on Demand
PFH      Probabilty of Failure on Hour
LOPA    Layer of Protection Analysis
HAZOP  Hazard and Operation

^ up

Terms:

Voting
NooK The system remain in operation while K component from N component is working properly.
Redundancy
Special case of voting when N = 1 and K = 2.
Availability
Availability in continuous operation, in case of failure repair is possible during operation (Example: distillation plant).
Reliability
Availability in periodic operation, in case of failure, repair is not possible during operation (Example: airplane).

^ up

Safety principles:

Overall Safety Lifecycle
See our presentations.
Safety layers
See our presentations.
Principle of independency
The Safety system shall be independent from other protection layer. We shall build up a functional independent safety layer. For better understanding here is a figure showing the „Safety Pyramid” consist of different safety layer which are independent each others.

^ up

Safety pyramid:

Disaster recovery
(Civil organization)
Corporate organization
 
Fire/Gas protection
 
Safety vessels
 
Relief valves
 
ESD (SIS)
 
Critical alarms
 
Basic Process Control System (DCS)
 
Process technology
 

^ up

Interpretation of integration:

Every system is design to perform a given function. Under operation, the system working with information and process them. This information is needed for the operations, actions of the ESD system, but the result of processing these information may inform the operators about the proper operation of the system sending failure message to the operators about system status, when the system failed (when one transmitter in a 2oo3 system fails) or sending information about start up of a pump or closing a valves with time stamp. The standard says that never integrate the functions (like control loop and Safety Logic loop, SIF) but the status information about the system transferred to the DCS system is very useful as DCS platform is the workstation of the operators. That is called integration, but not the integration of the functionality rather integration only of the information. In practice ESD system never gets back instruction via bus from the BPCS but the opposite direction of the communication is allowed and useful. Same rule control the connection of the HART maintenance system to the ESD system.

^ up