Let's give it a try ....

Safety Critical Components :

Those components that encapsulate into one single component the 2 safety
layers
that are normally used to isolate the operator (and others) from a hazard.
In electrical safety land that's mostly an electrical hazard

Safety Related Component

All components that -by there function- may create a hazardous situation
when defective, direct or indirect.

All safety critical components are safety related; the inverse is not
necessary true.


As you may all know, most protection systems in safety land consist of 2
layers. A well known concept is double insulation.
Both layers of a double insulation are in themselves not a safety critical
component; once they are integrated into one part -called reinforced- they
are.
Both insulation layers are only safety related components. They have to meet
their specs; if one layer fails nothing happens. If they do not meet their
specs
you have a problem. That's why they are safety related.

A supply transformer of a not grounded SELV is a safety critical component.
A supply transformer of a grounded SELV is a safety related component.
The insulation sheets (if double) are safety related each.


The latter creates (when defective) a hazard only when the grounding fails.

I believe that similar reasoning can be made for most hazards, although most
safety related standards are not implementing this in full.

Fa. a hot component needs protection for the operator in 2 ways:

(1)limited access +  (2) warning

Both protection methods are safety related. If they are integrated in ONE,
or if one measure is not possible, the other becomes safety critical.

Fire protection:

2 measures:

(1) limit the temperature of component  + (2) no combustible materials close
to it


If you are not allowed to remove dangerous and flammable objects far away
from a heat
generating component, then the temperature limiter becomes critical.


To make the measures non critical another degree of protection is required.
This is called redundancy. ( in fact the second layer is redundant too, but
seen
from the safety perspective two layers is a minimum)

Creating a safe device has everything to do with creating multiple layers
of safety.

Letting your PC control a Hazardous process is an often made mistake against
this
rule. Not only is software error-sensitive (and difficult to debug), but the
hardware
most often is crash vulnerable. One crash would create a hazardous
situation.
Hardened Personal computers will limit this risk, as does certified
software,
but for true safe operation on the level we are used to work with in f.a.
insulations,
you would need 2 computers in parallel, plus a decision device, of which the
operation will then be safety critical.

The safety standard EN 60730 (that I am a bit familiar with) shows many ways
of
creating dual safety concepts for processor controlled hazardous processes.

The single fault concept we are familiar with is just a way of finding out
all just safety related components and -measures, so we can
finally identify the safety critical ones and take precautions.

Many standards have pre-cooked these concept in lists of simple measures,
more easy to use in checklist form. This does not mean we should limit
ourselves to these checklists.

The art of safety thinking is finding and recognizing these double
protection layers
in equipment, processes and concepts (or the lack thereof).
And most important: not forgetting one.



Regards,

Gert Gremmen, (Ing)

ce-test, qualified testing

===============================================
Web presence  http://www.cetest.nl
CE-shop http://www.cetest.nl/ce_shop.htm
/-/ Compliance testing is our core business /-/
===============================================


>>-----Original Message-----
>>From: [email protected]
>>[mailto:[email protected]]On Behalf Of Allen, John
>>Sent: Friday, November 02, 2001 9:52 AM
>>To: 'Rich Nute'; [email protected]; [email protected]
>>Subject: "Safety Critical" etc - the future
>>
>>
>>
>>Hi Folks
>>
>>We have now had this discussion and it brought out a number of useful and
>>enlightening points, and Lauren's and Rich's summaries of the
>>various inputs
>>are both interesting and thought-provoking.
>>
>>However, I now come back to a point that I made in one of my earlier
>>messages: Where do we go from here?
>>
>>For most people participating in this forum, I suspect that the major
>>contact that they have with any concept of component- criticality is in
>>respect of simple standards (e.g. standards mandated under the
>>LVD/EMC/R&TTE
>>or other national equivalents) compliance for a single item of equipment.
>>
>>Their major issue will, I guess, be the attitudes taken by the various
>>product test and certification authorities that they deal with
>>because those
>>organisations directly influence what the product design and manufacturing
>>companies need to reflect in their internal documentation and processes.
>>
>>Therefore, the test and certification authorities need to jointly
>>decide and
>>declare the following:
>>
>>a) The methods and criteria for identification, selection and listing of
>>"critical components" for both product standards compliance and system
>>safety compliance
>>
>>b) The terms they wish to use for the various aspects of criticality.
>>
>>Personal Comment:
>>I think that "safety critical component" is fine in the system safety
>>context - and that is how it is already referenced in many risk-assessment
>>standards and guidance documents.
>>
>>However, I am not so sure/happy about Rich's suggestion of
>>"safeguard" as I
>>think that it is similar to the term "safety critical" in the
>>system-safety
>>context but will sound rather "vague" to many non-knowledgable people (and
>>is not very appropriate in the context of product standards compliance).
>>
>>Nevertheless it seems to me that this subject does need to be debated at a
>>very high level (of knowledgable people!)within the IEC (notably the CB
>>Certification organisation, CENELEC and the US/Canadian NRTL organisations
>>with the object of reaching some mutually agreed methodologies. (Once they
>>reach some decisions, most other organisations will follow!)
>>
>>I know that some of the forum participants operate in these
>>areas, and thus
>>ask them how we should proceed from here?
>>
>>This will be a long process - but I think it is essential to kick it off
>>ASAP.
>>
>>Over to you guys!
>>
>>Regards
>>
>>John Allen
>>Thales Defence Communications Division (for the moment!!)
>>Bracknell, UK
>>
>>-------------------------------------------
>>This message is from the IEEE EMC Society Product Safety
>>Technical Committee emc-pstc discussion list.
>>
>>Visit our web site at:  http://www.ewh.ieee.org/soc/emcs/pstc/
>>
>>To cancel your subscription, send mail to:
>>     [email protected]
>>with the single line:
>>     unsubscribe emc-pstc
>>
>>For help, send mail to the list administrators:
>>     Michael Garretson:        [email protected]
>>     Dave Heald                [email protected]
>>
>>For policy questions, send mail to:
>>     Richard Nute:           [email protected]
>>     Jim Bacher:             [email protected]
>>
>>All emc-pstc postings are archived and searchable on the web at:
>>    No longer online until our new server is brought online and
>>the old messages are imported into the new server.
>>
>>

<<attachment: Gert Gremmen.vcf>>

Reply via email to