Cumputer Based Systems PDF
Cumputer Based Systems PDF
Cumputer Based Systems PDF
1 General requirements 1.5.3 The failure and restarting of computer based systems
should not cause processes to enter undefined or critical
states.
1.1 General
1.1.1 The characteristics of the system are to be compatible 1.6 System redundancy
with the intended applications, under normal and abnormal
process conditions. The response time for alarm function is 1.6.1 If it is demonstrated that the failure of the system,
to be less than 5 seconds. which includes the computer based system, leads to a dis-
ruption of the essential services, a secondary independent
1.1.2 When systems under control are required to be dupli- means, of appropriate diversity, is to be available to restore
cated and in separate compartments, this is also to apply to the adequate functionality of the service.
control elements within computer based systems.
2 Hardware
1.1.3 As a rule, computer based systems intended for
essential services are to be type approved.
2.1 General
1.2 System type approval 2.1.1 The construction of systems is to comply with the
requirements of Ch 3, Sec 4.
1.2.1 The type approval is to cover the hardware and basic
software of the system. The type approval requirements are
detailed in Ch 3, Sec 6. A list of the documents to be sub- 2.2 Housing
mitted is provided in Ch 3, Sec 1.
2.2.1 The housing of the system is to be designed to face
the environmental conditions, as defined in Ch 2, Sec 2,
1.3 System operation [1], in which it will be installed. The design will be such as
to protect the printed circuit board and associated compo-
1.3.1 The system is to be protected so that authorised per- nents from external aggression. When required, the cooling
sonnel only can modify any setting which could alter the system is to be monitored, and an alarm activated when the
system. normal temperature is exceeded.
1.3.2 Modification of the configuration, set points or 2.2.2 The mechanical construction is to be designed to
parameters is to be possible without complex operations withstand the vibration levels defined in Ch 2, Sec 2,
such as compilation or coded data insertion. depending on the applicable environmental condition.
1.3.3 Program and data storage of the system is to be
designed so as not to be altered by environmental condi- 3 Software
tions, as defined in Ch 2, Sec 2, [1], or loss of the power
supply. 3.1 General
3.1.5 Software versions are to be solely identified by num- 4.3 Transmission software
ber, date or other appropriate means. Modifications are not
to be made without also changing the version identifier. A 4.3.1 The transmission software is to be so designed that
record of changes is to be maintained and made available alarm or control data have priority over any other data. For
upon request of the Society. control data, the transmission time is not to jeopardise effi-
ciency of the functions.
3.2 Software development quality
4.3.2 The transmission protocol is preferably to be chosen
3.2.1 Software development is to be carried out according among international standards.
to a quality plan defined by the builder and records are to
be kept. The standard ISO 9000-1, or equivalent interna- 4.3.3 A means of transmission control is to be provided
tional standard, is to be taken as guidance for the quality and designed so as to verify the completion of the data
procedure. The quality plan is to include the test procedure transmitted (CRC or equivalent acceptable method). When
for software and the results of tests are to be documented. corrupted data is detected, the number of retries is to be
limited so as to keep an acceptable global response time.
The duration of the message is to be such that it does not
4 Data transmission link block the transmission of other stations.
4.2.2 The choice of transmission cable is to be made 4.5.3 When not in operation, the redundant network is to
according to the environmental conditions. Particular atten- be permanently monitored, so that any failure of either net-
tion is to be given to the level characteristics required for work may be readily detected. When a failure occurs in one
electromagnetic interferences. network, an alarm is to be activated.
4.2.3 The installation of transmission cables is to comply 4.5.4 In redundant networks, the two networks are to be
with the requirements stated in Ch 2, Sec 11. In addition, mutually independent. Failure of any common components
the routing of transmission cables is to be chosen so as to be is not to result in any degradation in performance.
in less exposed zones regarding mechanical, chemical or
EMI damage. As far as possible, the routing of each cable is 4.5.5 When redundant data communication links are
to be independent of any other cable. These cables are not required, they are to be routed separately, as far as practica-
normally allowed to be routed in bunches with other cables ble.
on the cable tray.
5 Man-machine interface
4.2.4 The coupling devices are to be designed, as far as
practicable, so that in the event of a single fault, they do not
alter the network function. When a failure occurs, an alarm 5.1 General
is to be activated.
5.1.1 The design of the operator interface is to follow ergo-
Addition of coupling devices is not to alter the network
nomic principles. The standard IEC 60447 Man-machine
function.
interface or equivalent recognised standard may be used.
Hardware connecting devices are to be chosen, when pos-
sible, in accordance with international standards.
5.2 System functional indication
When a computer based system is used with a non-essential
system and connected to a network used for essential sys- 5.2.1 A means is to be provided to verify the activity of the
tems, the coupling device is to be of an approved type. system, or subsystem, and its proper function.
8.1.1 The system tests are to be carried out according to Ch 9.1.1 System maintenance is to be planned and docu-
3, Sec 6. mented.
8.1.2 All alterations of a system (hardware and software) 9.1.2 Remote software maintenance amy be considered on
are to be tested and the results of tests documented. case by case basis.