Standards and certifications
96
Mobile Panel 40/50 User's manual V1.80
Safety integrity level - SIL
(gemäß IEC 61508-2)
Ausgangspunkt für die
Risikoabschätzung des
sicherheitsbezogenen
Teils der Steuerung
B, 1 bis 4
Bevorzugte Kategorien
Mögliche Kategorien, die zusätzliche Maßnahmen erfordern
Maßnahmen, die in Bezug auf das zutreffende Risiko überdimensioniert sein können
Sicherheitskategorien für sicherheitsbezogene Teile von Steuerungen
Sicherheitskategorie
(gemäß EN 954-1)
Figure 65: Risk graph per
EN
954-1, annex B
The
safety
category to be used is determined by starting at the specified starting point and taking the parameters
S, F and P into consideration.
Parameter S ... Severity of injury
S1
Slight (normally reversible injury).
S2
Severe (usually irreversible) injury.
Parameter F ... Frequency and/or exposure to hazard
F1
Seldom to slightly more frequent and/or short exposure duration.
F2
Frequent to continuous and/or long exposure duration.
Parameter P ... Possibility of preventing danger
P1
Possible under specific conditions.
P2
Scarcely possible.
Table 50: Parameters S, F and P lead you to the
safety
category to be used
5.4.5 Selecting the performance level and category per
EN
ISO
13849-1
The
machinery directive
dictates that a defect in the logic of the
control
loop – or disturbance or damage to the
control
loop itself – is not permitted to result in a dangerous situation. This general approach is standardized in
EN
ISO
13849-1 "
Safety
-related parts of
control
systems", which defines performance levels (PL a to e) for
safety
-
related
control
systems. The PL depends on the category, the MTTF
d
value and the DC of the corresponding
safety
circuit. The CCF examination must also be performed.
As in the earlier
EN
954-1 standard, the category describes the structure of the
safety
functions. What is new is
the performance level (PL), which describes the
safety
function's probability of
failure
and ability to detect faults.
The PL is selected by the
machine
manufacturer according to the actual potential for hazardous situations deter-
mined by the danger and risk assessment. At a minimum, PL d is normally required for dangers that
can
result
in irreversible injury or death.
The category specified with the PL provides information about the following:
•
Whether the system is designed as a 1-channel system, in which case a fault could lead to a loss of the
safety
function but component
availability
is high (category 1)
•
Whether the system is designed as a 1-channel system, in which case a fault could lead to a loss of the
safety
function but the fault is detected by the system and indicated in one form or another (category 2)
•
Whether the system is designed as a 2-channel system and a fault will not lead to a loss of the
safety
function (category 3)
•
Whether the system is designed as a 2-channel system and an accumulation of faults will not lead to a
loss of the
safety
function (category 4)