IEC 61508 Is An International Standard Published by The International Electrotechnical Commission Consisting
IEC 61508 Is An International Standard Published by The International Electrotechnical Commission Consisting
IEC 61508 Is An International Standard Published by The International Electrotechnical Commission Consisting
IEC 61508 is an international standard published by the International Electrotechnical Commission consisting
of methods on how to apply, design, deploy and maintain automatic protection systems called safety-related
systems. It is titled Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related
Systems (E/E/PE, or E/E/PES).
IEC 61508 is a basic functional safety standard applicable to all industries. It defines functional safety as: “part
of the overall safety relating to the EUC (Equipment Under Control) and the EUC control system which
depends on the correct functioning of the E/E/PE safety-related systems, other technology safety-related
systems and external risk reduction facilities.” The fundamental concept is that any safety-related system must
work correctly or fail in a predictable (safe) way.
1. An engineering process called the safety life cycle is defined based on best practices in order
to discover and eliminate design errors and omissions.
2. A probabilistic failure approach to account for the safety impact of device failures.
The safety life cycle has 16 phases which roughly can be divided into three groups as follows:
All phases are concerned with the safety function of the system.
Central to the standard are the concepts of probabilistic risk for each safety function. The risk is a function of
frequency (or likelihood) of the hazardous event and the event consequence severity. The risk is reduced to a
tolerable level by applying safety functions which may consist of E/E/PES, associated mechanical devices, or
other technologies. Many requirements apply to all technologies but there is strong emphasis on programmable
electronics especially in Part 3.
Specific techniques ensure that mistakes and errors are avoided across the entire life-cycle. Errors introduced
anywhere from the initial concept, risk analysis, specification, design, installation, maintenance and through to
disposal could undermine even the most reliable protection. IEC 61508 specifies techniques that should be
used for each phase of the life-cycle.
Contents
Hazard and risk analysis
Safety integrity level
Probabilistic analysis
IEC 61508 certification
Industry/application specific variants
Automotive software
Rail software
Process industries
Nuclear power plants
Machinery
Testing software
See also
References
Further reading
Textbooks
External links
The standard advises that 'Either qualitative or quantitative hazard and risk analysis techniques may be used'
and offers guidance on a number of approaches. One of these, for the qualitative analysis of hazards, is a
framework based on 6 categories of likelihood of occurrence and 4 of consequence.
Consequence categories
Category Definition
Catastrophic Multiple loss of life
Critical Loss of a single life
Marginal Major injuries to one or more persons
Negligible Minor injuries at worst
Consequence
Likelihood Catastrophic Critical Marginal Negligible
Frequent I I I II
Probable I I II III
Occasional I II III III
Remote II III III IV
Improbable III III IV IV
Incredible IV IV IV IV
Where:
1. Systematic Capability (SC) which is a measure of design quality. Each device in the design has an SC
rating. The SIL of the safety function is limited to smallest SC rating of the devices used. Requirement for SC
are presented in a series of tables in Part 2 and Part 3. The requirements include appropriate quality control,
management processes, validation and verification techniques, failure analysis etc. so that one can reasonably
justify that the final system attains the required SIL.
2. Architecture Constraints which are minimum levels of safety redundancy presented via two alternative
methods - Route 1h and Route 2h.
Probabilistic analysis
The probability metric used in step 3 above depends on whether the functional component will be exposed to
high or low demand:
high demand is defined as more than once per year and low demand is defined as less than or
equal to once per year (IEC-61508-4).
For functions that operate continuously (continuous mode) or functions that operate frequently
(high demand mode), SIL specifies an allowable frequency of dangerous failure.
For functions that operate intermittently (low demand mode), SIL specifies an allowable
probability that the function will fail to respond on demand.
Note the difference between function and system. The system implementing the function might be in operation
frequently (like an ECU for deploying an air-bag), but the function (like air-bag deployment) might be in
demand intermittently.
3 ≥ 10−4 to < 10−3 ≥ 10−8 to < 10−7 (1 dangerous failure in 1140 years)
Automotive software
ISO 26262 is an adaptation of IEC 61508 for Automotive Electric/Electronic Systems. It is being widely
adopted by the major car manufacturers.
Before the launch of ISO 26262, the development of software for safety related automotive systems was
predominantly covered by the Motor Industry Software Reliability Association guidelines.[1] The MISRA
project was conceived to develop guidelines for the creation of embedded software in road vehicle electronic
systems. A set of guidelines for the development of vehicle based software was published in November
1994.[2] This document provided the first automotive industry interpretation of the principles of the, then
emerging, IEC 61508 standard.
Today MISRA is most widely known for its guidelines on how to use the C and C++ languages. MISRA C
has gone on to become the de facto standard for embedded C programming in the majority of safety-related
industries, and is also used to improve software quality even where safety is not the main consideration.
MISRA has also developed guidelines for the use of model based development.
Rail software
IEC 62279 provides a specific interpretation of IEC 61508 for railway applications. It is intended to cover the
development of software for railway control and protection including communications, signaling and
processing systems.
Process industries
The process industry sector includes many types of manufacturing processes, such as refineries, petrochemical,
chemical, pharmaceutical, pulp and paper, and power. IEC 61511 is a technical standard which sets out
practices in the engineering of systems that ensure the safety of an industrial process through the use of
instrumentation.
IEC 61513 provides requirements and recommendations for the instrumentation and control for systems
important to safety of nuclear power plants. It indicates the general requirements for systems that contain
conventional hardwired equipment, computer-based equipment or a combination of both types of equipment.
Machinery
IEC 62061 is the machinery-specific implementation of IEC 61508. It provides requirements that are
applicable to the system level design of all types of machinery safety-related electrical control systems and also
for the design of non-complex subsystems or devices.
Testing software
Software written in accordance with IEC 61508 may need to be unit tested, depending up on the SIL level it
needs to achieve. The main requirement in Unit Testing is to ensure that the software is fully tested at the
function level and that all possible branches and paths are taken through the software. In some higher SIL level
applications, the software code coverage requirement is much tougher and an MC/DC code coverage criterion
is used rather than simple branch coverage. To obtain the MC/DC (modified condition/decision coverage)
coverage information, one will need a Unit Testing tool, sometimes referred to as a Software Module Testing
tool.
See also
Functional safety
Safety standards
FMEDA
Spurious trip level
Time-triggered system (A software architecture used to achieve IEC 61508 compliance)
References
1. Control Systems Safety Evaluation and Reliability. ISA. 2010. ISBN 978-1-934394-80-9.
2. Development Guidelines for Vehicle Based Software. MISRA. 1994. ISBN 0952415607.
Further reading
Textbooks
W. Goble, "Control Systems Safety Evaluation and Reliability" (3rd Edition ISBN 978-1-
934394-80-9, Hardcover, 458 pages).
I. van Beurden, W. Goble, "Safety Instrumented System Design-Techniques and Design
Verification" (1st Edition ISBN 978-1-945541-43-8, 430 pages).
M.J.M. Houtermans, "SIL and Functional Safety in a Nutshell" (Risknowlogy Best Practices, 1st
Edition, eBook in PDF, ePub, and iBook format, 40 Pages) SIL and Functional Safety in a
Nutshell - eBook introducing SIL and Functional Safety
M. Medoff, R. Faller, "Functional Safety - An IEC 61508 SIL 3 Compliant Development
Process" (3rd Edition, ISBN 978-1-934977-08-8 Hardcover, 371 pages, www.exida.com)
C. O'Brien, L. Stewart, L. Bredemeyer, "Final Elements in Safety Instrumented Systems - IEC
61511 Compliant Systems and IEC 61508 Compliant Products" (1st Edition, 2018, ISBN 978-
1-934977-18-7, Hardcover, 305 pages, www.exida.com)
Münch, Jürgen; Armbrust, Ove; Soto, Martín; Kowalczyk, Martin. “Software Process Definition
and Management“, Springer, 2012.
M.Punch, "Functional Safety for the Mining Industry – An Integrated Approach Using
AS(IEC)61508, AS(IEC) 62061 and AS4024.1." (1st Edition, ISBN 978-0-9807660-0-4, in A4
paperback, 150 pages).
D.Smith, K Simpson, "Safety Critical Systems Handbook: A Straightforward Guide to
Functional Safety, IEC 61508 (2010 Edition) And Related Standards, Including Process IEC
61511 and Machinery IEC 62061 and ISO 13849" (3rd Edition ISBN 978-0-08-096781-3,
Hardcover, 288 Pages).
External links
IEC 61508-1:2010 Functional safety of electrical/electronic/programmable electronic safety-
related systems- Parts 1 (https://webstore.iec.ch/preview/info_iec61508-1%7Bed2.0%7Db.pdf)
"IEC 61508" (http://www.iec.ch/search/?q=61508) at International Electrotechnical Commission
IEC Functional Safety zone (http://www.iec.ch/functionalsafety)
61508 Association (http://www.61508.org/) A cross-industry group of organizations with an
interest in achieving a dependable and cost-effective method for demonstrating compliance
with IEC 61508 and related standards.
Text is available under the Creative Commons Attribution-ShareAlike License; additional terms may apply. By using this
site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia
Foundation, Inc., a non-profit organization.