0% found this document useful (0 votes)
9 views22 pages

Understanding Safety Integrity Levels

This document presents the key concepts related to the safety integrity level (SIL) approach. It defines SIL, presents its history and basic principles, and describes its application for industrial systems and valves.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views22 pages

Understanding Safety Integrity Levels

This document presents the key concepts related to the safety integrity level (SIL) approach. It defines SIL, presents its history and basic principles, and describes its application for industrial systems and valves.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

WATER CYCLE INDUSTRY/ENERGY BUILDING

The SIL
Safety Integrity Level
Security integrity level
Preface

PROFLUID is the French professional organization


representative of pump and agitator manufacturers,
compressors and industrial and sanitary fittings. At
heart of national and European decisions, it is
member of the FIM (Federation of Mechanical Industries), of
PNEUROP (European Committee of Manufacturers of )
compressors, vacuum pumps and compressed air tools,
d'EUROPUMP (European Committee of Manufacturers of)
Pumps) and the CEIR (European Committee of the Pump Industry)
Fittings.
Having noted that the concept of security integrity level
(SIL approach) becomes a recurring theme, but very often
reserved for specialists, PROFLUID has decided to write a
presentation guide to help manufacturers understand
and use these concepts wisely.
p.2 p.3

Summary 1 INTRODUCTION

The SIL (Safety Integrity Level), or level of integrity of


> 1INTRODUCTION..................................................................................p.3
security, is a measure of the level of security provided by
a technical risk control measure, in a
> 2HISTORY...........................................................................................p.4
industrial environment.
> 3DEFINITIONS...........................................................................................p.5 This concept is gaining increasing importance among
operators and consequently with their suppliers;
> 4BASIC PRINCIPLES....................................................................p.7 the factors behind this trend are:
4.1 Determination of the required SIL.......................................................p.7 A regulatory pressure: operators must
4.2 Security life cycle of a system..........................p.7 provide proof that they have identified and addressed the risks
associated with their processes in order to obtain authorization
4.3 Calculation of PFD and redundancy...............................................p.18
to exploit.
4.4 Typical Architectures...................................................................p.19
4.5 SIS Combinations.....................................................................p.20 A societal pressure: the workers, the residents,
politicians are no longer inclined to accept exposure
4.6 Cost Concepts.....................................................................................p.21 at risk, however small it may be (precautionary principle).
> 5APPLICATIONS: SYSTEMS...........................................p.22 An economic pressure: beyond human losses
5.1 Good Practices................................................................................p.22 and materials, an incident or accident at an industrial site
leads to operating losses that can quickly
5.2 Maintaining the SIL level.........................................................p.24 jeopardize the viability of a site. In this regard, the approach
5.3 Other Criteria........................................................................................p.27 SIL is an extension of the LCC approach, Life Cycle
Cost, which, beyond the investment cost, takes into
> 6APPLICATIONS: VALVES..............................p.28 count the costs associated with operation and maintenance
6.1 Application of SIL concepts......................................p.28 of the equipment.
Through this document, which aims to be easily accessible, PROFLUID
6.2 Main difficulties......................................................................p.32
wants to present to its members the principles of the
6.3 Importance of Testability.....................................................p.32
approach and the main concepts associated with it. Without
> 7CERTIFICATION AND DATABASES.......p.34 being a technical guide, this document is therefore a tool
educational, intended for the uninitiated.
7.1 TÜV Rheinland........................................................................................p.34
7.2 Bureau Veritas.........................................................................................p.35
7.3 INERIS..............................................................................................................p.35
7.4 EXIDA................................................................................................................p.35
7.5 Databases.............................................................................p.36

> 8SOURCES................................................................................................p.37
p.4 p.5

2 HISTORY 3 DEFINITIONS

The consideration of operational safety during Operational safety


the design of systems is a relatively It is about the trust one can have in a system.
recent. It involves its reliability, testability, maintainability,
This type of approach was initiated in the early 1990s. its availability and its security.
by manufacturers and users of electronic equipment, Confidence level
where unexpected breakdowns were difficult to handle This is a quantification of operational safety.
counts in reliability calculations. An approach The SIL is a level of confidence, but other methods
Probabilistic methods thus began to take shape. can be used.
In 1998, a pooling of knowledge resulted in SIL (Safety Integrity Level)
the publication of the IEC 61508 standards series 'Safety The SIL, or safety integrity level, is a quantification
functional electrical/electronic systems integer number from 1 to 4 of the risk reduction level
programmable electronics related to security. specified for a safety function in a process.
Standards introduce for the first time the concept of SIL.
The SIL level is directly related to performance of the
They were subject to a revision in 2010.
security system :
Subsequently, in 2003, the IEC 61511 standards 'Safety
functional - Instrumented safety systems for the SIL PFD RRF PFH
"sector of transformation industries" have broadened this Probability of Factor of Probability of
notion of systems, integrating mechanical components, failure at the reduction failure
solicitation of risk dangerous per hour
called "actuators".
1 10-1at 10-2 10 to 100 10-5at 10-6
Proof of their interest and use, these standards have
2 10-2to 10-3 100 to 1,000 10-6at 10-7
were taken up at the European level (CENELEC) in 2002 for
the standard 61508 and in 2004 for the 61511. 3 10 -3 -4
at 10 1000 to 10,000 10-7to 10-8
4 10 -4
to 10 -5
10,000 to 100,000 10-8to 10-9
It is also noteworthy that the probabilistic approach initiated
by the SIL is frequently referenced in other standards, Table 1: Correspondences between performance and SIL
such as EN 13849, which deals with systems
of order, and which is a harmonized standard for the
SIS (Instrumented Safety System)
Directive Machines 2006/42/CE.
System performing one or more instrumented functions
Like any standard, these documents are applicable. security. The typical architecture is a sensor chain -
voluntary, however, some local regulations processing unit - actuator.
tends to make them indispensable. This is the case in
PFD (Probability of Failure on Demand)
France, which is implementing a monitoring system of
critical equipment for safety. For the systems Average failure probability under stress.
security instruments, the Level of Trust is part of PFH (Probability of Dangerous Failure per Hour)
information to track. This Level of Trust, in Average probability of dangerous failure, per hour,
many cases can be interpreted as the SIL. during continuous use.
p.6 p.7

RRF (Risk Reduction Factor)


Risk reduction factor = 1/PFD
4 BASIC
PRINCIPLES

FMEA (or FMECA) 4.1 DETERMINATION OF REQUIRED SIL


Analysis of failure modes and their criticality. The SIL level is an intrinsic characteristic of the
Systematic and inductive approach aimed at system. It is set by the operator following an analysis of
determine the potential failure modes of risk that will determine which barriers of
components of a system, their causes and their effects. These security measures must be put in place, with what level of
modes can be hierarchized by multiplying indices trust.
of severity, occurrence, and detection probability. We
then talk about FMEA or FMECA. The integration of Thus, the SIL level is a target that the equipment
diagnostic functions in this approach is also must satisfy, in a sustainable manner.
If possible, then it is the FMEDA method.
MTBF (Mean Time Between Failure) 4.2 SECURITY LIFE CYCLE OF A SYSTEM
Average operating time before failure In order to design and operate an instrumented system of
MTTR (Mean Time To Repair) security, it is necessary for the company to rely on a
organized, competent, informed structure of the strategy
Average repair time after failure
in terms of security and having a planning of
ALARP (As Low As Reasonably Practicable) documented functional safety operations. This
Literally "as weak as reasonably possible". implies that suppliers must have a
Principle applicable for determining tolerable risk quality management system.
and required security integrity levels. The team responsible for security assessment
LOPA (Layer Of Protection Analysis) functional will rely on the life cycle analysis of
system security.
Analysis of protective layers. Qualitative method
allowing the assignment of safety integrity levels to A typical form of the security life cycle is given
technical barriers depending on the results of in diagram 1.
risk analysis.
HAZOP (Hazard and Operability study)
Risk analysis method for an industrial process, by
systematic study of possible anomalies, of their
causes and their consequences.
p.8 p.9

4.2.1 Analysis of hazards and risks


Objective: Identify the dangers and events
dangerous of the process and associated equipment, the
Hazard analysis sequence of events leading to the event
and risks dangerous, the risks associated with the process
the dangerous event, the requirements regarding the
risk reduction and the required safety functions
Allocation of functions to achieve the necessary risk reduction.
security layers
of protection Method: Generally the 'bow tie', which distributes,
around the dreaded central event, its causes and its
consequences. The HAZOP method allows for the identification and
to assess the dangers in a process installation,
Prescriptions Conception & as well as issues of fitness for operation without
of security development danger susceptible to compromising its ability to
Specification other means
risk reduction achieve the expected level of productivity.
for the SIS

Article Anomalies Causes Consequences


Conception &
SIS engineering Failure
ContainerLevel
raised
of the systemPressure
raised Operator
of conduct
Installation, putting in place
Evaluate the
in service & validation Alarm, conditions
Level Spill operator for the
Pressure raised yourelease layer of spillage
protection or the
Exploitation & raised Fire in clearance
Maintenance external the environment
System in
deluge the environment
ment
Modification Flow No Failure
weak of the system consequence
nonexistent interesting driving
Declassification
Flow None
consequence
inverted interesting
Diagram 1: Security life cycle of a system
Table 2: Example of HAZOP study results
p.10 p.11

Causes Consequences An important work of analysis and documentation has already


was carried out by the operators and manufacturers to associate
a required SIL level at an identified risk level.
Specifically, the levels thus defined correspond to
Event failure probabilities of the safety loop
feared (including all its components). The values are
indicated in the two tables below.

Tree of causes Event tree


Continuous operation (e.g. control valve)
Diagram 2: Generic example of a butterfly node: SIL level PFH
barriers can help prevent the event
fear or reduce its consequences. 4 10-9≤ PFH < 10-8
3 10-8≤ PFH < 10-7
4.2.2 Allocation of security functions 2 10-7≤ PFH < 10-6
Objective: Allocation of security functions to layers 1 10-6≤ PFH < 10-5
of protection and for each instrumented function of
Table 3: Correspondences between SIL and probability of
security, the level of associated security integrity.
dangerous failure per hour
Method: By analyzing the butterfly node, layers of
protection is defined, as well as the levels of SIL
associated with each instrumented system. Methods
are explained in the EN 61511-3 standard. Among these Operation in solicitation mode (e.g. shut-off valve)
methods, we can mention:
SIL level PFD RFF
Layer of Protection Analysis (LOPA)
The calibrated risk graph 4 10-5≤ PFD < 10-4 10,000≤ RFF < 100,000

The security layers matrix 3 10-4≤ PFD < 10-3 1.000≤ RFF < 10.000

The semi-quantitative method (ALARP) 2 10-3≤ PFD < 10-2 100≤ RFF < 1.000
1 10-2≤ PFD < 10-1 10≤ RFF < 100

Table 4: Correspondences between SIL and probability of


t failure or risk reduction factor

Process
Diagram 3: Typical construction of protective layers
p.12 p.13

The method of the safety layer matrix is 4.2.3 Safety prescription


frequently used to determine the level or levels Objective: Specify the requirements for each SIS, in
of SIL required. As explained in table 5, in terms of instrumented security functions required and
crossing the gravity and the probability of occurrence of their associated security integrity, in order to obtain security
dangerous events identified, we can determine required functionality.
simply the required SIL level, according to the number of
Method: The aim is to provide a specifications document.
protective layers to be implemented.
detailed to the equipment suppliers, it is about realizing
For example, a minor dangerous event, but of a comprehensive and detailed study of the conditions of
high probability of occurrence will require a system operation of safety instrumented systems.
level 2 security instrument or two This analysis must among other things identify:
level 1 protective layers.
The SIL level for each safety function
Common modes of failure
Name • The individually safe states of the process, which,
of layers combined, can create a danger
of protection Required SIL level
The permissible parasitic trigger rate
3 1 1 The average repair time...
2 1 1 2 1 2 3
1 1 2 1 2 3 3 3 3 4.2.4 Design and engineering of the SIS
Probability Objective: To design the SIS to meet the requirements
of occurrence instrumented functions of security and integrity of
of an event
dangerous security.
Minor Grave Very serious Method: In addition to complying with the specifications defined by
the operator, the requirements are numerous. Some
Ranking by severity of which are detailed below:
dangerous events
Independence of security functions and functions
Table 5: Example of a security layer matrix unsafe.
• If it is not possible, the non-secure functions
must be treated according to the highest SIL level.
SIL3 insufficient, plan for
additional protections Taking into account the operational necessities of the
maintenance and tests during design,
notably ergonomic.
Taking into account the level of qualification of the personnel
Examples of SIL level:
to which the equipment is intended.
SIL 1: 'classic' gas detection system
• Stability in a safe state until reset.
SIL 2: automotive ABS braking system
Presence of manual actuators on the elements
SIL 3: train braking system terminals.
SIL 4: railway signaling system Food monitoring.
p.14 p.15

•Handnilgofdetcetddangerousanomaeilsn,i 4.2.5 Installation, commissioning and validation


taking into account a repair time longer than Objective: Integrate and test the SIS. Validate that the SIS
Specified MTTR. satisfied, in all respects, with the security requirements, in
Tolerance to equipment anomalies (ability to terms of instrumented safety and integrity functions
function in case of component failure). required security.
Involves the design of redundant subsystems. Method: The installation and commissioning must be
planned in order to have the material resources and
Minimal tolerance to equipment anomalies necessary humans. In view of the security validation
the SIS, all the operating modes of the process
SIL SFF < 60 % 60% ≤ SFF ≤ 90% SFF > 90 % must be swept, including abnormal conditions
reasonably predictable.
1 1 0 0
2 2 1 0
3 3 2 1 4.2.6 Exploitation and maintenance
4 Particular requirements (see EN 61508) Objective: Ensure that the functional safety of the SIS is
preserved during operation and maintenance.
Table 6: Minimum tolerances for anomalies of
material according to the SILlevel (programmable electronics) Method: Exploitation and maintenance in particular
must be planned, by addressing:
• Periodic and unusual operating activities
SIL Minimum tolerance to equipment anomalies Periodic testing and maintenance activities
preventive and troubleshooting
No security Positive security Proven equipment The procedures, measures, and techniques to be used for
positive or self-diagnosis protection the operation and maintenance
self-diagnostic settings
It is particularly important to document the
1 1 0 0 necessary procedures to maintain a level of
2 2 1 0 acceptable safety when a shunt (short-circuiting of the
3 3 2 1 safety barrier) is necessary for maintenance or to the
periodic tests.
4 Specific requirements (see EN 61508)
These tests are of crucial importance for maintenance
Table 7: Minimum tolerances for anomalies of of the security integrity level provided by the SIS. They
equipment according to the SIL level (sensors, elements must allow to verify the correct functioning of
terminals, non-programmable logic each sensor, terminal elements, the right one
realization of the logical action as well as the good
• Choice of components and subsystems: possibility operation of signaling and alarms. A plan
to choose elements 'proven by use'. It is A visual inspection must necessarily be established.
It is important to gather as much feedback as possible.
possible.
Requirements regarding maintainability and testability (in
globality or by parts.
• Calculation of failure probabilities. Several tools
existent, in different domains of validity (Simulation,
FMEA, Failure Tree, Markov Models…
p.16 p.17

4.2.7 Modification 4.3 PFD CALCULATION AND REDUNDANCY


Objective: To make corrections, improvements or As seen in 4.2.4, achieving certain levels of SIL
adaptations to the SIS, ensuring that the level of integrity requires tolerance to hardware anomalies. The
The required security is obtained and maintained, even improved. infinite reliability components do not exist, the good
Method: Any modification must be justified and its The practice is to implement redundancies.
detailed and quantified consequences. It is particularly relevant For example, instead of using a pressure sensor, we use one.
to conduct pre- and post-modification tests to identify use 2 or 3, with a voting system to trigger
of potential harmful effects. the security action.
The choice of architectures will impact reliability,
4.2.8 Downgrading as well as availability. The literature concerning the calculation
The probability of dangerous failure (PFD) is
Objective: Ensure the review, the ad hoc sector organization,
abundant and is not the subject of this document. The
and ensure that the SIF remains appropriate.
FMEDA approach that helps determine the rates of
Method: An evaluation of the impact of the downgrade on certain, dangerous, detected and undetected failures
functional safety as well as an update of the study detected is frequently used. It should be noted that the
hazard and risk assessments must be carried out. multiplication of independent channels allows for reduction
the PFD, and that a 'vote' system by majority allows
to increase availability. The additional cost incurred by this
4.2.9 Verification this type of architecture is often compensated by
Objective: Try and evaluate the outputs of a phase minor operating losses.
data, to ensure accuracy and consistency with regard to The most commonly encountered architectures related to this
to the products and standards provided as inputs to this the latest types of redundancy are as follows:
phase.
With n=number of independent channels, and m=number of
Method: Verification is a planned activity, each signals necessary for triggering the action of
life cycle phase must be the subject of a plan and the security
verification results must be traced. Many
1oo1 (m=n=1): This architecture includes only one.
tools are possible, and depend on the phase to be verified and
of the complexity level of the material. Likewise, the element, and any dangerous failure of this element
prevents the correct processing of any alarm signal
the frequency of assessments depends on the complexity,
valid.
the importance of security, of feedback
available on similar systems. 1002 (m=1 and n=2): This architecture includes two
connected elements in parallel so that each
The evaluators are necessarily independent of
may handle the security function. As long as an element is
the team in charge of the system development as well as
of the one responsible for the operation of the process. Operational, security is guaranteed.
p.18 p.19

2oo2 (m=2 and n=2): This architecture includes two 4.5 COMBINATIONS OF SIS
connected elements in parallel so that it is In some cases, a very effective risk reduction factor
necessary that both elements request the function of high may be necessary. However, the realization of systems
security before it occurs. Both must high-level SIL instruments are difficult and
elements are operational to ensure the function of expensive (especially the SIL 4 level, very complex).
safety. The dangerous failure of a single element
prevents the correct processing of any alarm signal It may be advantageous in this case to combine several
valid. SIS of a lower SIL level. It is then appropriate to be
2003 (m=2 and n=3): This architecture includes three attentive to common cause factors, which will come
elements connected in parallel with a logic device reduce the risk reduction factor obtained.
majority for the output signals so that the state These factors are numerous and can be difficult to
the output is not modified when only one element gives a eliminate. Can be cited:
result different from the other two elements. As long as two Electronic components of the same origin
elements are operational, security is guaranteed. It
Human factors (programming, maintenance)
it would require the dangerous failure of two elements for
that a valid alarm signal is not processed correctly. Programming language
This architecture currently represents the 'state of the art' because Climate factors
it allows a good compromise between security and availability It is generally discouraged to use together
production tools. two identical systems, which will share many
common causes. It is better to use a second
4.4 TYPICAL ARCHITECTURES non-redundant system.
The concept of minimal tolerance to anomalies, seen in In practice, when several SIS are used in series, the
4.2.4 led to the creation of 'type' architectures, the SIL level retained for the whole will be the lowest of
allowing to meet the criteria of SIL1, SIL2, or SIL3. all the SIS. When several SIS are used in parallel,
• SIL 1: Architecture 1oo1 with 1 sensor, 1 unit of an analysis of common modes will be necessary for
treatment and 1 terminal element. determine whether the overall SIL level can be increased. In
• SIL 2: Integration of diagnostic functions and in any case, the SIL3 level cannot be
redundancy of sensors and the processing unit. outdated.
The terminal element can also be the subject of
redundancy.
• SIL 3: Typically, redundancy of sensors, of the unit
of processing and the terminal element; functions of
advanced diagnostics, online validation of the function of
security to limit the frequency of attempts.
p.20 p.21

5
4.6 NOTIONS OF COST
One will easily understand that risk reduction APPLICATIONS :
increasing by a factor of 10 between each SIL level, the SYSTEMS
requirements for the equipment and multiple redundancies
possibilities heavily impact the cost when the level of
SIL requested increases. 5.1 BEST PRACTICES
As a reference, we consider that the cost of development 5.1.1 Proven concept
and dual equipment when the SIL level Once the security-instrumented system architecture
increases by one unit. All precautions taken, it can defined, it is necessary to proceed with the selection of components and
It would be more interesting to use a SIL1 and a SIL2 instead. subsets. The EN 61511 standard requires the use of
that a SIL3. components certified according to EN 61508 (elements
electric and electronic) or proven.
This option has been added due to the low number.
field equipment (e.g., valves) designed according to
the EN 61508.
5 Based on the analysis of feedback, it is necessary to
demonstrate that the equipment will be capable of achieving the PFD
target and that it is usable in architectural conditions
1 determined during the design of the SIS.
1 2 3 4 By definition, users are reluctant to use
SIL level new technologies for security functions, the
the feedback will mainly come from the
process control functions. However, it will be necessary to
Diagram 4: Link between SIL and the cost of the instrumented system ensure that the terms of use are
of security comparables.
One of the main difficulties of the application of
The concepts of SIL is the collection of feedback.
to help operators and manufacturers, bases of
data was collected (see chapter 7). However,
in order to have a sufficient statistical panel, the
materials are grouped by families, which limits the precision
reliability data.
In order to be representative and exploitable, the data obtained
the feedback must necessarily hold
account for certain parameters.
p.22 p.23

PARAMETERS Self-diagnostic
Just like before, a detection function or
Field device
(valves, sensors...) Logical units forecasting dangerous failures helps to limit the
recourse to redundancies.
• Hardware version It is therefore recommended to provide self-diagnosis functions,
Function when the process allows it.
• Version software
Operating range Software
Process conditions I/O Configuration
(pressure, T°, products) 5.2 MAINTENANCE OF SIL LEVEL
Connection to the process Response time
• Solicitation rate The evaluation of the SIL of a safety instrumented function
is insufficient to ensure the maintenance of the level of
Environmental conditions security over time. Indeed, like any device,
Electromagnetic compatibility the system is subject to aging, which will alter its
performances and effectively lower the achieved SIL.
Schema 5: Minimum parameters to consider 5.2.1 Testability
during the feedback return Periodic tests allow for the detection of failures.
dangerous.
The interval of these carefully chosen tests allows for
guarantee the required level of trust (graph below).
This interval is particularly relevant during the calculation of
5.1.2 Positive Security PFD/PFH.
A positive security system (or intrinsic security, or The SIL of a system or the SIL capacity of a component is
"fail safe" is a system that enters a state therefore inseparable from the determined period for the tests.
of safety in its main mode of failure.
A certain number of precautions must be taken when
For example, we cite a valve equipped with an actuator. from the design of test phases. Indeed, the implementation
single-acting pneumatic designed to stop a flow in case of trials may require the establishment of diversions
of suppression. A loss of compressed air supply (shunt) reducing the security level of the SIS. Some
The actuator will cause the valve to close. appropriate procedures must be established in order to inform
Some systems cannot be fail-safe, and to limit such situations in time.
They are said to be 'at emission'. This is typically the case.
of a fire and gas detector or a water curtain.
As seen in table 7, the use of this type of elements
allows to limit the minimum tolerance to anomalies of
material, and therefore the redundancies.
p.24 p.25

10-2
SIL2

10-3

SIL3 SIL2

10-4
SIL4 SIL3
T1
10-5 T1
SIL4
T2 T2

TIME TIME

Element 1
Element 2
test interval of element 1 full test interval
test interval of element 2 partial test interval

Diagram 6: Evolution of the PFD of 2 elements in the Diagram 7: Evolution of the PFD of the same subset
The element 2 is capable of maintaining a rate of depending on whether he undergoes a full long-term test or
failure compatible SIL3 longer than element 1. partial tests at a higher frequency. The level of
SIL2 is maintained longer with partial tests.

Full testing allows for requalification


5.2.2 Maintenance
the equipment for a full period, but this is
sometimes very difficult to achieve. Indeed, some trials Who says test and self-diagnosis says detection of problems. It
require stopping the process or are very dangerous to it is necessary that maintenance operations be
to implement. It is therefore difficult to reconcile a level taken into account during the design of the system
raised from SIL and long test intervals (which security instrument. Maintenance operations in
would correspond, for example, to the scheduled stops of marches should not trigger a trigger
production). untimely, nor compromise the security of the process. The
the use of redundancies or derivations is often
To partially remedy this problem, many
necessary.
components or subsets contain functions
self-diagnosis, based on partial tests or by
party.
Although these tests do not allow for validation
the entirety of the system states, it is possible to scan
the main failure modes. One thus observes a
controlled derived from the SIL level.
p.26 p.27

6
5.3 OTHER CRITERIA
APPLICATIONS :
5.3.1 Response time
PLUMBING
A target response time must be determined for each
safety function, depending on the kinetics of the
consequences of a feared event. We saw it, an instrumented security system
A chain chemical reaction will require for example compose from the following chain.
a security measure much quicker than a
overflow of petroleum product storage tank. Sensor Logical unit Terminal element
Just like the level of security integrity, this time of
response should be evaluated regularly in order to detect In very many cases, if not the majority,
possible anomalies. The tests may be partial the terminal element that will physically put the
when a complete online test is not feasible. The process in a safe state is a valve. However, it is estimated
5.3.2 Integration of the human factor that the valves are responsible for 50% of the anomalies
The EN 61508 and EN 61511 standards do not provide for affecting the security instrumented systems!
the integration of the risks related to human factors into calculations Both shut-off valves and
the PFD of an instrumented safety function, for the Adjustment valves can be used in SIS.
simple reason that it is not quantifiable. In the case of control valves, it should be remembered that it
Instrumented off-function, it is nonetheless estimated that the It is difficult to reach a high SIL level when the
The PFD of a trained and unstressed operator is included. security functions are not independent of
between 10 -4
and 10
-2
and in stressful situations, the PFD is those of process control.
ranging from 0.5 to 1 (from 50% to 100% risk) Safety valves are components.
of error !). widely used for risk reduction, but
The necessary integration of the human factor during the they are generally not instrumented and are not
development of instrumented safety functions so not considered during safety studies of
will be through the user documentation, which will have to be operations related to the SIL.
extremely explicit, as well as through the training of
operators. 6.1 APPLICATION OF SIL CONCEPTS
Two cases can be distinguished, depending on the needs:
6.1.1 Provide reliability data
At the request of the integrator, the faucet supplier
must indicate reliability data (and not some)
SIL values, which concern the safety chain). It
it is therefore a matter of implementing a feedback process
of experience, which is structured as follows:
Determination of failure modes (FMEA)
Collection of reliability data under real conditions (or to
defect, by tests)
Counting to assign failure rates to
identified modes.
p.28 p.29

6.1.2 Indicate a SIL capability ANALYZE DUBESOIN


for a "catalog" equipment
Precise identification of the user's need:
This involves describing the security life cycle, Life cycle of the organ
as indicated in EN 61508, which serves as a reference for Operational and shutdown phases
different certification bodies (see chapter 7). Environment of the organ during each phase
• Regulatory and normative constraints
• Specific requirements
1 ANALYSE DUbESoIN

2 MASTERING ANOMALIES OF DESIGN AND MANUFACTURING

2 MANAGEMENT OF ANOMALIES
3 FUNCTIONAL DESCRIPTION OF THE ORGAN DE CONCEPTION ET FABRICATION
Identification of influencing factors from the design stage
4 ANALYSIS OF FAILURE MODES OF THE ORGAN Implementation of preventive and corrective measures
Requires a structured organization
Effective Quality Assurance System
5 EVALUATION OF THE RELIABILITY OF THE ORGAN

6 EVALUATION OF THE SECURITY LEVEL OF THE ORGAN

3 FUNCTIONAL DESCRIPTION
Scheme 8: General approach to security assessment MATERIAL OF THE ORGAN
functional.
The report 'Performance - Application Guide for Gather the useful information afterwards:
"SIL concepts to valve equipment" • Material constitution of the organ (physical limits,
from a study of the Professional Taps Commission nomenclature, overall plan
the CETIM (see references in chapter 8) provides a • Operating principle (principle diagram, mode of
detailed description of the different steps. The diagram continuous / intermittent operation
below summarizes the various points to be addressed. Functional decomposition of the organ (technical functions
interns to secure, associated characteristics and performances,
participation of technical functions in service functions
Participation of components in technical functions
p.30 p.31

6.2 MAIN DIFFICULTIES


To certify, and all the more so, to have a SIL capacity certified is not
4 ANALYSIS OF FAILURE MODES easy choice.
Failure Modes and Effects Analysis (FMEA) If the method seems to unfold naturally, the
Potential failure mode of the component the faucet designer will be almost
(under operating conditions) inevitably facing certain pitfalls:
Possible causes of this failure
Knowledge of operation and environment
Functional failure of the organ as a consequence
realities of the organ. This data is generally not
Prevention and protection measures implemented accessible to the manufacturer, who will therefore have to consider some
typical uses, under typical conditions.
• Evaluation of reliability: This is the main difficulty.
Feedback data is scarce and
5 EVALUATION OF RELIABILITY generally aggregated, which does not allow for
distinguish a design productα of a product of
Based on tests, feedback, databases of conceptionβIt is therefore desirable that practices
reliability or expert opinion, determination of failure rates
data sharing from experience feedback
components. If possible, we will determine:
establishing between manufacturers, operators and
• λSUundetected failure rates
certifying organisms.
• λSDsure failure rates detected
• λYOUrate of undetected hazardous failures • Notion of material 'tested by use'. The calculation of
• λDDrate of dangerous failures detected Based on feedback, it is difficult to
justifying a SIL capability on new equipment. By
consequently, manage to demonstrate the notion of 'tried'
by the use of new material, and, moreover,
Innovating is a challenge.
6 EVALUATION OF SECURITY LEVEL Differences between the practices of organizations
FUNCTIONALITY OF THE ORGAN certifiers.
Based on the failure rates determined previously, one can
calculate: 6.3 IMPORTANCE OF TESTABILITY
• PFH (organs functioning continuously): PFH =λDU* We saw it in the case of systems, and it's even more
PFDavg(organs functioning on demand): marked for the valves, due to their "mechanical" appearance,
PFDavg= λDDx MttR +λYOUxt/2 * the probability of failure on demand (PFDavg)
with MTTR: Mean Time to Repair, increases very quickly after each attempt of
T = mission period = frequency of tests operation.
valid formulas for a single-channel architecture
However, essays can be extremely complicated and
dangerous to organize, and the respect of downtime periods
installations may be contradictory with the SIL level
Diagram 9: General approach to security assessment sought after.
functional. Alternatives exist; it has thus been demonstrated that some
partial course tests on the valves allow for
lower the PFDavg. Specifically, it is about initiating the
shutter movement, without going as far as the action
complete (closure or opening).
p.32 p.33

7
CERTIFICATION
AND BASES
0.1 OF DATA
The use of certification is not mandatory for
certify the conformity of a SIL level according to the
0.01 standards EN 61508 or EN 61511. However, it is about
a good way to attest to the quality of the work done
work and respect for the numerous requirements
requirements.
0.001
TIME The classic approach to certify a level of SIL
Partial test period for an instrumented security system dedicated to a
industrial process involves using electrical equipment and
Full test period
electronics certified according to EN 61508 and
equipment 'mechanical' tested by use.
Partial course test The main certification bodies proceed
according to the following approach:
Complete race test
• Life cycle assessment of equipment security.
Diagram 10: Influence of partial tests on the PFD • Evaluation of failure probabilities (dangerous
/ non-dangerous, detected / not detected.
This example clearly shows that the use of tests Evaluations are both qualitative (system
partial exams may help maintain a level of SIL at a of quality assurance) than quantitative (calculation of PFD
lower value, awaiting the full testing period, according to feedback data, trials, of
for example on the occasion of a scheduled stop of database, etc.).
the installation.
The offering in terms of certification services is still
If the use of partial run tests can be limited, many providers nonetheless offer
considered as a good practice, their implementation support and evaluation services. The
can be difficult: The list below enumerates some of the main actors.
Very short response time in this field. It is generally a process
• Very weak shutter speed costly.
• Normally closed valve: risk of loss of sealing
•… 7.1 TÜV RHEINLAND
• SIL certification according to the EN 61508 standard (electrical /
electronics / programmable electronics
Assessment of SIL characteristics by FMEA
Evaluation of SIL characteristics through the approach
"proven-in-use" according to the EN 61511 standard

[Link]/en
p.34 p.35

7.2 BUREAU VERITAS 7.5 DATABASES


SIL assessment of functions, equipment, and systems The use of feedback is essential for
safety instruments according to the standards EN 61508, EN able to justify the 'proven by use' character of
61511… equipment.
• QUALISIL Certification: Certification of individuals for Some operators or organizations have thus developed
to attest to their qualification, to guarantee their databases compiling statistics on reliability
skills as well as mastery of a universal language components.
regarding the operational safety. The main database is that of OREDA,
[Link] organization created by major clients of
Oil & Gas market. This database is reputed
7.3 INERIS very conservative ([Link]).
SIL-INERIS certification according to the EN 61508 standard for The European database EIREDA (nuclear) is
electrical / electronic systems / electronics also an important source of information, but
programmable for security. relatively old. It is not available online
but can be ordered.
• QUALISIL Certification: Certification of individuals in order
to certify their qualification, to guarantee their One should be cautious about the use of
skills as well as mastery of a universal language statistics presented in the databases: this is
regarding operational safety. average data concerning large families of
products, which will not be able to reflect the different
[Link] technologies, nor the significant variations in conditions
common in industrial environments. The EN 61508 standard imposes
7.4 EXIDA Moreover, there are certain constraints for their use during the
• SIL certification according to the EN 61508 standard calculations of PFD.

FMEA and FMEDA


Justification of the notion of 'proven concept'
Provision of a database of equipment
having a certification
[Link]
p.36

8 SOURCES
STANDARDS :
EN 61508-1: Functional safety of systems
electric / electronic / electronic
programmes related to security - Part 1 :
general prescriptions
EN 61508-2: Functional Safety of Systems
electrical / electronic / electronic
Programmables related to security - Part 2:
prescriptions for electrical / electronic systems
programmable electronics related to security
EN 61511-1: Functional safety - Systems
safety instruments for the industrial sector
Transformation - Part 1: framework, definitions,
requirements for the system, hardware and software
EN 61511-2: Functional Safety - Systems
safety instruments for the industrial sector
Transformation - Part 2: Guidelines for
the application of IEC 61511-1
EN 61511-3: Functional safety - Systems
safety instruments for the industrial sector
Transformation - Part 3: Tips for the
determination of security integrity levels

OTHER MEDIA:
• Guidelines for applying SIL concepts to
faucet equipment - CETIM Performances
Evaluation of technical security barriers -
Ω10 - INERIS
Assessment approach for human barriers
securityΩ20 - INERIS
File 'Process Security' - Measures November
2005
[Link]
[Link]
[Link]
All rights reserved - Reproduction prohibited - Edition 2011

The elements contained in this document and


the exploitation that can be made of it cannot lead to
no way the responsibility of the French Association of
Pumps and Agitators, Compressors and
Faucetry.
45 Louis Blanc Street
92400 Courbevoie
+33 (0)1 47 17 62 98
+33 (0)1 47 17 63 00
Email:profluid@[Link]
[Link]

FEDERATION EUROPEAN ASSOCIATION EUROPEAN COMMITTEE EUROPEAN COMMITTEE


THE INDUSTRIES THE BUILDERS COMPRESSOR MANUFACTURERS OF THE INDUSTRY
MECHANICS PUMPS VACUUM PUMPS AND COMPRESSED AIR TOOLS FROM THE PLUMBING

You might also like