
12
Rockwell Automation Publication 1756-RM001I-EN-P - May 2012
Chapter 1
SIL Policy
Programming and Debugging Tool (PADT)
For support in creation of programs, the PADT (Programming and Debugging
Tool) is required. The PADT for ControlLogix is RSLogix 5000, per
IEC 61131-3, and this Safety Reference Manual.
For more information about programming a system by using pre-developed
subroutines or Add-On Instructions, see these publications:
•
ControlLogix SIL 2 System Configuration Using RSLogix 5000
Subroutines, publication
•
ControlLogix SIL 2 System Configuration Using RSLogix 5000
Subroutines, publication
About the ControlLogix System
The ControlLogix system is a modular programmable automation system with
the ability to pre-configure outputs and other responses to fault conditions. As
such, a system can be designed to meet requirements for ‘hold last state’ in the
event of a fault so that the system can be used in up to, and including, SIL 2-level
Gas and Fire and other applications that require that output signals to actuators
remain ON. By understanding the behavior of the ControlLogix system for an
emergency shutdown application, you can incorporate appropriate system design
measures to meet other application requirements. These measures relate to the
control of outputs and actuators which must remain ON to be in a safe state.
Other requirements for SIL 2 (inputs from sensors, software used, and so on)
must also be met.
Gas and Fire Considerations
Listed below are the measures and modifications related to the use of the
ControlLogix system in Gas and Fire applications.
•
The use of a manual override is necessary to make sure the operator can
maintain the desired control in the event of a controller failure. This is
similar in concept to the function of the external relay or redundant
outputs required to make sure a de-energized state is achieved for an ESD
system should a failure occur (for example, a shorted output driver) that
would prevent this from normally occurring. The system knows it has a
failure, but the failure state requires an independent means to maintain
control and either remove power or provide an alternate path to maintain
power to the end actuator.
•
If the application cannot tolerate an output that can fail shorted
(energized), then an external means such as a relay or other output must be
wired in series to remove power when the fail shorted condition occurs.
See
.
Summary of Contents for 1756-L6 Series
Page 24: ...24 Rockwell Automation Publication 1756 RM001I EN P May 2012 Chapter 1 SIL Policy Notes ...
Page 76: ...76 Rockwell Automation Publication 1756 RM001I EN P May 2012 Chapter 6 FLEX I O Modules Notes ...
Page 126: ...126 Rockwell Automation Publication 1756 RM001I EN P May 2012 Appendix D Checklists Notes ...
Page 133: ...Allen Bradley Motors ...