Each function uses sensors to detect the condition, a logic solver to decide the action, and final elements to affect the process.
An SIS is designed from hazards and required risk reduction. It requires sufficient independence from the basic process control system (BPCS) so control-system failure or a common cause does not defeat the safety function. Integrated designs may share infrastructure, but each safety function must meet its required safety integrity.
Key points
Start from hazardsDefine the hazardous event, safe state, initiating causes, required action, response time, demand assumptions, and independence needed from other protection layers.
Manage the safety lifecycleSpecify, design, verify, validate, operate, proof-test, maintain, modify, and retire each safety function under controlled competence and documentation.
Protect independence and integrityAssess common-cause failures, shared networks and services, engineering access, logic changes, bypasses, diagnostics, and dependencies on the basic control system.
Coordinate cybersecurity changesAuthorize and test patches, configuration changes, remote access, monitoring, and incident actions so they do not delay a trip, cause a spurious trip, or hide degraded protection.
Important limitationAn SIS is not ordinary process control and must not be treated as a general cybersecurity backstop. Availability of the production process cannot override the required safe action, while a careless security control can itself create a dangerous failure or unnecessary shutdown.