Functional Safety: practical applications on devices

Reading time: 6 minutes - Difficulty: Medium
If you are looking for concise yet accurate answers to the key questions about the functional safety of components, systems, and industrial plants, you are in the right place. Discover the meaning of SIF and much more that is useful for everyday operations, explored in depth and verified by our assessors, certified FS Engineers (TÜV Rheinland).

1. What is a SIF and how is it implemented?

A SIF (Safety Instrumented Function) is a safety-related instrumented function, i.e. a function related to safety for which it is essential to guarantee a given SIL (Safety Integrity Level).
Let us take as an example the temperature control of a boiler. Every single component within this control system function, from the temperature probe to the boiler burner shutdown system, has a SIL rating.
 
Likewise, any one of the items that make up this function, such as the temperature probe, can be used for multiple safety functions, each with a different SIL level.
This means that within a plant there are multiple safety functions, each associated with a specific hazard and each associated with a specific SIL level. Therefore, the set of components in each system must comply with the overall SIL level to be achieved according to the standards established by IEC 61508.
 
To design a SIF in compliance with IEC 61508, risk and reliability analyses are carried out for SIL calculation purposes, supported by safety requirements documentation, as well as verification and validation of the function to test its performance. Learn more about what we can do for you.

2. Which devices must be assessed for SIL?

Among the devices covered by IEC 61508 and sector-specific standards are:

  • Sensors: pressure switches, temperature or level transmitters
  • Control logic: safety PLCs, safety relays, safety controllers
  • Actuators: emergency valves, motors, safety switches

In other words, every component representing a link in the Input – Logic – Output chain must be assessed for the SIL required by the safety function.

Save this link

SIL Level calculation

3. How are analyses such as LOPA or FMEDA carried out?

LOPA and FMEDA analyses are fundamental tools for assessing the risk and reliability of safety systems in industrial plants, in compliance, respectively, with IEC 61511 and IEC 61508 and related standards:

  • LOPA (Layer of Protection Analysis): a quantitative risk analysis according to IEC 61511-2 for one or more accidental scenarios classified according to the severity of consequences and frequency of occurrence. The analysis helps identify the risks present in complex systems or entire production processes by carrying out risk analysis for the purpose of determining the SIL level.
  • FMEDA (Failure Modes, Effects and Diagnostic Analysis): an analysis according to IEC 60812, based on the systematic breakdown of the product into its components in order to evaluate failure rates and their effects on safety functions. The analysis helps to understand how the failure of a single device impacts the entire system and with what consequences. Reliability studies are recommended for devices whose correct operation is essential for the availability of the entire system or industrial process. Learn more.

Recommended in-depth study

RAMS Engineering

4. What is an SRS (Safety Requirement Specification) and what does it contain?

The SRS (Safety Requirement Specification) is the technical document that defines what a safety function must do. For proper setup, it must be prepared according to functional safety standards before the device is designed.
 
Here is an example of the contents of an SRS prepared according to ISO 13849:

  • Expected risk scenarios and resulting risks to be reduced
  • Required PLr and category to be achieved
  • Requirements deriving from other applicable standards (e.g. Type C standards)
  • Safe state of the machine to be achieved after the activation of each safety function
  • Machine behavior in the event of a power supply interruption
  • Software requirements
  • Demand rate of safety functions
  • Response time of safety functions
  • Intended use and measures against reasonably foreseeable misuse
  • Priority of functions that may be active simultaneously and may cause conflicting actions
  • Environmental conditions
  • Maintenance constraints

5. How is OT cybersecurity integrated with functional safety?

OT cybersecurity is a necessary condition to ensure the reliability of SIL safety functions in connected or digitalized plants. Regulatory standards themselves highlight the close connection between safety and security: a cyberattack on a control system can compromise safety functions, with significant consequences for business continuity and asset protection.

For this reason, IEC 62443 fits into the safety world (IEC 61511, EU Machinery Regulation 1230/2023), suggesting a risk-based approach as a starting point. Implementing the IEC 62433 standard is an innovation that can be fully trusted.
 
Some of the recommended actions include:

  • Network segmentation
  • Access protection
  • Change control
  • Continuous anomaly monitoring
  • Update and patch management

The integration of cybersecurity and safety extends throughout the entire device lifecycle. Read the full article.

6. Why must SIL-certified PLCs also be cyber secure?

Because a SIL-certified PLC, like any other network-connected safety device, ensures reliability in the event of accidental faults, but does not automatically protect against cyber threats. A cyberattack on an automated safety device may prevent the safety function from being activated, thereby nullifying its intervention.

The ideal solution for having devices that are safe from every perspective is to maintain SIL certification according to functional safety standards and make the system compliant with IEC 62443 cybersecurity standards.