Issue 5 - September 2006
Page 12 of 65
3
Configuration Application Design
3.1 Introduction
This section provides the guidelines that must be followed if certification to DIN VDE 0801 AK 6 /
IEC 61508 SIL 3 is to be maintained. The guideline deals only with the Triguard SC300E Safety
PLC and its implementation into a Safety System. It does not remove the responsibility of the
Systems Designer to ensure that all other analysis and design processes have been completed
correctly.
This section covers the design and configuration of a Safety System based on the Triguard
SC300E Product up to and including the factory acceptance stage.
3.2 Assumptions
The following assumptions have been made in this section.
The system design/integration company is operating accredited quality procedures for the
design and manufacture of Software based Safety Systems to the standard of ISO 9001, TOPS
or equivalent or higher standard and has received training on Triguard SC300E system
integration.
That all earlier life cycle parts of the design phase have been completed correctly including
Hazops and Safety Loop Systems Integrity Level (Safety Classification) Requirements
That the specified plant input and output configuration fully meets the required Safety
Classification (Safety Integrity Level) Selections (eg for Safety Classification AK6 (Safety
Integrity Level 3) Loops at least 2 independent final element paths are established).
That the Cause and Effect, Fault Schedule, Function Block Diagrams or other primary design
information is correct.
That the process safety times have been defined.
That the process safety time constraint has been defined.
3.3 Safety Related Inputs and Outputs
The Safety Loops, Cause and Effect Charts or other design data will define which loops are to
be considered as Safety Loops. All inputs and outputs associated with Safety Loops must
follow the design guidelines laid out in this section.
All Modules must be configured for 320 fail safe operation.
All output modules associated with Safety Loops must be configured with adjacent hot repair
partner slots. The hot repair partners for output modules
must not
be fitted during normal
operation.
Output hot repair (HR) partners can be left installed if using RTTS 8.30-009 (or later versions)
and TriBuild 1.44 (or later versions). This combination supports an auto hot repair feature. The
system will swap the control duty of one HR partnership every 1 to 255 hours, set using a
TriBuild low level system parameter.