Professional Documents
Culture Documents
ID: tsc_ievc_doc_rams_pha
Version: V3.2
Status: Published
Author: Marianne Roussel
Date: 14/12/2022
Review: !1108
Authorized by: Alexandre Betis
Configuration Management
Commit: d9b20221
Document signature
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
CONTENTS
2 Introduction 4
2.1 Context . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
2.2 Purpose . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
2.3 Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
2.4 Applicable documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
2.5 Reference documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
2.6 Terms and definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
2.7 Artifacts definition . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
6 System Description 9
8 Conclusions 15
9 Annex A Causes 39
2 of 79 CONTENTS
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
CHAPTER
ONE
TWO
INTRODUCTION
2.1 Context
The IEVC project consists into developing an ETCS on-board inter-operable constituent (IC). This project also
covers tools developed around this IC.
The present document constitutes the main deliverable of CENELEC phase 3 (“Risk analysis and evaluation”). It
describes (i) how the risk assessment (risk analysis and risk evaluation) is undertaken during the earlier stages of
the iEVC project and (ii) how hazards are tracked, managed and closed through a specific hazard log.
2.2 Purpose
This documents describes the generation and the basic approach of a first accident list generation (high-level
hazards), its extension to a preliminary hazard analysis (PHA) and their inclusion into an agile structure of hazard
log (HazLog).
The present deliverable responds to the following objectives:
1. to identify hazards derived from possible system errors and faulty states in main operative conditions;
2. to assess the resulting risk level derived from identified hazards (risk qualifying);
3. to identify mitigation measures for each identified hazard;
4. to evaluate resulting safety level (residual risk) after implementation of the measures;
5. to identify Safety Related Application Conditions (operational procedures to be applied in normal or de-
graded conditions, respectively operational maintenance activities);
The safety assessment of the iEVC ETCS system consists in identification of hazards that can be induced by
failures of the system. The identified hazards are then analyzed, and the risks associated with these hazards
evaluated. Finally, all the information concerning safety management activities, hazards identification, decisions
undertaken and solutions adopted is recorded in a HazLog (Hazard Log) table.
2.3 Contents
4 of 79 2. Introduction
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
• Conclusions;
• Annex A Causes;
• Annex B Preliminary hazard analysis (PHA).
The terms and definitions used in the IEVC project are summarized and explained in the TSC glossary
[PHA-R4-Glossary].
Artifact
iEVC Preliminary Hazard Analysis [artifact]
THREE
3.1 Creation
3.2 Revision
This PHA represents the initial risk analysis performed for the iEVC system. This document is created at the
beginning of the program, and to be used as the basis for performing other safety-related activities.
New revisions of the PHA are triggered by the iEVC Safety Assurance Manager[role]. The document is to be
updated by the occurrence of:
• Addition of other hazards, possibly identified throughout the iEVC Program development process (and
documented as part of this hazard analysis and subsequent hazard analyses);
• Occurrence of relevant changes to the requirements, organization or process;
• Reception of comments from the Employer or independent body.
3.3 Filing
Storage and diffusion of this document is performed according to the rules described in [PHA-R1-PQP].
FOUR
In application of the iEVC ETCS Safety [PHA-R10-ETCSSP], the scope of this analysis is to identify all haz-
ards related to the iEVC Platform System during normal or degraded operation conditions, respectively during
preventive, corrective maintenance, or decommissioning activities.
All the risks identified during the PHA are registered in the hazard log [PHA-R3-hazlog].
All the other hazards, which are related to railway operations or to permanent railway infrastructure, trackside sys-
tems and routing/interlocking equipment are transferred respectively to the Railway Company or the Infrastructure
Manager.
Specific use and limitations of the system (with respect to geographical boundaries, interfaces, modes, etc.) are
detailed further in the system definition [PHA-R2-SD].
FIVE
The analysis was carried out under the following assumption: iEVC design currently do not include any battery
or accumulator. The system is fully powered by current delivered by train equipment
SIX
SYSTEM DESCRIPTION
The iEVC project consists into developing an ETCS on-board based on ERTMS interoperability constituents (IC)
including tools development around this IC. A description of the IEVC ETCS system is given in the IEVC System
Definition [PHA-R2-SD].
The iEVC ETCS system is a model-oriented on-board platform. Its main purpose is to execute on-board signalling
applications, as specified in [PHA-R6-Subset-026]. Applications are executed on-board by a Virtual Machine. The
applications loaded on this VM are grouped in a coherent package, that regroups the applications to run, but also
their configuration, as well as the sequence in which these applications must be run.
In order to support the execution of ETCS signalling applications, the iEVC platform interfaces this VM with
speed sensors, balises and radio communications.
The iEVC ETCS system is composed of the iEVC Platform and a Safe Integrated Development Environment
(SIDE) suite, for configuration and authorization purposes.
The iEVC Platform is mainly composed by three hardware boxes (Computer box, Sensor box and Telecom box),
driver machine interfaces (DMI) in the driver cabin and a crash protected memory (CPM), Eurobalise antenna and
odometry sensors as illustrated in Fig. 6.1. Each box regroups together components having similar life cycles and
managing similar peripherals. Additional computer box is optional.
6. System Description 9 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
10 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
CHAPTER
SEVEN
The initial identification of hazards is elementary for the further risk assessment of a system. The Preliminary
Hazard Analysis (PHA) is an inherent part of the risk assessment process.
For railway systems, the focus on hazard analysis is on the physical integrity of human and on the undisturbed
operation of the transportation system. By consequence, the hazard analysis shall systematically identify potential
impacts (i) on the physical integrity of persons and (ii) on the integrity of the infrastructure (i.e. rolling stock,
track, civil works, etc.) or the environment.
The complexity of the PHA depends on several boundary conditions (e.g. physical, operational), which are gen-
erally specified in the system definition for further assessment as well as the level of detail of the PHA.
An deductive, or top-down, approach is used to develop the PHA. Significant or top-level events (i.e. hazards) are
initially identified, followed by what might have caused them.
The main goal being to achieve the most complete as possible hazard identification.
The preliminary hazard analysis of the IEVC ETCS system consists of:
• Research the causes and circumstances of potential accidents related to the system and its interfaces (with
other subsystems and with the environment), whether they are generated directly by the IEVC ETCS system
or by events outside the IEVC ETCS system;
• Identify the subsystems or elements of the system that may cause these hazards;
• Define mitigation measures to be applied to eliminate or reduce the criticality of the identified potential
hazards and make this level of criticality acceptable (according to the definitions accepted for the project).
• This analysis is based on the development of a hazard tree, which details the potential accidents applicable
to the entire IEVC ETCS system.
Based on this hazard tree, hazard analysis tables identify the elements that can cause hazards, depending on the
circumstances in which they may occur.
PHA leads to the definition of mitigation measures to be taken to reduce the occurrence of potential hazards, or
even to reduce the severity of the consequences of a potential accident in order to make the risk acceptable.
Note: Only direct hazards created by external events are considered. Each of these events can also have indirect
repercussions following the degradation of equipment (example: lightning causes a failure of the system is con-
sidered but lightning causes a failure of signalling is not considered. . . ); this point is not taken into account in this
analysis.
At the Risk Analysis phase, this analysis reveals safety requirements for the various parties in charge of the
subsystems making up the transport system:
• On the structural subsystems: onboard safe computer, DMI, iBTM, Euroantenna, odometry system, TIU.
Hazard Log
* entrapment, lightning and injuries, diseases and dangerous occurrences could lead to multiple
injuries (for lightning, the locomotive is a Faraday cage, in consequence, the gravity is considered
as low)
This is resumed in the table Fig. 7.2;
– Initial Occurrence: initial occurrence estimated in a qualitative/semi- quantitative/quantitative way
according to Fig. 7.3;
– Initial Risk: initial risk estimation according to Fig. 7.4 and Fig. 7.5 ;
• Mitigation measures:
– Measure ID: Unique and sequential Identification number;
– Measure description: detailed description of the mitigation measure;
– Measure owner: responsible for the implementation of the measure ;
• Residual risk estimation:
The residual risk is to consider for all the mitigation of a scenario.
Two incompatible mitigations for the same cause should not happen.
– Final Gravity: gravity estimated after the implementation of the measure(s) according to
Fig. 7.1;
– Final Occurrence: occurrence estimated after the implementation of the measure(s) accord-
ing to Fig. 7.3;
– Final Risk: risk estimation after the implementation of the measure(s) according to Fig. 7.4
and Fig. 7.5;
• General remarks: additional information about pending actions, references and/or exported hazards.
The Hazard Log that has been opened and updated as the consequence of Preliminary Hazard Analysis, (see
[PHA-R3-hazlog]).
EIGHT
CONCLUSIONS
The preliminary hazard analysis has been performed for the iEVC ETCS system.
A hazard identification list has been proposed and all applicable potential hazards have been analyzed considering
personnel error, environmental conditions, design inadequacies, procedural deficiencies, system, subsystem or
component failure, or malfunction. Potential impacts (i) on the physical integrity of persons and (ii) on the
integrity of the infrastructure (i.e. rolling stock, track, civil works, etc.), as well as (iii) consequences for the
environment have been also considered.
The main inputs that have been used for the Hazard Analysis are:
• The iEVC system definition [PHA-R2-SD];
• The Lineas BR001 Contract User Requirement Specification [PHA-R5-LineasBR001];
• The detailed analysis of Safety Requirements for the Technical Interoperability of ETCS in Levels 1 & 2
(Subset 091) [PHA-R8-Subset-091];
• The detailed Safety Analysis of ETCS Application Levels 1 & 2 (Subset 088) [PHA-R7-Subset-088];
• The detailed Functional Safety Analysis of ETCS DMI for ETCS Auxiliary Hazard (Subset 118)
[PHA-R9-Subset-118].
The results of the analysis are recorded in the Hazard Log V1 [PHA-R3-hazlog] which contains the hazards iden-
tified during the PHA and the evaluated risk, proposed mitigations measures, derived requirements and SRACs.
Additional hazards may be identified in the future phases of the project.
From each hazard a requirement has been defined, this requirement aims to reduce the initial risk to acceptable
level where possible. Where appropriate a resulting mitigation measure and a formal property has been identified
and recorded. The requirement ID contains the indication of the component /function of the system to which is
applicable.
The residual risk corresponds to the level of risk after the application of identified safety requirements/ mitigation
measures; where the residual risk is different from negligible, further mitigation (technical and/or operation) is
needed.
The following tables resumes the mitigations identified during the PHA.
The structure of the table is:
• id: Unique Identification number
• argument: mitigation description
• allocated_to: ci to which the mitigation is allocated
• exported_to: (only for exported mitigation): responsible for the implementation of the measure
Recap Table
8. Conclusions 15 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
16 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
17 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
18 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
19 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
IEVC-PHA-MM-071 All cables (both exterior and in- iEVC ETCS kit[ci] PHA[ci]
terior) must be compliant with
at least HL2 fire behaviour re-
quirements of EN45545-2:2013
IEVC-PHA-MM-072 The secondary odometry sen- iEVC ETCS kit[ci] PHA[ci]
sor must be compliant with at
least HL2 fire behaviour re-
quirements of EN45545-2:2013
IEVC-PHA-MM-073 The antennas (GSM-R, 4G iEVC ETCS kit[ci] PHA[ci]
and/or GPS) must be com-
pliant with at least HL2 fire
behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-074 The iODO module must be iEVC ETCS kit[ci] PHA[ci]
compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-075 The iODO BITE module must iEVC ETCS kit[ci] PHA[ci]
be compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-076 The Computer box hardware iEVC ETCS kit[ci] PHA[ci]
must be compliant with at least
HL2 fire behaviour require-
ments of EN45545-2:2013
IEVC-PHA-MM-077 The Sensor box hardware must iEVC ETCS kit[ci] PHA[ci]
be compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-078 The Telecom box hardware iEVC ETCS kit[ci] PHA[ci]
must be compliant with at least
HL2 fire behaviour require-
ments of EN45545-2:2013
IEVC-PHA-MM-079 The Crash protected memory iEVC ETCS kit[ci] PHA[ci]
(CPM) must be compliant with
at least HL2 fire behaviour re-
quirements of EN45545-2:2013
IEVC-PHA-MM-080 The DMI hardware must be iEVC ETCS kit[ci] PHA[ci]
compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-082 Power supplies for iEVC system iEVC ETCS kit[ci] PHA[ci]
must be properly sized to match
overall loads from all subsys-
tems and components, in order
to optimize thermal dissipation
and reduce electrical stress at
line extremes (i.e. fuse break-
ing)
IEVC-PHA-MM-083 The systhem design shall speci- iEVC ETCS kit[ci] PHA[ci]
fiy a maximum consumption for
the iEVC system
20 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
21 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
22 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
23 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
24 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
IEVC-PHA-MM-129 The iEVC system must continue iEVC ETCS kit[ci] PHA[ci]
to display the speed of the train
on the DMI screen, even if the
iEVC is isolated
IEVC-PHA-MM-130 The iEVC DMI screen shall be iEVC ETCS kit[ci] PHA[ci]
compliant with requirements of
ERA_ERTMS_015660 v3.6.0
subset
IEVC-PHA-MM-131 All specific DMI functions that iEVC ETCS kit[ci] PHA[ci]
are not specified in the applica-
ble standards (i.e. dealing with
degraded modes) must be in-
cluded in the O&M manuals
IEVC-PHA-MM-132 Functional redundancy of the iEVC ETCS kit[ci] PHA[ci]
DMI screen, with one screen
presenting mandatory ETCS in-
formations and a second screen
presenting non-ETCS data or
applications chosen by the user
(typically the driver during nor-
mal operations)
IEVC-PHA-MM-133 Inhibition of the primary DMI iEVC ETCS kit[ci] PHA[ci]
screen in case of faults or fail-
ures and presentation of manda-
tory ETCS informations in the
second screen (degraded mode)
IEVC-PHA-MM-134 Speed determination from the iEVC ETCS kit[ci] PHA[ci]
wheel pulse generator primary
information must take into ac-
count a reasonable slip or slide
tolerance on the wheel rotation
IEVC-PHA-MM-135 The iEVC system shall be tested iEVC ETCS kit[ci] PHA[ci]
in different low track-adhesion
conditions before commission-
ing
IEVC-PHA-MM-136 DMI audio signals (i.e. mes- iEVC ETCS kit[ci] PHA[ci]
sages and alarms) must be com-
pliant with requirements of ISO
7731
IEVC-PHA-MM-137 The iEVC DMI screen shall iEVC ETCS kit[ci] PHA[ci]
be compliant with luminance,
brightness and viewing angle re-
quirements of EN 16186:2016
IEVC-PHA-MM-138 The DMI computer shall offer iEVC ETCS kit[ci] PHA[ci]
the possibility to adjust the lu-
minance and the brightness of
the screen using a softkey or a
plus/minus key
IEVC-PHA-MM-140 The system must provide a spe- iEVC ETCS kit[ci] PHA[ci]
cific iEVC interactive test mode
for the maintainer being able
to trigger tests inside the DMI
computer (i.e. through a Built-
In Test capacity)
25 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
IEVC-PHA-MM-141 The iEVC system shall require iEVC ETCS kit[ci] PHA[ci]
the driver to identify on DMI
display before being able to
configure train data
IEVC-PHA-MM-142 The iEVC system shall require iEVC ETCS kit[ci] PHA[ci]
the driver to validate train data
configuration through the DMI
display
IEVC-PHA-MM-143 A specific data entry opera- iEVC ETCS kit[ci] PHA[ci]
tional procedure shall be de-
fined to protect against hu-
man error during train con-
figuration (i.e. wheel diame-
ter, tilting/non-tilting category,
length, load and axle gauge,
maximum speed, etc.)
IEVC-PHA-MM-144 The DMI display must give the iEVC ETCS kit[ci] PHA[ci]
possibility to the driver to ad-
just the adhesion factor on the
DMI, when the system acquires
an adhesion factor that is greater
than achievable under prevailing
conditions
IEVC-PHA-MM-147 iEVC communications shall iEVC ETCS kit[ci] PHA[ci]
comply with EN 50159
IEVC-PHA-MM-150 iEVC system shall detect the iEVC ETCS kit[ci] PHA[ci]
Functional Failure of the stand-
still detection according to Sub-
set 026 in a safe way
IEVC-PHA-MM-151 iEVC system shall detect the iEVC ETCS kit[ci] PHA[ci]
failure of Standstill Supervision
Function as per subset-026-3
IEVC-PHA-MM-152 iEVC system shall supervise the iEVC ETCS kit[ci] PHA[ci]
movement authority (MA) ac-
cording to Subset 026 in a safe
way
IEVC-PHA-MM-153 iEVC system shall compute the iEVC ETCS kit[ci] PHA[ci]
confidence interval and reloca-
tion of the train position accord-
ing to Subset 026 in a safe way
IEVC-PHA-MM-154 iEVC system shall compute a iEVC ETCS kit[ci] PHA[ci]
traction/braking model accord-
ing to Subset 026 in a safe way
IEVC-PHA-MM-155 iEVC system shall supervise re- iEVC ETCS kit[ci] PHA[ci]
verse movement according to
Subset 026 in a safe way
IEVC-PHA-MM-156 The iEVC system shall identify iEVC ETCS kit[ci] PHA[ci]
the position of the train in rela-
tion to the reference position ac-
cording to Subset 026 in a safe
way
IEVC-PHA-MM-157 iEVC system shall identify the iEVC ETCS kit[ci] PHA[ci]
cab status (TIU failure) accord-
ing to Subset 026 in a safe way
26 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
IEVC-PHA-MM-158 iEVC system shall check the iEVC ETCS kit[ci] PHA[ci]
Balise messages consistency ac-
cording to Subset 026 in a safe
way.
IEVC-PHA-MM-159 iEVC system shall check the iEVC ETCS kit[ci] PHA[ci]
Radio messages consistency ac-
cording to Subset 026 in a safe
way.
IEVC-PHA-MM-160 iEVC system shall check the iEVC ETCS kit[ci] PHA[ci]
Loop messages consistency ac-
cording to Subset 026 in a safe
way.
IEVC-PHA-MM-161 iEVC system shall supervise or iEVC ETCS kit[ci] PHA[ci]
monitor the train trip monitor-
ing according to Subset 026 in
a safe way
IEVC-PHA-MM-162 iEVC system shall supervise iEVC ETCS kit[ci] PHA[ci]
the driver acknowledgement ac-
cording to Subset 026 in a safe
way
IEVC-PHA-MM-163 iEVC system shall inform the iEVC ETCS kit[ci] PHA[ci]
trackside with train data accord-
ing to Subset 026 in a safe way
IEVC-PHA-MM-164 the iEVC system shall not con- iEVC ETCS kit[ci] PHA[ci]
tain potentially ignition sources
IEVC-PHA-MM-165 the iEVC system shall control iEVC ETCS kit[ci] PHA[ci]
the of electromechanical equip-
ment temperature
IEVC-PHA-MM-166 the iEVC system shall not con- iEVC ETCS kit[ci] PHA[ci]
tains potentially explosive mater
IEVC-PHA-MM-167 the installation of iEVC system iEVC ETCS kit[ci] PHA[ci]
on the roof of the locomotive
shall not be a point of attraction
for lightning
IEVC-PHA-MM-168 The speed measure system shall iEVC ETCS kit[ci] PHA[ci]
allow to reach SIL4 for the
odometry function of the iEVC
IEVC-PHA-MM-169 The iEVC system shall process iEVC ETCS kit[ci] PHA[ci]
DMI display according to Sub-
set 026 in a safe way
IEVC-PHA-MM-170 In case of multiple installations iEVC ETCS kit[ci] PHA[ci]
of IEVC systems on a train, the
leading iEVC shall be identi-
fied.
IEVC-PHA-MM-171 iEVC system shall supervise the iEVC ETCS kit[ci] PHA[ci]
train movement in order to pro-
tect against the undesired move-
ment according to Subset 026 in
a safe way
IEVC-PHA-MM-172 The driver shall not be hurt iEVC ETCS kit[ci] PHA[ci]
by the alarm noise level of the
iEVC system.
IEVC-PHA-MM-173 The iEVC system shall allow to iEVC ETCS kit[ci] PHA[ci]
reach SIL4 for the braking func-
tion (including TIU)
27 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
IEVC-PHA-MM-174 The design shall take into ac- iEVC ETCS kit[ci] PHA[ci]
count adhesion conditions for
the calculation of train speed
and position
IEVC-PHA-MM-176 The installation of the iEVC iEVC ETCS kit[ci] PHA[ci]
system shall respect the ac-
cepted or qualified loading
gauge
IEVC-PHA-MM-177 The iEVC system must be pro- iEVC ETCS kit[ci] PHA[ci]
tected against cyber-attacks, es-
pecially if the iEVC system
opens new access doors to the
system (usb port, 4G access
point, ethernet port, etc.)
IEVC-PHA-MM-179 The iBTM RX module must iEVC ETCS kit[ci] PHA[ci]
be compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-180 The iBTM TX module must iEVC ETCS kit[ci] PHA[ci]
be compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-181 The Euroantenna must be iEVC ETCS kit[ci] PHA[ci]
compliant with at least HL2
fire behaviour requirements of
EN45545-2:2013
IEVC-PHA-MM-183 The elements of the iEVC sys- iEVC ETCS kit[ci] PHA[ci]
tem that normaly are not in-
teracting with the driver shall
not distract him, during the nor-
mal operation (for exemple with
sounds or lights)
IEVC-PHA-MM-184 The ievc shall be fixed such that iEVC ETCS kit[ci] PHA[ci]
the element are not easily acces-
sible and demontable
IEVC-PHA-MM-185 Freeze of DMI display shall de- iEVC ETCS kit[ci] PHA[ci]
tect and system shall switch to a
safe state
IEVC-PHA-MM-186 Alarms of the iEVC system iEVC ETCS kit[ci] PHA[ci]
shall be heard by the driver in
every condition.
Recap Table
28 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
29 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
30 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
31 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
32 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
33 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
34 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
35 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
The following table resumes the mitigations identified as not applicable during the PHA.
The structure of the table is:
• id: Unique Identification number
• argument: mitigation description
• status: Status of the requirement
• source_justification: justification of the requirement status
• mitigation_status: Status of the mitigation
Recap Table
36 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
37 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
38 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
CHAPTER
NINE
ANNEX A CAUSES
The following table resumes the applicable causes identified during the PHA.
The structure of the table is:
• id: Unique Identification number
• argument: cause description
• mitigation: list of the mitigations required for this cause
• applicable: if false, the mitigation is not applicable
• justification: (only for non applicable causes) justification of the non applicability of the cause
Recap Table
9. Annex A Causes 39 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
40 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
41 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
42 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
43 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
44 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
45 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
46 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
47 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
48 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
49 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
50 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
51 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
52 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
53 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
54 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
55 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
56 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
57 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
58 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
59 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
Recap Table
60 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
61 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
62 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
63 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
64 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
65 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
66 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
67 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
68 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
69 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
70 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
71 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
72 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
73 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
74 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
75 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
76 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
77 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
iEVC Preliminary Hazard Analysis
Some causes of type ‘Refer to’ were used in the PHA excel file to make the link between hazard with identical
scenarios.
78 of 79
381783a7f0b45c8b0c2df11e1a7cc16cb71b2b7d
CHAPTER
TEN
Attached file
tsc_ievc_rams_pha [attach]