Understanding Safety Integrity Levels
Understanding Safety Integrity Levels
The SIL
Safety Integrity Level
Security integrity level
Preface
Summary 1 INTRODUCTION
> 8SOURCES................................................................................................p.37
p.4 p.5
2 HISTORY 3 DEFINITIONS
The security layers matrix 3 10-4≤ PFD < 10-3 1.000≤ RFF < 10.000
The semi-quantitative method (ALARP) 2 10-3≤ PFD < 10-2 100≤ RFF < 1.000
1 10-2≤ PFD < 10-1 10≤ RFF < 100
Process
Diagram 3: Typical construction of protective layers
p.12 p.13
2oo2 (m=2 and n=2): This architecture includes two 4.5 COMBINATIONS OF SIS
connected elements in parallel so that it is In some cases, a very effective risk reduction factor
necessary that both elements request the function of high may be necessary. However, the realization of systems
security before it occurs. Both must high-level SIL instruments are difficult and
elements are operational to ensure the function of expensive (especially the SIL 4 level, very complex).
safety. The dangerous failure of a single element
prevents the correct processing of any alarm signal It may be advantageous in this case to combine several
valid. SIS of a lower SIL level. It is then appropriate to be
2003 (m=2 and n=3): This architecture includes three attentive to common cause factors, which will come
elements connected in parallel with a logic device reduce the risk reduction factor obtained.
majority for the output signals so that the state These factors are numerous and can be difficult to
the output is not modified when only one element gives a eliminate. Can be cited:
result different from the other two elements. As long as two Electronic components of the same origin
elements are operational, security is guaranteed. It
Human factors (programming, maintenance)
it would require the dangerous failure of two elements for
that a valid alarm signal is not processed correctly. Programming language
This architecture currently represents the 'state of the art' because Climate factors
it allows a good compromise between security and availability It is generally discouraged to use together
production tools. two identical systems, which will share many
common causes. It is better to use a second
4.4 TYPICAL ARCHITECTURES non-redundant system.
The concept of minimal tolerance to anomalies, seen in In practice, when several SIS are used in series, the
4.2.4 led to the creation of 'type' architectures, the SIL level retained for the whole will be the lowest of
allowing to meet the criteria of SIL1, SIL2, or SIL3. all the SIS. When several SIS are used in parallel,
• SIL 1: Architecture 1oo1 with 1 sensor, 1 unit of an analysis of common modes will be necessary for
treatment and 1 terminal element. determine whether the overall SIL level can be increased. In
• SIL 2: Integration of diagnostic functions and in any case, the SIL3 level cannot be
redundancy of sensors and the processing unit. outdated.
The terminal element can also be the subject of
redundancy.
• SIL 3: Typically, redundancy of sensors, of the unit
of processing and the terminal element; functions of
advanced diagnostics, online validation of the function of
security to limit the frequency of attempts.
p.20 p.21
5
4.6 NOTIONS OF COST
One will easily understand that risk reduction APPLICATIONS :
increasing by a factor of 10 between each SIL level, the SYSTEMS
requirements for the equipment and multiple redundancies
possibilities heavily impact the cost when the level of
SIL requested increases. 5.1 BEST PRACTICES
As a reference, we consider that the cost of development 5.1.1 Proven concept
and dual equipment when the SIL level Once the security-instrumented system architecture
increases by one unit. All precautions taken, it can defined, it is necessary to proceed with the selection of components and
It would be more interesting to use a SIL1 and a SIL2 instead. subsets. The EN 61511 standard requires the use of
that a SIL3. components certified according to EN 61508 (elements
electric and electronic) or proven.
This option has been added due to the low number.
field equipment (e.g., valves) designed according to
the EN 61508.
5 Based on the analysis of feedback, it is necessary to
demonstrate that the equipment will be capable of achieving the PFD
target and that it is usable in architectural conditions
1 determined during the design of the SIS.
1 2 3 4 By definition, users are reluctant to use
SIL level new technologies for security functions, the
the feedback will mainly come from the
process control functions. However, it will be necessary to
Diagram 4: Link between SIL and the cost of the instrumented system ensure that the terms of use are
of security comparables.
One of the main difficulties of the application of
The concepts of SIL is the collection of feedback.
to help operators and manufacturers, bases of
data was collected (see chapter 7). However,
in order to have a sufficient statistical panel, the
materials are grouped by families, which limits the precision
reliability data.
In order to be representative and exploitable, the data obtained
the feedback must necessarily hold
account for certain parameters.
p.22 p.23
PARAMETERS Self-diagnostic
Just like before, a detection function or
Field device
(valves, sensors...) Logical units forecasting dangerous failures helps to limit the
recourse to redundancies.
• Hardware version It is therefore recommended to provide self-diagnosis functions,
Function when the process allows it.
• Version software
Operating range Software
Process conditions I/O Configuration
(pressure, T°, products) 5.2 MAINTENANCE OF SIL LEVEL
Connection to the process Response time
• Solicitation rate The evaluation of the SIL of a safety instrumented function
is insufficient to ensure the maintenance of the level of
Environmental conditions security over time. Indeed, like any device,
Electromagnetic compatibility the system is subject to aging, which will alter its
performances and effectively lower the achieved SIL.
Schema 5: Minimum parameters to consider 5.2.1 Testability
during the feedback return Periodic tests allow for the detection of failures.
dangerous.
The interval of these carefully chosen tests allows for
guarantee the required level of trust (graph below).
This interval is particularly relevant during the calculation of
5.1.2 Positive Security PFD/PFH.
A positive security system (or intrinsic security, or The SIL of a system or the SIL capacity of a component is
"fail safe" is a system that enters a state therefore inseparable from the determined period for the tests.
of safety in its main mode of failure.
A certain number of precautions must be taken when
For example, we cite a valve equipped with an actuator. from the design of test phases. Indeed, the implementation
single-acting pneumatic designed to stop a flow in case of trials may require the establishment of diversions
of suppression. A loss of compressed air supply (shunt) reducing the security level of the SIS. Some
The actuator will cause the valve to close. appropriate procedures must be established in order to inform
Some systems cannot be fail-safe, and to limit such situations in time.
They are said to be 'at emission'. This is typically the case.
of a fire and gas detector or a water curtain.
As seen in table 7, the use of this type of elements
allows to limit the minimum tolerance to anomalies of
material, and therefore the redundancies.
p.24 p.25
10-2
SIL2
10-3
SIL3 SIL2
10-4
SIL4 SIL3
T1
10-5 T1
SIL4
T2 T2
TIME TIME
Element 1
Element 2
test interval of element 1 full test interval
test interval of element 2 partial test interval
Diagram 6: Evolution of the PFD of 2 elements in the Diagram 7: Evolution of the PFD of the same subset
The element 2 is capable of maintaining a rate of depending on whether he undergoes a full long-term test or
failure compatible SIL3 longer than element 1. partial tests at a higher frequency. The level of
SIL2 is maintained longer with partial tests.
6
5.3 OTHER CRITERIA
APPLICATIONS :
5.3.1 Response time
PLUMBING
A target response time must be determined for each
safety function, depending on the kinetics of the
consequences of a feared event. We saw it, an instrumented security system
A chain chemical reaction will require for example compose from the following chain.
a security measure much quicker than a
overflow of petroleum product storage tank. Sensor Logical unit Terminal element
Just like the level of security integrity, this time of
response should be evaluated regularly in order to detect In very many cases, if not the majority,
possible anomalies. The tests may be partial the terminal element that will physically put the
when a complete online test is not feasible. The process in a safe state is a valve. However, it is estimated
5.3.2 Integration of the human factor that the valves are responsible for 50% of the anomalies
The EN 61508 and EN 61511 standards do not provide for affecting the security instrumented systems!
the integration of the risks related to human factors into calculations Both shut-off valves and
the PFD of an instrumented safety function, for the Adjustment valves can be used in SIS.
simple reason that it is not quantifiable. In the case of control valves, it should be remembered that it
Instrumented off-function, it is nonetheless estimated that the It is difficult to reach a high SIL level when the
The PFD of a trained and unstressed operator is included. security functions are not independent of
between 10 -4
and 10
-2
and in stressful situations, the PFD is those of process control.
ranging from 0.5 to 1 (from 50% to 100% risk) Safety valves are components.
of error !). widely used for risk reduction, but
The necessary integration of the human factor during the they are generally not instrumented and are not
development of instrumented safety functions so not considered during safety studies of
will be through the user documentation, which will have to be operations related to the SIL.
extremely explicit, as well as through the training of
operators. 6.1 APPLICATION OF SIL CONCEPTS
Two cases can be distinguished, depending on the needs:
6.1.1 Provide reliability data
At the request of the integrator, the faucet supplier
must indicate reliability data (and not some)
SIL values, which concern the safety chain). It
it is therefore a matter of implementing a feedback process
of experience, which is structured as follows:
Determination of failure modes (FMEA)
Collection of reliability data under real conditions (or to
defect, by tests)
Counting to assign failure rates to
identified modes.
p.28 p.29
2 MANAGEMENT OF ANOMALIES
3 FUNCTIONAL DESCRIPTION OF THE ORGAN DE CONCEPTION ET FABRICATION
Identification of influencing factors from the design stage
4 ANALYSIS OF FAILURE MODES OF THE ORGAN Implementation of preventive and corrective measures
Requires a structured organization
Effective Quality Assurance System
5 EVALUATION OF THE RELIABILITY OF THE ORGAN
3 FUNCTIONAL DESCRIPTION
Scheme 8: General approach to security assessment MATERIAL OF THE ORGAN
functional.
The report 'Performance - Application Guide for Gather the useful information afterwards:
"SIL concepts to valve equipment" • Material constitution of the organ (physical limits,
from a study of the Professional Taps Commission nomenclature, overall plan
the CETIM (see references in chapter 8) provides a • Operating principle (principle diagram, mode of
detailed description of the different steps. The diagram continuous / intermittent operation
below summarizes the various points to be addressed. Functional decomposition of the organ (technical functions
interns to secure, associated characteristics and performances,
participation of technical functions in service functions
Participation of components in technical functions
p.30 p.31
7
CERTIFICATION
AND BASES
0.1 OF DATA
The use of certification is not mandatory for
certify the conformity of a SIL level according to the
0.01 standards EN 61508 or EN 61511. However, it is about
a good way to attest to the quality of the work done
work and respect for the numerous requirements
requirements.
0.001
TIME The classic approach to certify a level of SIL
Partial test period for an instrumented security system dedicated to a
industrial process involves using electrical equipment and
Full test period
electronics certified according to EN 61508 and
equipment 'mechanical' tested by use.
Partial course test The main certification bodies proceed
according to the following approach:
Complete race test
• Life cycle assessment of equipment security.
Diagram 10: Influence of partial tests on the PFD • Evaluation of failure probabilities (dangerous
/ non-dangerous, detected / not detected.
This example clearly shows that the use of tests Evaluations are both qualitative (system
partial exams may help maintain a level of SIL at a of quality assurance) than quantitative (calculation of PFD
lower value, awaiting the full testing period, according to feedback data, trials, of
for example on the occasion of a scheduled stop of database, etc.).
the installation.
The offering in terms of certification services is still
If the use of partial run tests can be limited, many providers nonetheless offer
considered as a good practice, their implementation support and evaluation services. The
can be difficult: The list below enumerates some of the main actors.
Very short response time in this field. It is generally a process
• Very weak shutter speed costly.
• Normally closed valve: risk of loss of sealing
•… 7.1 TÜV RHEINLAND
• SIL certification according to the EN 61508 standard (electrical /
electronics / programmable electronics
Assessment of SIL characteristics by FMEA
Evaluation of SIL characteristics through the approach
"proven-in-use" according to the EN 61511 standard
[Link]/en
p.34 p.35
8 SOURCES
STANDARDS :
EN 61508-1: Functional safety of systems
electric / electronic / electronic
programmes related to security - Part 1 :
general prescriptions
EN 61508-2: Functional Safety of Systems
electrical / electronic / electronic
Programmables related to security - Part 2:
prescriptions for electrical / electronic systems
programmable electronics related to security
EN 61511-1: Functional safety - Systems
safety instruments for the industrial sector
Transformation - Part 1: framework, definitions,
requirements for the system, hardware and software
EN 61511-2: Functional Safety - Systems
safety instruments for the industrial sector
Transformation - Part 2: Guidelines for
the application of IEC 61511-1
EN 61511-3: Functional safety - Systems
safety instruments for the industrial sector
Transformation - Part 3: Tips for the
determination of security integrity levels
OTHER MEDIA:
• Guidelines for applying SIL concepts to
faucet equipment - CETIM Performances
Evaluation of technical security barriers -
Ω10 - INERIS
Assessment approach for human barriers
securityΩ20 - INERIS
File 'Process Security' - Measures November
2005
[Link]
[Link]
[Link]
All rights reserved - Reproduction prohibited - Edition 2011