IEC 61508 is an international standard developed by the International Electrotechnical Commission (IEC) to ensure the functional safety of systems that incorporate electrical, electronic, or programmable electronic (E/E/PE) devices. It provides a framework for designing, implementing, operating, and maintaining safety-related systems to reduce risks to a tolerable level. Have a look at our guide to IEC 61508 to navigate the standard with confidence. There’s a comprehensive FAQ section, too.

In safety-critical industries, system failures can have catastrophic consequences. This can include injuries, loss of life, or environmental harm. IEC 61508 plays a crucial role in mitigating these risks by providing a structured framework for the design, implementation, and maintenance of safety-related systems to ensure their functional safety.

السلامة الوظيفية allows systems to perform their intended safety functions reliably when required, reducing risks to an acceptable level. IEC 61508 serves as the foundation for numerous industry-specific standards, offering a consistent reference point for developing safety-related systems across various sectors.

Also, IEC 61508 carries significant legal implications, particularly in Europe, where it aligns with the General Product Safety Directive 2001/95/EC (GPSD). This directive mandates that manufacturers of safety-critical products adhere to ‘State-of-the-Art’ development principles. 

In the context of electronic safety-related systems, ‘State-of-the-Art’ refers to widely accepted best practices, which are now encapsulated in IEC 61508:2010 and its derived industry-specific standards. Failure to comply with these established practices could leave companies unable to use the “State-of-the-Art” defense in legal disputes concerning product fitness for purpose.

a man in a woodworking factory

إلى ماذا تشير E/E/PE و E/E/PES؟

المعيار الدولي IEC 61508:2010 يحمل العنوان الرسمي "السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة."

نظرًا لطوله، غالبًا ما يُختصر هذا العنوان إلى "السلامة الوظيفية للأنظمة المتعلقة بالسلامة E/E/PE" أو حتى أكثر من ذلك إلى "السلامة الوظيفية للأنظمة E/E/PES."

أهداف IEC 61508

تشمل الأهداف الرئيسية للمعيار ما يلي:

  • تعزيز الابتكار التكنولوجي: دعم التقدم في الأنظمة الكهربائية والإلكترونية والإلكترونية القابلة للبرمجة (E/E/PE) ضمن إطار سلامة متين.
  • تقديم نهج منهجي ومرن: تقديم منهجية سليمة تقنيًا وقائمة على الأنظمة وقابلة للتكيف مع التطورات المستقبلية.
  • Adopt a risk-based methodology: Utilise a risk-based approach to define the required performance of safety-related systems, ensuring specified risks are managed effectively. These risks can be quantified or addressed in semi-quantitative terms.
  • Support industry and sector standards: Serve as a generic standard applicable across industries while also assisting in the development of sector-specific standards (e.g., machinery, chemical processes) or product-specific standards (e.g., power drive systems).
  • بناء الثقة في الأنظمة القائمة على الحاسوب: توفير الأدوات والإرشادات للمستخدمين والجهات التنظيمية للثقة في تقنيات السلامة القائمة على الحاسوب.
  • تبسيط سلاسل التوريد والتواصل: وضع مبادئ مشتركة من أجل:
  • تعزيز الكفاءة في سلاسل التوريد لمكونات مثل أجهزة الاستشعار ووحدات التحكم.
  • تحسين الوضوح في التواصل ومتطلبات المواصفات.
  • تعزيز تطوير التقنيات والتدابير القابلة للتطبيق في جميع القطاعات.
  • تمكين تقييم المطابقة: تسهيل إنشاء خدمات تقييم المطابقة حيثما دعت الحاجة، مع ضمان الامتثال لمعايير السلامة.

كم عدد الأجزاء في IEC 61508؟ وما الأجزاء التي تتعلق بالبرمجيات؟

تنقسم معيار IEC 61508 إلى سبعة أجزاء رئيسية:

الجزء 1: المتطلبات العامة: تحدد المتطلبات الشاملة لتحقيق السلامة الوظيفية، بما في ذلك دورة حياة السلامة، ومنهجيات تقييم المخاطر، وبروتوكولات إدارة السلامة.

الجزء 2: Requirements for E/E/PE Safety-related Systems: Focuses on specific requirements related to the hardware components of electrical, electronic, and programmable electronic (E/E/PE) safety-related systems.

الجزء 3: Software Requirements: Details the requirements for the software components used in safety-related systems, covering the complete software development lifecycle, from initial specification to final validation.

الجزء 4: التعريفات والاختصارات: يوفّر مسردًا شاملًا للمصطلحات والاختصارات المستخدمة في معيار IEC 61508.

الجزء 5: أمثلة على طرق تحديد مستويات سلامة الأمان (SIL): يقدم أمثلة عملية وطرقاً متنوعة لتحديد مستوى SIL المناسب لوظائف السلامة المحددة.

الجزء 6: إرشادات تطبيق الجزأين 2 و3: تقدّم توجيهاً حول كيفية تنفيذ المتطلبات الواردة في الجزء 2 (الأجهزة) والجزء 3 (البرمجيات) بفعالية.

الجزء 7: نظرة عامة على التقنيات والتدابير: تقدّم نظرة شاملة على مختلف التقنيات والتدابير التي يمكن استخدامها لتحقيق السلامة الوظيفية والحفاظ عليها.

Parts 1 through 3 contain the standard’s core requirements and are therefore normative. Part 4 provides essential definitions. The remaining sections, Parts 5 through 7, offer supportive guidelines and illustrative examples for development, making them informative in nature.

While all sections are relevant to some degree, software developers will primarily focus on IEC 61508-3:2010, titled “Functional safety of electrical/electronic/programmable electronic safety-related systems – Part 3: Software requirements.” This part details the specific requirements for software used in safety-related systems. However, it’s crucial to remember that a comprehensive understanding of IEC 61508 necessitates familiarity with all seven parts of the standard.

المفاهيم الأساسية في السلامة الوظيفية

لفهم IEC 61508 بفعالية، من الضروري استيعاب عدة مفاهيم ومصطلحات أساسية:

  • السلامة الوظيفية: This aspect of overall system safety relies on the system’s ability to operate correctly in response to inputs. It involves preventing dangerous failures and, if a failure occurs, ensuring the system responds in a manner that minimises risk.
  • مستوى السلامة Integrity (SIL): SIL measures the reliability and performance of a safety function. It’s quantified by the probability of failure on demand (PFD) or the frequency of dangerous failures per hour. There are four SILs, ranging from SIL 1 (the lowest level of safety integrity) to SIL 4 (the highest).
  • دورة حياة السلامة: This structured process encompasses all stages of a safety-related system’s life, from initial concept to decommissioning. It guarantees that safety is considered and managed throughout the entire system’s lifespan.

ما هي مستويات السلامة SIL وفقًا لمعيار IEC 61508 (مستويات السلامة الوظيفية)؟

​For embedded software developers working with IEC 61508:2010, Part 3, “Software Requirements,” is of primary importance. However, the effort needed to fulfill each objective within this standard is directly related to the Safety Integrity Level (SIL) of the safety functions implemented by the system.

Determining the appropriate SIL is detailed in Part 5 of the standard, titled “Examples of methods for the determination of safety integrity levels.” This section outlines various quantitative methods for SIL derivation.

Annex A of the standard addresses the concept of “Necessary Risk Reduction.” The tolerable risk level is contingent on factors such as the severity of potential injuries, the number of individuals exposed to the hazard, and the frequency and duration of that exposure. 

IEC 61508 defines Safety Integrity as “the probability of a safety-related system satisfactorily performing the required safety functions under all the stated conditions within a stated period of time.”

Therefore, the SIL assigned to each safety function depends on the probability of failure, which can be assessed using different approaches. A higher probability of failure necessitates a higher SIL (ranging from SIL1 to SIL4), resulting in more stringent and demanding software development practices to achieve an acceptable level of risk.

  • SIL 1: أدنى مستوى من السلامة الوظيفية، مع احتمالية أعلى للفشل.
  • تتطلب مستويات SIL الأعلى متطلبات أكثر صرامة، مما يجعل الامتثال أكثر استهلاكًا للموارد.
  • SIL 3: مستوى عالٍ من السلامة الوظيفية، مع احتمال فشل أقل بكثير من SIL 2.
  • SIL 4: أعلى مستوى من السلامة الوظيفية، مع أدنى احتمال للفشل.
IEC 61508: A comprehensive guide to functional safety with FAQ 
Table: Frequency vs. Severity of Consequence

نهج دورة حياة السلامة

The figure illustrates a simplified representation of the Overall Safety Lifecycle, which is one of three key safety lifecycles: the Overall Safety Lifecycle, the E/E/PE System Safety Lifecycle, and the Software Safety Lifecycle. 

IEC 61508: A comprehensive guide to functional safety with FAQ 
Diagram illustrating a simplified representation of the Overall Safety Lifecycle

Each of these life cycles consists of multiple phases, with each phase outlining specific requirements that must be met. These requirements are closely tied to technical specifications, ensuring that safety considerations are systematically addressed throughout the development process.

IEC 61508 serves as the foundation for numerous sector-specific functional safety standards. These adapted standards address the unique needs of various industries and are often more appropriate for those contexts, for example, ISO 26262, designed for functional safety in motor vehicles, or IEC 62304, tailored for medical device software.

أدناه يمكنك الاطلاع على كيفية ارتباط IEC 61508 بالمعايير الأخرى:

  • IEC 61508 و IEC 61511: IEC 61511, “Functional safety – Safety instrumented systems for the process industry sector,” exemplifies an industry-specific standard derived from IEC 61508. While their lifecycle processes are conceptually similar, IEC 61511 utilises terminology and examples directly relevant to the process industries. The software development processes promoted by both standards are essentially identical, with IEC 61511 referencing IEC 61508 for software-specific guidance.
  • IEC 61508 و ISO 26262: ISO 26262, focused on the automotive sector, is also derived from IEC 61508. ISO 26262 can be more prescriptive in certain areas; for instance, it defines a specific Hazard and Risk Analysis (HARA) technique. Variations between the standards reflect the specific conditions of the automotive industry, such as higher production volumes, which make approaches like “proven in use” more applicable. It also uses “ASILs” (Automotive Safety Integrity Levels), which are qualitative measurements of risk derived differently from the SILs in IEC 61508.
  • IEC 61508 وISO 13849 وIEC 62061: ISO 13849 (“Safety of machinery — Safety-related parts of control systems”) and EN IEC 62061 (“Safety of machinery, functional safety of safety-related electrical, electronic and programmable electronic control systems”) are harmonised to the EU’s Machinery Directive. While a proposed standard (IEC/ISO 17305) to merge them was cancelled, ISO 13849-1 suggests that Safety-Related Parts of Control Systems (SRP/CS) designed to an appropriate level in ISO 13849, IEC 62061, or IEC 61508 can be combined.

متغيرات خاصة بكل قطاع

تعتمد الأنظمة الحرجة من حيث السلامة في مختلف الصناعات على معايير متخصصة مستمدة من إطار IEC 61508 الأساسي لضمان السلامة الوظيفية.

قطاع السيارات

ISO 26262، وهو تكييف للمعيار IEC 61508، هو المعيار الأساسي للسلامة الوظيفية في الأنظمة الكهربائية والإلكترونية للسيارات. وقد اعتمدته شركات تصنيع السيارات الكبرى على نطاق واسع. 

Prior to ISO 26262, the Motor Industry Software Reliability Association (MISRA) guidelines were the main reference for developing safety-related automotive software. MISRA, established to guide the creation of embedded software for road vehicle electronic systems, published its first set of guidelines in 1994. This document was the automotive industry’s initial interpretation of IEC 61508 principles. 

Today, MISRA is best known for its C and C++ programming guidelines, which have become the de facto standard for embedded programming in safety-critical industries and are also used to enhance software quality in non-safety applications.

Rail

IEC 62279 provides a specialised interpretation of IEC 61508 for railway applications, focusing on software development for control and protection systems, including communication and signaling. Its equivalent CENELEC standards are EN 50128 and EN 50657.

الصناعات العملية

IEC 61511 addresses safety practices in the process industry, covering sectors such as refineries, petrochemical plants, pharmaceuticals, pulp and paper production, and power generation. It provides guidance on engineering systems that ensure process safety through instrumentation.

محطات الطاقة

IEC 61513 specifies requirements for instrumentation and control systems critical to the safety of nuclear power plants. It encompasses both conventional hardwired and computer-based equipment or their combinations. ISO also provides an overview of nuclear power plant-specific safety norms.

الآلات

IEC 62061 is the machinery-specific implementation of IEC 61508. It outlines requirements for designing safety-related electrical control systems at the system level and for non-complex subsystems or devices.

industry 4.0 building automation

التحديات والاعتبارات

تعقيد دورة حياة السلامة

IEC 61508 defines a comprehensive safety lifecycle with 16 phases, covering analysis, realisation, and operation. Managing activities across all these phases requires significant resources and coordination.

يُعد ضمان الاتساق وإمكانية التتبع طوال دورة الحياة أمرًا معقدًا، لا سيما بالنسبة للأنظمة الكبيرة ذات الترابطات المتعددة.

تحديد مستويات السلامة التكاملية (SILs)

يتضمن تعيين مستويات SIL المناسبة تحليلاً صارماً للمخاطر والأخطار، وهو أمر قد يكون ذاتياً ويفتقر إلى منهجية موحدة منصوص عليها في المعيار.

• دلالات البيانات، على سبيل المثال، درجة حرارة الغرفة، درجة حرارة الغرفة المستهدفة، درجة حرارة الماء، إلخ.

معالجة الأعطال المنهجية والعشوائية

يتطلب المعيار تدابير لمنع الأخطاء المنهجية (مثل عيوب التصميم) والتخفيف من الأعطال العشوائية في الأجهزة. وهذا التركيز المزدوج يزيد من تعقيد جهود الامتثال.

يُعد تنفيذ التصاميم القادرة على تحمل الأخطاء وضمان أنماط الفشل المتوقعة أمراً صعباً من الناحية التقنية.

التحديات الخاصة بالبرمجيات

يجب أن يتبع تطوير البرمجيات بموجب IEC 61508 إرشادات صارمة، بما في ذلك معايير الترميز (مثل MISRA) وإجراءات اختبار دقيقة للقضاء على الأخطاء.

يُعد تحقيق التتبع ثنائي الاتجاه بين المتطلبات والتصميم والاختبار أمراً بالغ الأهمية، لكنه صعب التنفيذ دون أدوات متخصصة.

متطلبات التوثيق

The standard mandates extensive documentation for hazard analysis, risk assessment, design specifications, testing results, and maintenance plans. This documentation must be detailed enough to demonstrate compliance during audits.

العوامل البشرية

قد تؤدي الأخطاء البشرية أثناء التصميم أو التنفيذ أو الصيانة إلى تقويض جهود الامتثال. ويُعد تدريب الموظفين على مبادئ السلامة الوظيفية أمراً أساسياً لكنه يستهلك موارد كبيرة.

العوامل البيئية والخارجية

يجب مراعاة التأثيرات الخارجية مثل تقلبات درجات الحرارة أو التداخل الكهرومغناطيسي أو اضطرابات الطاقة في تصميم النظام واختباره.

تكاليف وجهود الشهادات

في حين أن الشهادة ليست إلزامية دائماً، فإن الحصول عليها يضيف مصداقية لكنه يتطلب استثماراً كبيراً في الوقت والأدوات والخبرة لتلبية المتطلبات الصارمة للمعيار.

تنفيذ IEC 61508

With extensive expertise in implementing IEC 61508 and related standards, our team has worked with a diverse range of enterprises, gaining invaluable insights into best practices and common pitfalls. 

إن فهمنا العميق لهذه المعايير يضمن قدرتنا على إرشادك خلال عملية التنفيذ بكفاءة، وتجنب الأخطاء المكلفة والتغلب على جميع التحديات. 

حدد موعدًا لاستشارة مجانية مع خبرائنا اليوم ودعنا نساعدك على دمج معايير IEC 61508 لتعزيز سلامة وموثوقية أنظمتك.

الأسئلة الشائعة: IEC 61508

To ensure safety, all significant hazards related to equipment and its control systems must be identified through a thorough hazard analysis, conducted by either the specifier or developer. This analysis determines whether functional safety measures are needed to provide adequate protection. If required, these measures must be integrated into the design in a structured and effective way. While functional safety plays a key role in risk mitigation, it is just one part of a broader safety approach—eliminating or reducing hazards through inherent safety in design remains the top priority.

يحدد معيار IEC 61508 أفضل الممارسات لتحقيق السلامة الوظيفية ضمن الأنظمة المعنية، مما يوفر إطارًا واضحًا لتصميم حلول موثوقة وآمنة.

IEC 61508 sets the framework for safety-related systems that rely on electrical, electronic, or programmable electronic (E/E/PE) components. It focuses on managing risks associated with the failure of safety functions these systems perform, rather than hazards linked to the hardware itself (e.g., electric shock). As a universally applicable standard, IEC 61508 can be used across industries, ensuring consistent safety measures regardless of the specific application.

Beyond preventing safety risks, the standard also addresses failures that could result in significant economic consequences. In such cases, IEC 61508 provides guidelines for implementing E/E/PE safety-related systems to protect both equipment and products. More detailed information on its scope is outlined in IEC 61508-1.

ينطبق المعيار على مجموعة واسعة من الأنظمة الحرجة للسلامة، بما في ذلك:

أنظمة الإيقاف الطارئ – إيقاف العمليات تلقائيًا في حال اكتشاف مخاطر.
أنظمة الحريق والغاز – الكشف عن تسربات الحريق أو الغاز والاستجابة لها.
التحكم في التوربينات – ضمان التشغيل الآمن وإيقاف التوربينات.
إدارة موقد الغاز – منع الأعطال وظروف الإشعال غير الآمنة.
مؤشرات سلامة الرافعات – مراقبة حالات التحميل الزائد ومنعها.
أنظمة سلامة الآلات – بما في ذلك أقفال الحماية وتداخل وظائف الإيقاف الطارئ.
الأجهزة الطبية – ضمان التشغيل الآمن والموثوق للمعدات الحيوية.
أنظمة التموضع الديناميكي – التحكم في حركة السفينة بالقرب من المنشآت البحرية.
إشارات السكك الحديدية – تعزيز سلامة القطارات من خلال أنظمة الإشارات الدقيقة.
محركات السرعة المتغيرة – الحد من السرعة لمنع الظروف الخطرة.
المراقبة والتحكم عن بُعد في العمليات – تمكين التشغيل الآمن والتدخل في الأنظمة الصناعية المتصلة بالشبكة.
أدوات دعم القرار – حيث قد تؤثر المخرجات غير الصحيحة على السلامة.

Safety functions in these applications are implemented using a variety of technologies, including electro-mechanical relays, non-programmable solid-state electronics, and programmable devices such as microprocessors and programmable logic controllers (PLCs).

Regardless of the technology, IEC 61508 applies to the entire safety-related system—from sensors to control logic, communication networks, and final actuators. The effectiveness of safety functions depends on viewing and designing the system, ensuring that every component works together to meet rigorous safety requirements.

IEC 61508 applies to any safety-related system that incorporates electrical, electronic, or programmable electronic (E/E/PE) devices. This broad applicability is intentional, as many of the standard’s requirements—particularly those outlined in IEC 61508-1—are technology-agnostic. In fact, the early stages of development, including concept definition, hazard and risk analysis, and overall safety requirement specification, often take place before the final implementation technology is even selected.

Even in later phases, such as system realisation, functional safety requirements extend beyond E/E/PE devices to include non-electronic components like mechanical systems. For instance, the hardware reliability and fault tolerance requirements specified in IEC 61508-2 apply to all components within a safety-related system, regardless of whether they rely on E/E/PE technology.

For low-complexity E/E/PE safety-related systems, full compliance with IEC 61508 is achievable without necessarily meeting every individual requirement, allowing for a flexible yet rigorous approach to ensuring system safety.

IEC 61508 focuses on achieving functional safety, which is defined as the absence of unacceptable risk of physical injury or harm to human health. This includes both direct impacts and indirect consequences resulting from damage to property or the environment (as outlined in IEC 61508-4, section 3.1). By explicitly addressing long-term health risks, including those arising from environmental or property damage, the standard ensures a comprehensive approach to safety.

Beyond physical safety, IEC 61508 also acknowledges the economic consequences of system failures. In cases where failure could result in significant financial losses, the standard can be applied to specify safety-related E/E/PE systems designed to protect equipment and products (IEC 61508-1, section 1.2f).

The necessary safety functions and their required performance levels are determined through hazard and risk analysis (as detailed in IEC 61508-5). A similar methodology can be applied to assess environmental or financial risks by substituting safety parameters with equivalent environmental or financial criteria. The core requirements of the standard remain relevant in these contexts, including the performance levels, which are quantified based on the probability or frequency of dangerous failures (refer to IEC 61508-1, Tables 2 & 3).

IEC 61508-1:2010
SC 65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 1: المتطلبات العامة

IEC 61508-2:2010
SC 65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 2: متطلبات الأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة

IEC 61508-3:2010
SC65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 3: متطلبات البرمجيات

IEC 61508-4:2010
SC65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 4: التعريفات والاختصارات

IEC 61508-5:2010
SC65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 5: أمثلة على طرق تحديد مستويات التكامل الآمن

IEC 61508-6:2010
SC65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 6: إرشادات حول تطبيق IEC 61508-2 وIEC 61508-3

IEC 61508-7:2010
SC65A
السلامة الوظيفية للأنظمة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة المتعلقة بالسلامة – الجزء 7: نظرة عامة على التقنيات والتدابير

IEC 61508 هو منشور مدفوع ويمكن شراؤه عبر الإنترنت من خلال IEC أو من هيئة المعايير الوطنية في بلدك.

ومع ذلك، تتوفر معاينة للمعيار، بما في ذلك جدول المحتويات والمقدمة والتمهيد والنطاق والمراجع المعيارية، للتنزيل المجاني على متجر IEC الإلكتروني.

Annex A of IEC 61508-5 introduces risk and safety integrity. In IEC 61508-1, clause 7 outlines the overall safety lifecycle requirements, which are visually represented in a lifecycle diagram (Figure 2) and summarised in Table 1. Additionally, key aspects such as verification, functional safety management, and functional safety assessment are detailed in clauses 7.18, 6, and 8, respectively.
للحصول على نظرة عامة أوسع، يقدّم الملحق A من IEC 61508-6 ملخصًا من ثماني صفحات لمتطلبات IEC 61508-2 وIEC 61508-3.

IEC 61508-2 presents the E/E/PE system safety lifecycle requirements in clause 7, with a corresponding lifecycle diagram in Figure 2 and a phase-by-phase summary in Table 1. Similarly, IEC 61508-3 outlines the software safety lifecycle requirements in clause 7, illustrated in Figure 3 and summarised in Table 1.

Each requirement within IEC 61508 should be interpreted in the context of its relevant lifecycle phase, considering the objectives set for that phase, clause, or subclause. These objectives are always stated before the corresponding requirements.

The adoption of IEC International Standards by any country, regardless of IEC membership, is entirely voluntary. However, IEC National Committees strive to incorporate these standards as transparently and extensively as possible into national and regional regulations. Any deviations from an IEC International Standard in a corresponding national or regional standard must be explicitly stated.

The standard provides a general framework for all safety lifecycle activities related to E/E/PE safety systems used to perform safety functions. This unified approach ensures the development of a rational and consistent technical policy for all E/E/PE safety systems, regardless of the application sector. One of the primary goals is to support the creation of international product and application sector standards based on the IEC 61508 series. As a result, the first four parts of the standard serve as foundational safety publications.

Parts 1, 2, 3, and 4 of IEC 61508 are recognised as IEC basic safety publications. This designation means that IEC Technical Committees must reference these parts when preparing their own international standards for products or application sectors that involve E/E/PE safety-related systems. As a result, IEC 61508 will have broad implications across all IEC application sectors.

Note 1: The basic safety publication status does not apply to low complexity E/E/PE safety-related systems or when the required safety integrity of the E/E/PE system is below the lowest safety integrity level specified in IEC 61508.

ملاحظة 2: لا تنطبق حالة منشور السلامة الأساسي لهذه المواصفة الدولية على المعدات الطبية المتوافقة مع سلسلة IEC 60601.

IEC 61513 ed1.0 (2001-03)
SC 45A
محطات الطاقة النووية – أجهزة القياس والتحكم للأنظمة المهمة للسلامة – المتطلبات العامة للأنظمة

IEC 61511-1 ed1.0 (2003-01)
SC 65A
السلامة الوظيفية – أنظمة السلامة المبنية على الأجهزة لقطاع الصناعات العملية – الجزء 1: الإطار والتعريفات ومتطلبات النظام والعتاد والبرمجيات

IEC 61511-2 إصدار 1.0 (2003-07)
SC 65A
السلامة الوظيفية – أنظمة السلامة المزوّدة بأجهزة القياس لقطاع الصناعات العملية – الجزء 2: إرشادات لتطبيق IEC 61511-1

IEC 61511-3 إصدار 1.0 (2003-03)
SC 65A
السلامة الوظيفية – أنظمة السلامة الموصولة لأغراض قطاع الصناعات التحويلية – الجزء 3: إرشادات لتحديد مستويات السلامة الوظيفية المطلوبة

IEC 62061 ed1.0 (2005-01)
TC 44
سلامة الآلات – السلامة الوظيفية لأنظمة التحكم الكهربائية والإلكترونية والبرمجية الإلكترونية المتعلقة بالسلامة

IEC 61800-5-2 ed.10 (2007-07)
SC 22G
أنظمة الإدارة الكهربائية للمحركات ذات السرعة القابلة للتعديل – الجزء 5-2: متطلبات السلامة – الوظيفية.

قد تكون معايير أخرى قيد التطوير أيضاً.

إلى جانب إنشاء المعايير الدولية لقطاع المنتجات والتطبيقات استناداً إلى IEC 61508، تشير العديد من المعايير إلى IEC 61508.

Due to the differing technical criteria in IEC 61508 and EN 954-1:1996 (which was also published as ISO 13849-1:1999 and later superseded by ISO 13849-1:2006), these two standards do not provide a sufficient technical basis to directly link safety performance measures based on the category requirements in EN 954-1:1996 with the safety integrity levels (SIL) requirements in IEC 61508.

However, from a practical perspective, an E/E/PE safety-related system that supports SIL1 safety functions (according to IEC 61508) generally meets the requirements for category 1 or category 2 systems (according to EN 954-1:1996). Similarly, SIL2 corresponds to category 3, and SIL3 corresponds to category 4.

It is crucial to note that there is no reverse correlation. For example, a category 3 E/E/PE safety-related system cannot be said to support SIL2 safety functions, as many of the IEC 61508 requirements have no equivalent in EN 954-1:1996.

لمزيد من التفاصيل، يُرجى الرجوع إلى IEC 62061.

Yes. A key objective of the standard is to facilitate the development of E/E/PE safety-related systems in sectors where product or application sector international standards are not yet available.

Many of the requirements in IEC 61508, especially those in IEC 61508-2 and IEC 61508-3, are not restated in product or application sector standards but are instead referenced. As a result, most users of product or application sector international standards will also need to consult IEC 61508.

لمزيد من المعلومات، يُرجى التواصل مع اللجنة الوطنية لديك.

يشير مصطلح "يجب" المستخدم في المتطلبات إلى أن المتطلب يجب اتباعه بصرامة إذا كان سيتم المطالبة بالامتثال للمعيار.

When “should” or “it is recommended that” is used, it suggests that, among various options, one is particularly suitable, without excluding others, or that a certain course of action is preferred but not obligatory.

تحدد العناصر المعيارية الأحكام التي يجب اتباعها للمطالبة بالامتثال للمعيار. وتتضمن هذه العناصر عادةً عبارات "يجب" و"ينبغي".

In IEC 61508, the normative elements are found in: Part 1 (excluding the annex), Part 2 (including annexes A, B, C, D, and E but excluding F), Part 3 (including annexes A and D but excluding annexes B, C, E, F, and G), and Part 4. Parts 5, 6, and 7 contain no normative requirements.

Informative elements provide supplementary information to assist in understanding or using the standard but are not mandatory for compliance. Informative elements cannot contain “shall.” Notes and footnotes are always considered informative.

في IEC 61508، تُعد الأجزاء التالية إعلامية: الملحق A من الجزء 1، والملحق F من الجزء 2، والملاحق B وC وE وF وG من الجزء 3، وجميع الملاحق في الأجزاء 5 و6 و7.

للاطلاع على البنية العامة لسلسلة IEC 61508، راجع IEC 61508-1، الشكل 1 (الصفحة 10 من المعاينة).

If the standard is applied to low complexity E/E/PE safety-related systems, and there is reliable field experience that provides sufficient confidence that the required safety integrity can be achieved, some of the requirements in the standard may be unnecessary. In such cases, exemption from compliance with these requirements is acceptable, provided it is justified (refer to section 4.2 of IEC 61508-1).

The standard does not specify which requirements this exemption applies to, leaving it to the user to determine and justify. However, it is important to note that the conditions under which this relaxation is permitted are very restrictive.

يقسم IEC 61508 مواصفات وظائف السلامة إلى مكونين:

متطلبات وظيفة السلامة (ما تقوم به الوظيفة)

متطلبات سلامة الأداء الوظيفي (احتمالية تنفيذ الوظيفة على نحو مُرضٍ)

لا يحدّد المعيار وظيفة السلامة الدقيقة أو متطلبات السلامة الوظيفية اللازمة لأي تطبيق معيّن.

يتوافق مستوى السلامة الوظيفية (SIL 1 أو 2 أو 3 أو 4) مع نطاق من قيم السلامة الوظيفية، والتي تُقاس لوظيفة سلامة محددة من حيث:

متوسط احتمالية الفشل الخطير عند الطلب (لوضع التشغيل منخفض الطلب)؛ أو

متوسط تكرار الفشل الخطير في الساعة (لوضع التشغيل عالي الطلب أو المستمر).

ملاحظة: لمزيد من المعلومات حول وضع التشغيل، راجع IEC 61508-4، البند الفرعي 3.5.16.

The safety integrity level allocated to a specified safety function within the E/E/PE safety-related system will determine the level of rigor required for compliance with the standard. Other factors will also influence this (see section 4.1 of IEC 61508-1).

تشير بعض أجزاء المعيار صراحةً إلى العلاقة بين المتطلبات ومستوى سلامة الأمان، مثل:

الجدول 5 من IEC 61508-1

الأقسام 7.4.2 والملاحق A و B من IEC 61508-2

الملحقان A و B من IEC 61508-3

على الرغم من أن الملاحق المعيارية الأربعة جميعها تقدم توصيات لتقنيات وتدابير محددة، إلا أنها تختلف في ما هو مطلوب للامتثال.

In subclause A.2 of IEC 61508-2, Table A.1 outlines the requirements for detecting faults or failures through techniques and measures to control hardware failures. Tables A.2 to A.15 in the same subclause support Table A.1 by recommending techniques and measures for diagnostic tests and specifying the maximum levels of diagnostic coverage that can be achieved. To comply with the standard, the requirements of Table A.1 must be fulfilled. However, Tables A.2 to A.15 offer just one set of possible ways to meet these requirements.

Subclause A.3 of IEC 61508-2, including Tables A.16 to A.18, recommends specific techniques and measures, but their use is not mandatory for compliance. If a highly recommended technique or measure for the safety integrity level is not used, the rationale for this decision must be documented. Additionally, any techniques or measures chosen from Tables A.16 to A.18 must be used to the extent necessary to achieve at least the level of effectiveness stated in the table. Table A.19 provides guidance on the meaning of “low” and “high” effectiveness for some of the techniques and measures.

Annex B of IEC 61508-2 provides recommendations similar to those in subclause A.3. When a technique or measure that is highly recommended for the safety integrity level is not used, or when a technique that is explicitly not recommended is used, the rationale must be detailed. It is also necessary to achieve the level of effectiveness stated in the table for any techniques or measures that are used. Table B.6 offers guidance on what constitutes low and high effectiveness for most techniques and measures.
في كل من الملحقين A وB من IEC 61508-2، يوفر تظليل الجداول إرشادات حول اختيار ودمج التقنيات والتدابير.

من المهم ملاحظة أن الملحق C من معيار IEC 61508-2 هو أيضًا معياري ويحتوي على متطلبات ضرورية للامتثال.

In Annexes A and B of IEC 61508-3, the standard requires that appropriate techniques and measures be selected based on the safety integrity level. While the annexes list specific techniques, other techniques may be used as long as they meet the relevant IEC 61508-3 requirements. Anyone claiming compliance with the standard must consider which techniques or measures are most appropriate for the specific challenges encountered during the development of each E/E/PE safety-related system. For guidance on justifying the selection of software techniques, refer to IEC 61508-3 Annex C (and supplementary information in IEC 61508-7 Annex F).

A key concern is the role of systematic factors in the failure of a safety function. These factors can arise in both hardware and software, and the effectiveness of measures used to meet the target failure measures for systematic safety integrity generally needs to be assessed qualitatively.

The tables in Annexes A and B of IEC 61508-3, which recommend software techniques, are not checklists for guaranteeing systematic safety integrity in software. Given the many factors that affect software systematic capability, it is not feasible to provide a one-size-fits-all approach for combining techniques and measures. This is why Annex C (and supplementary information in IEC 61508-7 Annex F) was developed, to:

توجيه اختيار التقنيات من الملحقين A وB لتحقيق القدرة المنهجية للبرمجيات.
تقديم مبرر لتبرير استخدام تقنيات غير مدرجة صراحةً في الملحقين A وB.
عند اختيار تقنيات البرمجيات، يجب أخذ عدة عوامل رئيسية في الاعتبار، بما في ذلك:
كفاءة المطورين وخبرتهم في التقنيات.
الإلمام بالتطبيق والتحديات المحتملة.
حجم التطبيق أو تعقيده.
توصيات قطاع الصناعة والممارسات الجيدة المعترف بها.
المعايير المنشورة الوطنية والدولية.

Annexes A and B recommend documenting the rationale for not following the guidance on highly recommended or not recommended techniques during safety planning, with the rationale being agreed upon with the assessor.

In both IEC 61508-2 and IEC 61508-3, the choice of techniques for each lifecycle phase must be documented (see clause 5 of IEC 61508-1). Additionally, some subclauses require justification for the selection of techniques and measures, even when all recommendations are followed. For example, see clauses 7.3.2.2 e) and 7.4.2.9 of IEC 61508-2, and 7.4.3.2 a) of IEC 61508-3.

Clause 6 of IEC 61508-1 outlines the requirements for organisations responsible for an E/E/PE safety-related system, or for one or more phases of the overall E/E/PE system or software safety lifecycle. Additionally, clause 5 of IEC 61508-1 specifies the documentation requirements. The key documentation requirement is that it must contain sufficient information for each completed phase of the E/E/PE system and software safety lifecycles to support effective performance in subsequent phases and verification activities (see clause 5 of IEC 61508-1).

Of relevance in this context is the “Safety Manual for Compliant Items” (see IEC 61508-2, Annex D). This manual serves to document all the necessary information for a compliant item, enabling its integration into a safety-related system or subsystem in compliance with the requirements of IEC 61508.

In summary, IEC 61508 establishes requirements to ensure that essential information is available to those responsible for achieving functional safety. Clause 5 of IEC 61508-1 sets out the general need for sufficient information, while the safety manual for compliant items specifies the information that must be provided for an item (e.g., a component) for which the supplier claims compliance with certain clauses of IEC 61508.

Table 1 of IEC 61508-1 specifies the information required for each phase of the overall safety lifecycle. Tables 1 of IEC 61508-2 and IEC 61508-3 provide equivalent information for the E/E/PE system safety and software safety lifecycles, respectively.

For example, part of the entry from Table 1 of IEC 61508-1 for the “Realisation” phase of E/E/PE safety-related systems is shown below. It demonstrates that a system supplier responsible for the realisation phase needs documentation containing the specification of the E/E/PES safety requirements. This specification outlines all the safety functions allocated to the E/E/PE safety-related system(s) along with the corresponding safety integrity requirements for each function.

No, a safety integrity level (SIL) is not directly assigned to individual subsystems, elements, or components. Instead, it applies to the safety function performed by the E/E/PE safety-related system.

IEC 61508 addresses all components of the E/E/PE safety-related system, including field equipment and specific project application logic. These subsystems, elements, and components, when combined to implement the safety function(s), must meet the safety integrity level (SIL) target of the relevant safety functions. Any design using subsystems and components that are claimed to be suitable for the required SIL target must be assessed to verify their suitability. Suppliers of products intended for use in E/E/PE safety-related systems must provide sufficient information to support a demonstration of compliance with IEC 61508. Additionally, they must comply with Annex D of IEC 61508-2, which outlines the requirements for the “Safety Manual for Compliant Items.”

As a supplier of items (such as components or elements) for which you are claiming compliance with specific clauses of IEC 61508, you are required to comply with IEC 61508-2, Annex D, “Safety Manual for Compliant Items.” The purpose of the safety manual is to document all the information needed to enable the integration of the compliant item into a safety-related system, subsystem, or element, in accordance with IEC 61508 requirements.

البُنود الفرعية التالية ذات صلة خاصة في هذا السياق:

IEC 61508-2/7.4.9.6: يجب على الموردين تقديم دليل سلامة لكل عنصر متوافق يوردونه ويدّعون توافقه، وفقاً للملحق D من IEC 61508-2.

IEC 61508-2/7.4.9.7: يجب على المورد توثيق مبرر لجميع المعلومات المقدمة في كل دليل سلامة للعناصر المتوافقة.

Note 1: It is crucial that the claimed safety performance of an element is supported by sufficient evidence. Unsupported claims do not contribute to establishing the correctness and integrity of the safety function that the element supports.

Note 2: There may be commercial or legal restrictions on the availability of evidence. These restrictions fall outside the scope of this standard. If such restrictions prevent the functional safety assessment from accessing the necessary evidence, the element cannot be considered suitable for use in E/E/PE safety-related systems.

No, the standard mandates that a functional safety assessment be conducted on all parts of the E/E/PE safety-related system throughout all phases of the lifecycle (see clause 8 of IEC 61508-1).

The required level of independence for the assessor varies depending on the safety integrity level (SIL). For SIL 1, the assessor may be an independent person within the same organisation, while for SIL 4, the assessor must be from an independent organisation. For SIL 2 and SIL 3, the level of independence is influenced by factors such as system complexity, design novelty, and the developers’ previous experience. Additionally, it is a specific requirement that the assessor be competent in the activities they are undertaking.

The required level of independence should be distinguished from the concept of third-party certification, which is not a requirement of IEC 61508. In some cases, companies may need to fulfill the requirement for independent persons or departments by engaging an external organisation. However, this does not mean that the external organisation must be a certification body. The external organisation should have the necessary competence and the appropriate level of independence to perform the task, but it may or may not be a certification body.

On the other hand, companies with internal organisations skilled in risk assessment and the application of safety-related systems, which are independent from and separate (in terms of management and resources) from those responsible for the main development, may be able to use their own resources to meet the requirements for an independent organisation (see note 2 of 8.2.12 of IEC 61508-1).

للاطلاع على تعريفات الشخص المستقل، والإدارة المستقلة، والمنظمة المستقلة، راجع الأقسام 3.8.10 و3.8.11 و3.8.12 من IEC 61508-4.

IEC 61508 mandates the consideration of human factors in identifying hazards and hazardous events (7.4.2.3 of IEC 61508-1) as well as in the design of the E/E/PE safety-related system (7.4.5.3 of IEC 61508-2). For E/E/PE safety-related protection systems, three key areas must be addressed:

الأفعال أو الأخطاء البشرية التي قد تفرض متطلباً على نظام الحماية المتعلق بالسلامة E/E/PE – يجب تحديدها وقياسها كمياً.
فشل بشري في الاستجابة بفعالية للإنذارات أو اتخاذ إجراءات من شأنها خلاف ذلك تقليل الطلب على نظام الحماية المتعلق بالسلامة الكهربائية/الإلكترونية/الإلكترونية القابلة للبرمجة.
الفشل البشري في اختبار وصيانة نظام الحماية المتعلق بالسلامة E/E/PE، مما قد يقلل من فعاليته ويزيد من احتمالية الفشل عند الطلب.

يحدد البند 7.5.2.4 من IEC 61508-1 المتطلبات اللازمة لعدم تصنيف نظام التحكم كنظام مرتبط بالسلامة. وباختصار، تشمل هذه المتطلبات:

السماح بمعدل فشل خطير لنظام التحكم أعلى من الحد الأقصى الذي يحدده المعيار لنظام مرتبط بالسلامة (أي أعلى من 10^-5 حالات فشل خطيرة في الساعة).

تقديم أدلة كافية على تحقيق معدل الفشل الخطير المسموح به (تتوفر تفاصيل إضافية في البند 7.5.2.4 من IEC 61508-1).

تحديد جميع أنماط الفشل الخطيرة القابلة للتنبؤ بشكل معقول في نظام التحكم.

It is important to note that the dangerous failure rate mentioned in these requirements refers to a specific dangerous failure mode of a function performed by the control system, which could, in this context, place a demand on a safety-related system.