![ABB Triguard SC300E Скачать руководство пользователя страница 26](http://html.mh-extra.com/html/abb/triguard-sc300e/triguard-sc300e_safety-manual_2874026.webp)
Issue 5 - September 2006
Page 26 of 65
If this feature is employed then system designers must ensure that the system’s I/O
configuration and application logic are structured such that both operators and plant are not
presented with a dangerous condition upon restoration of system power after a power outage.
3.6.5 Application
Logic
Verification
A peer to peer application logic code walk through should be completed prior to Test.
3.6.6 Application
Logic
Validation
Prior to the Acceptance Test the application logics should be fully functionally tested on the
target system.
Particular care should be taken in the testing of the application logic if the system auto-restart
feature is used.
3.6.7 Start-up
Overrides
If the application requires certain safety permits to be overridden during the process start-up, the
override logic must automatically time-out within the process safety time related to the start-up
sequences.
Start-up overrides may only be enabled via keyswitch or password operator protection.
3.6.8 System
Acceptance
Test
The System Acceptance Test should at minimum cover mechanical inspection, electrical testing
(isolation and earth bonding / continuity) and functional testing.
The System Acceptance Test harness should be configured to as closely as possible simulate
the site functional conditions.
All Triguard SC300E input and output modules must have their 3-2-0 configuration checked and
logged prior to the start of the Factory Acceptance Test (FAT).
In addition to a 100% Cause and Effect Validation (full Functional Test), the FAT should include
as much random testing as is practical as well as test to confirm both fault tolerance and
maintainability.
Particular care should be taken in the testing of the application logic if the system auto-restart
feature is used.
3.6.9 Application
Software
Documentation
The TriBuild Software Development Tools provide version control, and it is mandatory that the
application software developer documents the networks thoroughly and provides tractability of
changes by adding the appropriate change description.
Typical well-documented networks are given in Appendix 1.
3.6.10 Application Logic Driven External Triplicated Watchdog Timer
The application logic used to drive the external triplicated watchdog timer is used to confirm that
the application logic is operating correctly and the outputs are being written to. The triplicated
watchdog timer should never be required to operate; however, it is an effective measure against
unknown systematic faults, which cannot otherwise be detected.
The outputs from the external watchdog can be used to shutdown the field power supplies or
disconnect the field power to the final elements on the systematic failure of 2 or more
processors. The configuration of the output of the external watchdog will depend on the end