In this episode of the Functional Safety Podcast:
The devil hides in the one-sentence clauses. Ed Marszal closes out IEC 61511 Section 11.2 with three deceptively brief requirements that open onto sprawling practical territory: why cybersecurity resilience demands coordinated BPCS and SIS protection, not SIS isolation; why the safety manual is where unscrupulous vendors bury their certification sins; and why “appropriate communications” still leaves engineers to prove SIL compliance. The episode moves from Ed’s blunt skepticism of ISA TR84.00.09 and the bloated IEC 62443 corpus, through war stories of gravity-dependent solenoid valves and impossible stack-overflow tests, to the plain reality that every SIS component—not just the certified logic solver—needs documented operational intelligence. For engineers who have treated safety manuals as box-checking afterthoughts, this is the episode that explains why reading them before purchase is a career-preserving habit.
Unscrupulous equipment vendors often bury critical safety information in a product’s safety manual to get their products certified. Therefore, it’s essential to read the manual thoroughly to uncover any potential hazards. Ed provides his thoughts on this topic in more detail while discussing clauses 11.2.12 to 11.2.14.
Tune in to the latest episode of the Kenexis Functional Safety Podcast, hosted by Ed Marszal, President and CEO of Kenexis. Now available on Spotify and Apple Podcasts, Ed offers his expert insights on the IEC 61511 standard.
With decades of experience in safety instrumented systems and as a Principal Engineer, Ed has a unique perspective to offer. He has been an active contributor to the ISA 84 committee since 1994, adding to his deep understanding of the field.
In this inaugural season, Ed delves into the IEC 61511 standard, unpacking the meaning behind each word and providing a thorough interpretation of its application. Through personal stories from his career and committee work, he offers valuable context and insights for professionals in the industry.
Full Episode Transcript
Introduction, Disclaimer, and Episode Overview
You must read a product safety manual because for unscrupulous equipment vendors, that is the place where you will find all of the bodies that needed to be buried for the certification process.
Welcome to the Kenexis Functional Safety Podcast. I’m your host, Ed Marszal, President and CEO of Kenexis. Kenexis is a technical safety consultancy that helps chemical process industry companies to analyze risk and design engineered safeguards like safety instrumented systems and fire and gas detection systems. Kenexis also provides the industry-leading suite of software tools, including our best-in-class Vertigo software for SIS safety lifecycle management.
In this first season of the podcast, we are going to focus on the IEC 61511 standard, doing a deep dive into the standard, including more depth of information on what the standard means and how to apply it, brought to life with personal war stories and behind-the-scenes discussions of the committee members as we develop the standard in ISA 84 and IEC SC 65.
Before we start, a little disclaimer. I will be providing my opinion on technical and engineering topics. This information is provided on a best-effort basis and is of a general nature. The information presented in this podcast might not be applicable to your specific application. It is the obligation of every engineer to thoroughly analyze any system that they are designing and not blindly rely on any general advice presented in this podcast.
All right. All right. We are going to be wrapping up Section 11.2 today. So 11.2, we’ve been in it for a while. It’s, again, one of my favorites because we’re in Clause 11, which is the SIS detailed design, if you will. And this is where, even though we have a performance-based standard where you pick a target and verify that you’ve achieved that target, there are actually a lot of cookbook-y prescriptive requirements that also need to be followed. And they are all in Clause 11.
And Clause 11.2 is titled General Requirements. So that makes this clause kind of a dumping ground for, you know, little dribs and drabs of things that didn’t kind of fit anywhere else, didn’t need a wider discussion. And as a result, you usually have one sentence hanging out there that ends up requiring, you know, an episode worth of discussion because it seems so innocuous. It seems so benign. But the tendrils go out in many different directions. So let’s get back into it. Last week, we spent an entire episode on Clause 11.2.11, which is Energize the Trip.
And in this episode, we’re going to knock through three clauses. That’s all that’s left. 11.2.12, 11.2.13, and 11.2.14 are the three clauses that are left that we’re going to be getting through today. And they are, shall we say, a little bit less involved than the Energize the Trip Clause. Okay, so let’s get to it.
Clause 11.2.12: Cybersecurity and SIS Risk Context
We are going to begin with Clause 11.2.12. 11.2.12 was added in the 2016 version of the Standard. And it has to do with a topic that was wildly popular at the time. And it’s still very, very popular, but it’s not getting the same amount of attention. A lot of practitioners have gotten bored with it. And that topic is cybersecurity.
Now, if you look at the clause, it’s, again, one sentence. And the note, there’s a note that is one sentence. And it’s going to refer back to Clause 11. I’m sorry, 11. It’s going to refer back to Clause 8.2.4, which is in the Hazard and Risk Analysis section, where we talked about the risk analysis that needs to be done with respect to cyber threats. So if you want to go back in time in the podcast, I discuss 8.2.4 at length. I’m not going to repeat that. I’m going to talk about the detailed design aspects related to cybersecurity.
And what you’re thinking is that there is a lot to the cybersecurity of a safety instrumented system, which is true. But at the same time, hacking into a safety instrumented system by itself really is not very spectacular. It’s not very dramatic. You’ll be able to shut down the plant. Okay. So it’s a nuisance. If you can hack into the SIS, it’s a nuisance.
But if you can hack into the basic process control system and hack into the safety instrumented system at the same time, now you can use the BPCS to take an action and you can compromise the safety instrumented system so that it doesn’t respond to the hazardous conditions that are created. So a good cyber attack is going to need to take down multiple systems at the same time in order to get to that dangerous outcome that the hackers are hoping for. Okay.
So let’s do this. 11.2.12 says, The design of the SIS shall be such that it provides the necessary resilience against the identified security risks. And then parenthetically refers to, it says, C8.2.4.
So in 8.2.4, this is where we try to determine what are the vulnerabilities, what are the threats that your safety instrumented system is vulnerable to that can be generated through a cyber attack. Now, as I’ve mentioned, a great way to determine what those threats are is through security PHA review.
And I highly recommend picking up a copy of that book from ISA. I know the author. I am the author. I also know the co-author because I am the author. Okay. So, but it is a really good process for going back through your process hazards analysis and identifying those consequence scenarios that can be generated via a cyber attack because everything lives in a computer that can speak an addressable protocol. That’s kind of a — in the book, we refer to those things as devices that are hackable.
So, a computer, some sort of microprocessor that’s on a network that can communicate can be threatened.
So, in Clause 8.2.4, we kind of identified the hackable scenarios. So, if a hacker were to be able to get control of the control system, and that means everything, every device that is hackable, what could they do? And sometimes it’s shocking how much they can do. Other times it’s shocking how little they can do. Because at the end of the day, something like an overpressure, generally it’s impossible for a hacker to overpressure a vessel because you have a relief valve that has its mode of operation is a spring.
And up until this point in time, I am unaware of any methodology that a cyber attack can use to override what a spring does. So, that’s kind of one of the starting points for what you focus on.
Clause 11.2.12: Cybersecurity Design Implementation
But now, all of that is in Clause 11. — I’m sorry. All of that is in Clause 8.2.4. It’s your risk analysis to determine what can go wrong. We’re in Clause 11 now. And in Clause 11, you will need to design your system. You’re going to need to design in the safeguarding measures. So, what do we mean by safeguarding measures that would be designed into your safety instrumented system?
Well, a lot of the security is going to come from firewalls. So, if you look into the language of the ISA standard — I’m going to go ahead and call it the ISA standard. It was ISA 99. As usual, ISA, the good old U.S., invents everything. And then IEC says, yoink, I will take that. And now the copyright is mine and you don’t own it anymore. So, it was ISA 99. It is now IEC 62443. And there’s also a technical report that was written by ISA. ISA TR84.00.09. Not a big fan of that. To be honest.
Because the cybersecurity standard contains all the techniques, tools, and protocols that you need to secure any industrial automation equipment. Any OT can be secured using the principles in 62443. There is nothing that you do different for a safety instrumented system than what you would do for the basic process control system when it comes to cybersecurity.
So, why did we need to have a technical report on how to do cybersecurity for safety instrumented systems? Well, somebody’s looking to lead a committee. I don’t know. Somebody basically wants to have their say who wants to override what’s in 62443. I don’t know. Don’t get me started on it. If you’re looking at guidance on cybersecurity, always go to IEC 62443. All like 10,000 pages of it. It is absolutely ridiculous how big that standard is.
I even hesitate to call it a standard because so much of it you can’t, you know, it really can’t even be considered to be normative because it’s like, well, you might want to do this. If this is happening. You might want to do that if this is happening. But I digress.
If you, you know, and what I would really, really, really, you know what? It would be very interesting to take all of the thousands and thousands of pages of IEC 62443 and say, go into your favorite large language model and say, take all of this information and condense it down to 50 pages of the essential non-repetitive requirements. Ooh, that would be sweet. Now, if we had 50 pages of non-repetitive essential requirements, everybody would be following it. Everybody would be following it. But instead, we got thousands of pages that have done more to confuse industry than actually help it.
But, you know, in the standards committee process, I have talked to you over and over about the standards committee process, what happens behind the scenes. And, you know, there’s a lot of politic and there’s a lot of self-promotion. There’s a lot of promotion of products. And, you know, sometimes we don’t always get the best product. But, yeah, that large language model thing, I might want to actually play around with that. That could be very interesting. Now, don’t put it into ChatGPT. Don’t put it into Gemini. Don’t put it into Grok.
Those tools are kind of notorious for stealing intellectual property. If you’re going to do something like this, make sure that the IP does not get out on the Internet. It does not get out into the wild, does not become the public domain. It is really, really easy for you to run large language models on your desktop. It’s not out of the realm of possibility. Go ask an AI how to run AI locally on your laptop, and it will gladly explain to you how to do it. Anyway, I’m digressing a little bit.
So, basically, we’ve got a nondescript, muddled up, motherhood and apple pie statement. The design of the SIS shall provide necessary resilience against the identified security risk. Necessary resilience. Wow, that seems completely arbitrary. What is necessary? Well, then again, tolerable risk is also kind of arbitrary if you look at it that way. So, that’s something to put in the back of your mind as you’re doing this. But how can I tell you how to implement this practically?
Well, I will tell you that in just a second, but why don’t I first start by telling you what the note to this clause is. The note to the clause states, guidance related to SIS security is provided in ISA TR84.00.09. You know, that technical report that I just gave a resounding meh to. And IEC 62443-2-1-2010. So, all that the note does is refer you to other places, which is actually a good thing because this standard doesn’t and shouldn’t contain details of how to do cybersecurity because it’s not a safety requirement.
It’s something that’s applicable to all of your instrumentation control, all of your OT. And it should be done consistently for everything and not done a special way for the safety instrument system. Okay, so that’s the clause.
What do I recommend that you actually do? So, what is Ed’s guidance for how to actually implement this clause? Well, the guidance is go to your cybersecurity team and make sure that they’re securing your safety instrumented system. Now, there are a whole lot of things to consider. And I don’t want to do a training class on cybersecurity, number one, because I don’t generally, I don’t care for the topic, to be honest. But also, there’s a lot to it. And I am not, I have not versed myself deeply in this. But ultimately, there are different fundamental requirements of cybersecurity.
Things like access control is one of the fundamental aspects. Data security. Response time. There are fundamental, I believe there are seven. Go look at the 615, or I’m sorry, the 62443 standard for that stuff. And for all of those requirements, you need to have a corporate policy for what you’re going to do. So, in terms of data security or access control, you know, someone plugging their iPhone into your operator station is an excellent pathway to inject the virus onto your operator station and thus your OT network.
So, you need to have policies and procedures to prevent that. There’s the administrative controls of training human beings what they’re not allowed to do. And then there are the physical controls of locking those ports out physically and then also in code getting those ports to be turned off or ignored. So, there are a lot of things that need to be done. And I just gave you the example of removable media. There’s also password control. You know, do you need two-factor authentication? Do you need a card, a physical card in addition?
And then, you know, everything that can be cyber controlled, a lot of times it can also be physically controlled.
So, the topic of security is way outside the scope of the 1511 standard. And all that the 1511 standard did is say, cybersecurity is an issue. Make sure it’s been dealt with. And if you don’t know how to deal with it, go to IEC 62443 and it will tell you how to deal with it. And if you can offload this work to somebody else, more power to you. All right. So, that’s cybersecurity clause 11 to 12.
Clause 11.2.13: Safety Manual Scope and Components
Let’s move on to the next clause. Which, again, one sentence. 11 to 13. One sentence. But, oh my goodness, is it packed full of stuff. And we are going to look at, literally, as we go through this, we’re going to read one word at a time. And discuss what that word means. Give you examples and so on. So, lots of good stuff packed into clause 11.2.13.
It says, let me go ahead and I’m going to begin by reading the whole thing. Then I’m going to break it down into its itty bitty tiny individual chunks. So, clause 11.2.13 states, A safety manual covering operation, maintenance, fault detection, and constraints associated with the SIS shall be available covering the intended configurations of the devices and the intended operating environment. Okay. So, that’s verbatim what the clause says. But, man, is it packed with a bunch of information.
Now, I’m going to start right in the middle of the sentence to disabuse you of some notions and maybe disappoint you, make you think about things that you haven’t done that you need to do now. So, Ed’s giving you a to-do list. All right. The first thing is, or the first set of words I want to look at is associated with the SIS. So, a safety manual is associated with the SIS.
Now, let me give you the most common interpretation, which is completely wrong. The most common interpretation is that when I said that the safety manual is associated with the SIS, that means it’s associated with a certified logic solver. And as long as I have the safety manual for my certified logic solver, I am good. Oh. Oh, no.
Safety manuals cover the wide gamut. So, when the standard says that the safety manual is associated with the SIS, it means not just the SIS logic solver, but everything in the SIS, every system, every subsystem, every component, every subcomponent, you need to have a safety manual. Oh, okay. So, all right, that’s fine. Or is it fine? Because, well, for my logic solver, I got the safety manual from the equipment vendor because I bought a fancy schmancy SIL certified logic solver. And, you know, I bought a pressure transmitter from vendor XYZ, and they also gave me a safety manual.
But the valve that I’m using doesn’t have a safety manual that was provided to me by the equipment vendor. I don’t, I only need the safety manual for stuff that’s been certified, and that manual comes from the vendor. Right? Right? Right? Please, Ed, tell me it’s right. I would love to, but I can’t.
Even if the vendor hasn’t certified the device and doesn’t have a safety manual, I’m not going to go all the way and say that you need to write a safety manual, but the information that the safety manual contains, you need to have that information in some way, shape, or form, whether it’s in your SRS general requirements, your SRS data sheets. That information is going to need to show up.
So, what did we learn from the middle of the clause? Safety manual applies to everything that the SIS is built out of, not just the logic solver. Furthermore, you need this information somewhere, maybe not in a separate document, but you need the information somewhere for every component, whether it’s certified or not.
So, all right, I will let you sulk a little bit and let that bad news sink in, and also kind of let you think about a strategy for what you’re going to do to implement this. Now, as you’re doing that, let me go and hit the different components of it. So, a safety manual covering is how the clause begins, and you’re going to get a bullet list of items that you need to have documentation about how to use, install, operate, what have you, the implementation of that device. So, let’s kind of put together a bullet list real quick. It says operation. One, operation. Two, maintenance.
Three, fault detection. Four, constraints. Those are the four things that are at the front of the sentence, but at the back of the sentence, you’re going to get items five and six, which are intended configurations and intended operating environment. So, that, those six items need to be known for every piece of equipment, every subcomponent of your, every safety instrumented function in your safety instrumented system. Let’s do this one more time. Six items you need to know about every component. Operation, maintenance, fault detection, constraints, configurations, and operating environment.
Intended configurations and intended operating environment. Okay. So, let’s keep digging by hitting each of these six requirements one at a time.
Safety Manual: Operation and Installation
Number one is operation.
Operation should be pretty straightforward. Some will argue, and you might be able to convince me of your argument, that it is so obvious how to operate it that it’s not worth writing down. So, if I have a pressure transmitter, how do you operate it? You use the signal that comes back into the control room. Not a whole lot to it. One thing that kind of could go in a bunch of different locations is installation. So, I kind of reserve installation for intended configurations. But how you install stuff is going to be very important. So, let me give you an example.
And, you know, I’ve got, you know, one of the, the advantages of being a seasoned expert and have done a lot of training classes, talked to a lot of people, been out in the field, in a lot of places all over the world, is that you hear stories about things that you would never consider would actually be possible. But, and yet they are. So, one of the war stories about installation has to do with solenoid valves.
So, solenoid valves, you know, again, real quick review. I’m sure I’ve already gone over this a million times. But, for a solenoid valve, same way as an electrical mechanical relay, you’re going to allow current to pass through a coil. The current passing through that coil is going to generate a magnet and the force of that magnet is going to move something mechanical. So, in a, an electromechanical relay, the magnetic field is going to move a set of contacts. It’s either going to open or close a set of contacts.
Well, in a solenoid valve, the electromagnetic field is going to move a spool piece. It’s most, most commonly called a spool piece.
I’m going to use interest, industry jargon. So, depending on the position of the spool, the fluid that’s passing through the solenoid valve will change directions depending on what the position of the spool is.
Now, in a well-designed solenoid valve that’s got a lot of magnetic force, the action of the magnetic force is going to move the spool into a position that is the normal operating condition of the plant in a de-energized a trip system harping back the last week. Um, and when it does that, it’s going to compress a spring. So, the whole time that the solenoid valves in operation in the normal state, that spring is compressed.
Now, when you remove power from the solenoid and you lose your magnetism, the spring should force that contact to the, uh, or the spring should force the spool to the safe state.
Now, I just said that during this process, that spring is compressed compressed the entire time. So, we’re going to be consuming a lot of energy holding that spring in the compressed position. And, while we need that to push the spool to the safe state when the energy is removed, well, you know, if I was a shyster equipment vendor and I wanted to build you something real cheap, well, I could put less copper wire, less windings on the coil generating less magnetism if I didn’t have to overcome the force of a spring. So, I’m going to cut back on the amount of wire I’m using.
That’s going to save me money. And, well, you know, if I don’t have a spring, I don’t have to pay for the spring. Okay, so, ooh, more money saved. Good deal. But, when I de-energize my coil, I’m going to need for the spool to move to the safe state. Well, you know, there is a force out there that’s always available free of charge. You might know it as gravity. So, instead of paying for the force provided by a compressed spring, let’s use that free force provided by gravity to move the spool to its safe state.
Alright, so now I got myself a low-priced solenoid valve, but with that solenoid valve, I have to be very careful and install that in the correct position that will cause gravity to allow that spool to move to the safe state. Don’t do that. Please don’t. Please, please don’t use a solenoid valve that relies on gravity
a safe state. That’s a horrible way save a buck, let me tell you.
But that’s an example of where the installation is very important. So, as you’re installing your equipment, you want to make sure that you’re following all the rules of its installation, which will be documented in the user manual and or the safety manual of the device you buy. The operation, even if it’s not a certified device that doesn’t have a safety manual, you should be able to find that type of information in just the plain old user manual of the device.
Safety Manual: Maintenance, Testing, and Vendor Obligations
All right, the next item up out of six, number two of six, is going to be maintenance. And that is, what are the maintenance activities? And let me really quickly separate maintenance and testing. So, maintenance is the actions that you take to repair minor degradation and return a device to as close as possible to its brand new good as new state.
So, an example of a maintenance activity on a valve might be that you might want to replace an O-ring because that O-ring has been smashed by the packing nut for years and it’s deformed and possibly it’s lost its plasticity because it’s been exposed to the process fluid and so on. So, a full list of instructions for things that you need to replace and, you know, kind of refreshing wearable components.
So, the archetype back in the day of maintenance was making sure that you grease your bearings on a certain time interval because the grease that you injected when the device was new has been contaminated with dirt, it’s been degraded due to use, etc.
Alright, so those are the maintenance activities that you need to perform, but part and parcel of the maintenance activities are test activities.
Now, let me give you an example in just a second here, but what’s important to understand and recognize at this point in time is that sometimes, especially if you buy a certified device, you will be required to perform maintenance activities that you don’t understand why you’re doing what you’re doing. For example, some of the early, early, early, early versions of safety transmitters had a clause in the user manual that said once per year you’re going
put your safety function in bypass. And you’re going to need to hook up a HART communicator to the transmitter and manually set the output to 0%, ramp it up to 100% and ramp it back down to 0%, then release the transmitter back to normal operation.
That was written in the safety manual. And a lot of times people didn’t know what that meant or why you would do that. I mean, that’s something that normal people don’t do this. Why are you asking me to do this? This doesn’t make any sense. I don’t understand why I’m being asked to do this. Well, it turns out that that process of manually going from 0% to 100% performed a diagnostic test that is not normally done or can’t be guaranteed to happen during normal operation.
So basically, you, the human being, through this manual test are doing a diagnostic test that will try to identify a failure in the transmitter device. They didn’t tell you this, but that’s exactly what happened.
So I am going to really stress that you focus on the maintenance aspects of your devices as you’re going through them. And I guess, you know, right here, I guess we’ll go ahead and throw another horror story of maintenance.
A lot of times, there are some certification bodies, you know, all of them have done questionable things in the past, but there are some certification bodies that let stuff slide a little bit more than other certification bodies. I’ll just leave it at that. And there are requirements that need to be done in IEC 61511. And if you’re the I’m sorry, IEC 61508, I’m talking about the equipment vendor standard now. So for the equipment vendor standard, you know, this is what the equipment vendors need to comply with to get their devices certified.
certified.
More on that coming up in clause 11.5. Let me tell you, there’s a lot more on that coming up in clause 11.5. But if there’s a requirement, it is not unacceptable for the equipment vendor when they’re getting certified to say, oh, how I meet that requirement is I wrote in my safety manual that the end user is required to do this action. And if the end user does this action like I told him to, then this requirement in IEC 61508 will be met. So please certify me.
And, you know, if you’re an end user, you’re like, no, no, they can’t really do that, can they? They most certainly can. And they do all the time, which is why it is incumbent upon you as an end user to always read the safety manual before you buy the device, not after you’ve already installed it.
Because a lot of times if you read what’s in the safety manual, you won’t buy the device. The safety manual ultimately is where the bodies are buried. It’s the graveyard of poorly met requirements by the equipment vendor. And I say poorly met because their equipment out of the box doesn’t meet the standard. Instead, they’ve dumped the work on you, the end user.
All right, so let me give you an example. There is a PLC vendor that shall remain nameless. You know who you are. If you’re listening to the podcast, you know who you are. And I will say that this equipment vendor has gone a long way in righting the wrongs of this particular safety manual, which was released, I’ll just suffice it to say, in the mid-2000s. So it was, you know, about 20 years ago. So they’ve done a lot to atone for their sins since that point in time.
But in the safety manual, the vendor said, on an annual basis, you, the end user need to perform a manual test to verify that all of the diagnostic routines that my PLC is capable of function properly.
Now, on a well-designed SIL 3 certified true safety PLC, all these routines are built into the system, performed automatically without you having to know it. But, you know, a basically a safety configured off-the-shelf PLC can get that Chiquita banana sticker from the certification bodies if they are sneaky enough in how they write their safety manual.
So I go in, and you know, the equipment vendors hate it when I show up. They’re like, oh God, Ed, you’re killing me. So I bust out their safety manual in front of them, and I’m like, okay, you said that the end users need to test all these diagnostic routines on a regular basis. Yes, annually. I’m like, okay, can you show me what the diagnostic routines are? And they’re like, oh, absolutely. Go to this appendix, and it’s going to give you a list of all the diagnostic routines.
And I go, okay, let’s go. So you go to that appendix, and I start with diagnostic routine number one. Diagnostic routine number one is stack overflow. So those of you that are kind of old school familiar with the guts of how computers work, you’ll know that there are registers that kind of sit in the CPU, and you’re going to move data from this register to that register. And there’s a stack of data, a stack of registers. Or you could be looking one register at a time.
But basically the intention is to, depending on your processor, either put 8 bits, or 16 bits, or 32 bits of information into that register. Well, if I tried to put 10 bits into a slot that can only contain 8 bits, I’m going to get a stack overflow. So that’s basically the computer telling me that you asked me to move something from thither to yon, from here to there, and the destination is not suitable, doesn’t match up with what you asked me to put into the destination. Now I have a stack overflow. overflow.
Okay, you know, if you’re the PLC’s firmware programmer, you understand what’s going on here, and you can kind of deal with this.
How dare you try to push this off on the end user? So I go to the equipment vendor, I’m like, look, how exactly can you write me a procedure for how the end user is capable of generating a stack overflow so that they can test this subroutine to make sure that it works. And of course, crickets. We have no idea how the end user would do that. So they required the end user to do something that they don’t know how to do, and to this day, I’m pretty sure is not physically possible for the end user to do.
This is something that you would need to inject stuff directly onto the circuit board to be able to test this kind of thing.
So it’s those types of activities that occur in the maintenance section of the safety manual that you need to just give a detailed read and understand what the vendor is asking you to do because this is where they’re going
get you. They’re going sell you something that you don’t want to buy because they hid the stuff in the safety manual, assuming nobody was going to read it.
Don’t be that guy. Okay, so that’s only item number two.
Safety Manual: Fault Detection and Device Constraints
Item number three is fault detection. So a lot of equipment has built in diagnostics. So there needs to be some sort of discussion of what are the internal diagnostics that are happening inside the device.
and when those internal diagnostics detect that a failure has occurred, what action is taken? Or what are the options that the user needs to select for the action that it’s taken. Another horror story. Every one of these requirements is going to have a horror story. So this horror story on fault detection comes from a lot of audits. So I, Kenexis, we do a lot of functional safety assessments, a lot of safety instrumented system audits. We’re very good and very efficient at it. Call Edward Naranjo, our director of sales, if you want us to do that for you.
But what I ask, so when I’m looking at not this requirement, but it’s going to be something that shows up in clause 10 about what you do when you diagnose a detected error, I will always ask, so for the equipment that you have, where have you documented what you do when the device fails? And they kind of start looking at each other, wondering how the heck to answer the question.
And then I say, okay, okay, well, let’s step back a little bit. So when a device fails, so if your pressure transmitter out in the field self-diagnoses that it’s in the failed state, what is it configured to do? Does it go off-scale high? Does it go off-scale low? Does it fail in place? Does it go to a known value like 3.7 milliamps? What does it do?
And the unfortunate answer that I get most of the time is not an answer but a question asking me, well, we use brand XYZ. Do you know what it does by default? That’s not the right answer. you should know this. So that kind of information about diagnostics, it might not be that important for you to know how it does the diagnostics, but how it responds when a diagnosed failure is present is very important for you to know.
It’s something important for you to document in your SRS, and it’s something that you may be able to configure yourself.
Okay, that’s item number three. Item number four is constraints associated with the SIS. So constraints, lots of things are constraints. So kind of on the installation side of the fence where I started, a constraint to that horrible solenoid valve is that it is installed so that the coil is at the top and the spool is at the bottom and it’s never installed at an angle. That is a constraint.
Constraints cover a lot of aspects of the design. So there are a list of things that you are allowed to do with your device and things that you are not allowed to do with your device. And that list of things that you are not allowed to do with your device that constrain the way that you are allowed to use it. And it might instead of being a list of things you’re not allowed to do it’s a list of these are the only ways that you’re allowed to use the device. That needs to be considered in your safety manual.
Okay moving on. Intended configurations and intended operating environment are the last two items in the safety manual clause.
So intended configurations configurations there might be a lot of different options for how to use a device how to install a device. So let me give you a perfect example of configurations. If you’re looking at a temperature transmitter the temperature transmitter might allow you to only use one type of thermocouple. it might allow you to use every type of thermocouple or a few different options. It might allow you to use a few different options of thermocouple or RTD.
The device might have a mode where you can connect two thermocouples into one transmitter and that way if one of the two thermocouples fails the device will switch over to the operating thermocouple to take its action.
So you’ll see that that temperature transmitter I just talked about had a whole bunch of different configurations that are possible. So the safety manual is going to tell you what are all of the different options that are possible under what circumstances would you want to use the different configurations.
And finally intended operating environment. If your device uses water you’re probably not going to be allowed to use it at below freezing temperatures. So you’re going to get constraints on the ambient environment that you are allowed to use the device in.
Temperature and this goes back to the very end of clause 10. What is the maximum and minimum temperature maximum and minimum humidity vibration all those aspects. You need to in clause 10 what we were doing is we were saying this is the environment that the device is going to be installed in make sure that it’s suitable. Here we’re looking at the device and the device is saying these are the environments for which I am suitable.
And at the end of the day you need to make sure that those two things match each other in order to get a good fit between the intended operating environments and the environment that you are going to install the device in. Now one item here and you might consider it to be constraints. You might consider it to be the operating environment that’s going to be the process service.
So sometimes there are going to be limitations on the process service so for a control valve actuator for instance you might have to install something called an extension bonnet to move physically move the actuator away from the process if the process is really hot. So in that case the actuator could say you know the process fluid of the material can’t be more than five or six hundred degrees fahrenheit whatever the number is and so on. So I will leave you to decide whether that is a constraint or that is an operating environment issue.
Anyway with all of that that’s again one clause 11.2.13. Good you know 20-30 minutes of discussion there on one clause. Because there is honestly there is a lot to that clause. There’s a lot to consider.
Clause 11.2.14: SIF Communication Techniques
All right. Finally we are going to look at clause 11.2.14. It is relatively brief because we’re almost at this for an hour so I’m going to need to let you go here soon. So in clause 11.2.14 the clause says and again it is one sentence with no notes. All communications used to implement a SIF shall be established using techniques appropriate for safety applications to meet the required SIL. Wow another hard to prove kind of subjective kind of ambiguous motherhood and apple pie statement. So there are a lot of communications inside a safety instrumented function.
And this is to implement the SIF.
So it could be the communication of the sensor to the logic solver. It could be from a remote IO rack to a CPU inside the logic solver. What we’re saying is that all the communication mechanisms that you’re going to use should be appropriate for the safety application. Okay so use of smoke signals generally going to be too slow to be effective for a safety application and kind of requires some human intervention. Although you know with machine learning that oh this is going to be fun.
I am going to have to try to train a camera with machine learning system to be able to interpret smoke signals. How fun does that sound oh okay all right
I’m digressing a little bit. Smoke signals something we’re generally not going to use. Two tin cans with a rope in between them. I think everyone as a child tried that out or at least people my age tried that out and we know that it really it doesn’t work it only works in cartoons. But you know copper wire is a great way to communicate between a transmitter and an SIS logic solver. It’s appropriate and it will meet the required SIL because there’s basically if you’re in de-energized to trip there are no dangerous failure modes of copper wire.
So yeah you need to what we’re going to find out in clause nine is you’re going to need to include the probability of failure of communications into your SIL verification calculations when you’re calculating that probability of failure on demand. So that number needs to be factored into whether or not you met your numerical SIL target in terms of PFD. Most of the time it’s ignored because if you’re just using copper wire there are no dangerous undetected failure modes in de-energize to trip. And for energized to trip you are going to have an unavailability if you drop your wire.
And that’s something that you might want to consider when you’re running your SIL COX but we’ll get to that when we get to clause 11.9 which is probably still going to be a few weeks away because next week we’re going to be talking about clause 11.3. We are certainly going to spend the entire session next time talking about clause 11.3 because there is that much to know about what the safety instrumented system does and what you do when you detect a dangerous failure.
Episode Sign-Off and Vertigo Software Advertisement
But that is all I have for this week. We will catch you next time. Now that you’ve heard some insights on technical safety functional safety and the IEC 61511 standard let me tell you a little bit more about how to easily and effectively implement the safety life cycle using the Kenexis integrated safety suite and our SIS safety life cycle management tool Vertigo Vertigo is a comprehensive tool set for performing assessment calculations documenting and maintaining the design of safety instrumented systems.
Analysis begins with importing or synchronizing a list of safety instrumented functions with their definitions and associated performance targets from our open PHA tool for HAZOP and LOPA documentation. Each safety function can then be analyzed by performing a SIL verification calculation complete with a collection of tools for optimizing designs and a database of thousands of potential instruments to define failure rates and diagnostic coverage capabilities.
After the SIL verification calculations are defined you can build an SRS by automatically generating a cause and effect diagram from the SIF definitions and other defined instruments. Each SIS instrument will include a customizable data sheet and general requirements that are applicable to the SIS as a whole and can be entered individually or even bulk imported from customizable libraries.
After the design phase you can even use Vertigo to track and document testing throughout the entire life of the facility Kenexis Vertigo is the most integrated easy to use enterprise tool for allowing the development of SIS design basis information more efficiently and effectively than any other software application.