systems engineering//functional safety//IEC 61508

IEC 61508 is the international standard for the functional safety of electrical, electronic and programmable electronic safety-related systems, and the generic parent from which most sector standards are derived; it is used directly for industrial equipment with no sector standard of its own, and indirectly through its children, such as IEC 61511 for the process industry, ISO 26262 for road vehicles and EN 50128 for railway software. Its question is how much a safety function can be trusted, and its answer is a **safety integrity level**, SIL 1 to 4, each a band of tolerable failure probability.


IEC 61508 is the international standard for the functional safety of electrical, electronic and programmable electronic safety-related systems, and the generic parent from which most sector standards are derived; it is used directly for industrial equipment with no sector standard of its own, and indirectly through its children, such as IEC 61511 for the process industry, ISO 26262 for road vehicles and EN 50128 for railway software. Its question is how much a safety function can be trusted, and its answer is a safety integrity level, SIL 1 to 4, each a band of tolerable failure probability.

For a function used rarely (an emergency shutdown that acts a few times a year, the low-demand mode), the measure is the average probability of failing when demanded: SIL 1 allows between one in ten and one in a hundred, and each level above divides it by ten, so SIL 4 allows between one in ten thousand and one in a hundred thousand. For a function in continuous use (a speed limiter always active) the measure is a dangerous failure rate per hour, from about one in a hundred thousand hours at SIL 1 to one in a hundred million at SIL 4. Most industrial safety functions sit at SIL 1 to 3; SIL 4 is rare and usually avoided by redesigning the process.

The standard's backbone is the safety lifecycle: hazard and risk analysis, allocation of safety requirements to functions, design, verification, installation, validation, operation, modification and decommissioning, each with documented outputs. It treats the two kinds of failure separately. Random hardware failures are bounded by numbers (failure rates, diagnostic coverage, redundancy architecture); systematic failures, in software and design, cannot be counted, so they are bounded by techniques that become mandatory as the SIL rises.

The SIL a function needs comes from hazard analysis: the risk without the function compared with the risk the plant owner accepts, the gap being what the function must close. A function that must reduce the risk by a factor between a thousand and ten thousand is SIL 3.

Hardware architecture is scored by how failures are detected and tolerated: the fraction of dangerous failures diagnostics catch and the number of faults the channel survives. Redundant channels only count if they do not share a cause (common-mode failure), which is why diversity of hardware or software is valued at the higher levels.

Software at higher SILs requires defined languages and coding rules, static analysis, structural test coverage and independent assessment, the same family of demands that DO-178C makes in aviation.

In a plant the standard is met through a safety instrumented system, designed to the process-sector child, IEC 61511.

It is the generic member of functional safety, and the one to read first to understand the others.