Rockwell Automation Publication 1756-RM093J-EN-P - April 2018
45
Characteristics of Safety Tags, the Safety Task, and Safety Programs
Chapter 5
Accessing Safety-related Systems
HMI- related functions consist of two primary activities: reading and writing
data.
Reading Parameters in Safety-related Systems
Reading data is unrestricted because reading doesn’t affect the behavior of the
safety system. However, the number, frequency, and size of the data being read
can impact controller availability. To avoid safety-related nuisance trips, use good
communication practices to limit the impact of communication processing on
the controller. Do not set read rates to the fastest rate possible.
Changing Parameters in SIL-rated Systems
A parameter change in a safety-related loop via an external (that is, outside the
safety loop) device (for example, an HMI) is allowed only with the following
restrictions:
•
Only authorized, specially-trained personnel (operators) can change the
parameters in safety-related systems via HMIs.
•
The operator who makes changes in a safety-related system via an HMI is
responsible for the effect of those changes on the safety loop.
•
You must clearly document variables that are to be changed.
•
You must use a clear, comprehensive, and explicit operator procedure to
make safety-related changes via an HMI.
•
Changes can only be accepted in a safety-related system if the following
sequence of events occurs:
a. The new variable must be sent twice to two different tags; that is, both
values must not be written to with one command.
b. Safety-related code, executing in the controller, must check both tags
for equivalency and make sure they are within range (boundary checks).
c. Both new variables must be read back and displayed on the HMI
device.
d. Trained operators must visually check that both variables are the same
and are the correct value.
e. Trained operators must manually acknowledge that the values are
correct on the HMI screen that sends a command to the safety logic,
which allows the new values to be used in the safety function.
In every case, the operator must confirm the validity of the change before
they are accepted and applied in the safety loop.
•
Test all changes as part of the safety validation procedure.
Содержание 1756-L61S ControlLogix 5561S
Страница 10: ...10 Rockwell Automation Publication 1756 RM093J EN P April 2018 Preface Notes...
Страница 64: ...64 Rockwell Automation Publication 1756 RM093J EN P April 2018 Chapter 6 Safety Application Development Notes...
Страница 70: ...70 Rockwell Automation Publication 1756 RM093J EN P April 2018 Chapter 7 Monitor Status and Handle Faults Notes...
Страница 114: ...114 Rockwell Automation Publication 1756 RM093J EN P April 2018 Index Notes...
Страница 115: ......