systems engineering//functional safety//safety instrumented system

A safety instrumented system is a set of sensors, a logic solver and final elements (valves, breakers, motor contactors), wired and programmed separately from the plant's control system, that takes the process to a safe state when a physical limit is crossed, without asking the control software; it is used in refineries, chemical plants, boilers, pipelines and large machines as the layer of protection that still works when the control system is wrong, hacked or dead. A reactor whose pressure passes its trip point gets its feed valves closed and its vent opened by the SIS, whatever the distributed control system is doing.


A safety instrumented system is a set of sensors, a logic solver and final elements (valves, breakers, motor contactors), wired and programmed separately from the plant's control system, that takes the process to a safe state when a physical limit is crossed, without asking the control software; it is used in refineries, chemical plants, boilers, pipelines and large machines as the layer of protection that still works when the control system is wrong, hacked or dead. A reactor whose pressure passes its trip point gets its feed valves closed and its vent opened by the SIS, whatever the distributed control system is doing.

Each protective action is a safety instrumented function: one hazard, the sensors that detect it, the logic that decides, the element that acts, and a required integrity level from IEC 61508 (in the process industry through its child standard, IEC 61511). The function is designed to be boring. It reads a few independent transmitters, often voting two out of three so that one failed sensor neither trips the plant nor blinds the protection (majority voting), and drives a final element that fails to its safe position on loss of power or air.

Separation is the point. The control system optimizes production and changes often; the SIS has one job, changes rarely and shares nothing with it, so that no software update, network fault or intrusion in the control layer can disable the trip. It is the plant's version of keeping immediate safety local, and the last automatic layer before mechanical relief valves and the fence line.

Independence erodes after commissioning unless someone guards it. Shared transmitters, shared power or a shared engineering workstation on the same network reintroduce the common-mode failure the separation was meant to remove. The Triton malware found in 2017 targeted safety controllers specifically, which says how much value the last layer holds.

Trips that never happen must still work, so functions are proof-tested at intervals set by their required failure probability, and a valve that has not moved in years is exercised on schedule. A SIS that trips spuriously is also a safety problem: operators learn to bypass it.

It is distinct from an alarm, which asks a person to act (alarm management), and from the control system's own interlocks, which are convenient but not credited as independent protection.

In a cyber-physical system the SIS is the physical answer to the question of what happens when the software lies; it belongs to functional safety.