Trust Safety Man2
Trust Safety Man2
Engineering Safe
Systems
Introduction Trusted ICS
Structure product is designed and certified for use
Fundamentals in safety-related applications
Generics as with other safety-related bespoke
Specifics systems, requires additional measures to
ensure the system as a whole is
appropriate for its safety-related
application
Safety Manual covers these
additional measures from initial
Summary requirements through to
More Info. decommissioning
Introduction
Summary
More Info.
Safety Management
Summary
More Info.
Safety Management
S tandby
E ducated
A ctive
S tandby
E ducated
A ctive
S tandby
E ducated
A ctive
S tandby
E ducated
A ctive
S tandby
E ducated
A ctive
S tandby
E ducated
1 2 1 2 1 2 1 2 1 2 1 2
SmartSlot
3 4 3 4 3 4 3 4 3 4 3 4
Sensors / Actuators
5 6 5 6 5 6 5 6 5 6 5 6
7 8 7 8 7 8 7 8 7 8 7 8
9 10 9 10 9 10 9 10 9 10 9 10
11 12 11 12 11 12 11 12 11 12 11 12
13 14 13 14 13 14 13 14 13 14 13 14
Configuration
17 18 17 18 17 18 17 18 17 18 17 18
19 20 19 20 19 20 19 20 19 20 19 20
21 22 21 22 21 22 21 22 21 22 21 22
23 24 23 24 23 24 23 24 23 24 23 24
25 26 25 26 25 26 25 26 25 26 25 26
27 28 27 28 27 28 27 28 27 28 27 28
29 30 29 30 29 30 29 30
Programming
29 30 29 30
31 32 31 32 31 32 31 32 31 32 31 32
33 34 33 34 33 34 33 34 33 34 33 34
35 36 35 36 35 36 35 36 35 36 35 36
37 38 37 38 37 38 37 38 37 38 37 38
39 40 39 40 39 40 39 40 39 40 39 40
“Common Cause”
Majority fault:
Summary Logic ‘0’
More Info. State ‘0x07’
Value -2048
Architectures (1)
Architectures (2)
TI + 2x scan time << PSTE then OK?
Trusted ICS Safety Manual Training Page 12 of 24
Introduction Energise to Action
Structure Mitigation,
Fundamentals Activation is hazard, or
Generics AK1 to 4 (≤SIL2)
Specifics Additional Measures
Architectures
Redundant, independent power sources
Sensors / Actuators
Power source monitoring
Configuration
Programming
Line monitoring
“Common Cause”
Summary
More Info.
Architectures (3)
Summary
More Info.
Architectures (4)
Programming
“Common Cause”
Summary
More Info.
Configuration (1)
Configuration
Shutdown Section
Energise to action
Programming
“Common Cause”
Flags Section
Line monitoring
Summary
More Info.
Configuration (2)
Configuration (3)
Configuration (4)
Peer Communications
Trusted ICS Safety Manual Training Page 18 of 24
Introduction Toolset Configuration
Structure Access protection
Language Selection
Fundamentals
Function block
Generics Subset
Specifics Additional functions, languages, commands
Architectures
Not ‘C’
Not SFC
Sensors / Actuators
Configuration
Programming
“Common Cause”
Summary
More Info.
Programming (1)
Configuration
Communications Interaction
Programming
Overrides
“Common Cause” Adjustment within safe limits
Summary
More Info.
Programming (2)
Sensors / Actuators
On-Line Modification
Configuration Logic change only
Programming Simulate
“Common Cause” Use validators
Summary
More Info.
Programming (3)
Sensors / Actuators
Configuration
Programming
“Common Cause”
Summary
More Info.
Further Information