SlideShare a Scribd company logo
Why SIL3?
Josse Brys TUV Engineer
j.brys@hima.com
22
Agenda
• Functional Safety
• Good planning if specifications are not right?
• What is the difference between a normal safety and SIL3 loop?
• How do systems achieve safety?
• Layers of protection
• Are you safe if you buy a SIL3 PLC?
• Safety & non safety in one application or separate safety and non-safety
• Cyber security
33
HIMA
SIS
Introduction : HIMA helps to prevent:
44
HIMA: Safety Systems Others: Safety is small part
of their business
HIMA
SIS
SIS
Others
Introduction HIMA
HIMA is focused on Safety Systems
55
SIL 3, SIL4 Safety PLC’s
Railways TMC BCS ESD F&G HIPPS Pipeline Logistics Nuclear
HIMA solutions for
Introduction HIMA
66
Safety ?
Why should we invest in safety?
‣ You think safety is expensive, try an accident…
‣ Today an accident cost more than 10x the investment in the process
‣ We have had terrible accidents in the past
‣ We learned, but accidents with serious impact still happen today
77
Functional Safety Standards
88
Safety Integrity Level - SIL
SIL is how we measure the performance of safety functions
carried out by safety instrumented systems
SIL has 3 sides to the story
‣ Process owners:
Which safety functions do I need and how much SIL do I need?
‣ Engineering companies, system integrators, product developers:
How do I build SIL compliant safety devices, functions or systems?
‣ Process operators:
How do I operate, maintain and repair safety functions and
systems to maintain the identified SIL levels?
99
SIL levels
Risk reduction
1010
SIL levels
Most famous SIL requirement is the Probability of Failure on Demand
PFDavg = Probability of Failure on Demand average
1111
Functional Safety
A safety instrumented system is 100% functionally safe if
All random, common cause and systematic failures do not lead to
malfunctioning of the safety system and do not result in
‣ Injury or death of humans
‣ Spills to the environment
‣ Loss of equipment or production
‣ 100% functional safety does not exist but SIL 1, 2, 3 or 4 does
1212
Common cause does not happen?
Complete plant flooded
because of heavy rainfall,
bad drainage and dike
1313
Good planning if specifications are not right?
IEC 61508 Lifecycle Concept
1414
Good planning if specifications are not right?
Lifecycle & Frequency of Failures
1515
Good planning if specifications are not right?
Think the following:
Your specifications = a red car with a horse
What would you get?
1616
A red car with a horse
1717
A red car with a horse
1818
What is the difference between a normal safety and SIL3 loop?
• SIL 1 Typically easy to achieve using standard components
• Through the selection of certified components, can achieve SIL 2 with
single channel sensing or final elements
• Still need to consider the systematic capability for the devices, however
these are less stringent for SIL 1 or 2
• Lifecycle cost typically the same as a normal BPCS loop.
NORMAL LOOP
BPCS = Basic Process Control System
1919
• Redundancy requirements for sensing and final elements
Required by Tables 2 and 3 of 61508-2. Based on SFF
Safe Failure Fraction = A measure of the effectiveness of the fail safe design and/or the built-in diagnostic tests
Depending on the logic solver, can be single channel
• Proof Test Coverage can be a limiting factor
• Systematic requirements higher
Requires careful selection of devices to ensure this is achieved.
May rule out your normal supplier
• Life cycle cost much higher
What is the difference between a normal safety and SIL3 loop?
SIL 3 LOOP
2020
• The higher the SIL the more techniques and measures are required to
detect, control and avoid human error
• SIL 1 Typically easy to achieve using a standard QMS system with added
competence requirements
• SIL 2 requires an “advanced” system with competence management and
reliance on testing
• SIL 3 has stringent requirements governing diversity in design,
competence of a high order and stringent testing requirements
What is the difference between a normal safety and SIL3 loop?
2121
How do systems achieve safety?
Safety Instrumented System
2222
How do systems achieve safety?
1oo3
2323
How do systems achieve safety?
Input
Output
2oo3
A B C
Voting systems
2oo3 Voting
1oo2D
Diagnostic systems
Diagnostics
Diagnostics
Input
Output
µP µP
Diag. Diagnostics
Diagnostics
Diagnostics
2424
How do systems achieve safety?
2525
Layers of protection
Increase safety and cyber security
prevent
mitigate
2626
Layers of protection
Specific
• must be specifically designed to be capable of preventing the consequences of the
potentially hazardous event
Independent
• must be completely independent from all other protection layers
Dependable
• must be capable of acting dependably to prevent the consequence from occurring
(systematic and random faults)
Auditable
• must be tested and maintained to ensure risk reduction is continually achieved
2727
Layers of protection – The 3 “ENOUGHS”
• Big Enough
• Must be big enough to cope the with the potential hazard
• Fast Enough
• Must be fast enough to sense and react to prevent the potential
• Strong Enough
• Must be able to survive all arising situations when preventing the hazardous
event.
2828
Are you safe if you buy a SIL3 PLC?
• NO!!!
• Need to consider Sensing and final elements
• Need to consider Systematic Capability
This applies to the integrator of the Logic Solver – important to look at their
quality system
Apples to the installer of the Safety Integrated Functions – important to look
at their quality system
• Need to carefully consider Proof Test Intervals and Proof test coverage
Short proof test intervals should be avoided as the testing requirements
often require plant shutdown
Incorrect to assume that the proof test is perfect
This can have a profound effect on the result because we are dealing with
very small numbers
2929
Safety & non safety in one application or separate
safety and non-safety
• Considerations for separating:
Hazards are caused by the non safety application
Risk assessment not able to separate the causes
Required by Buncefield recommendation 3
– “physical and electrical independence”
Need for Cyber security
• Considerations for systematic capability!!!
Often the same person programming the non-safety will be programming
the safety!
3030
Safety & non safety in one application or separate
safety and non-safety
prevent
mitigate
3131
Safety & non safety in one application or separate
safety and non-safety
The risk we talk about is related to a hazard
‣ Risk is a combination of
‣ The severity of consequences (C)
‣ The frequency of occurrence (F)
‣ Risk = C x F
Risksafety = probability of a damage * potential of the damage
3232
Security is a foundation for safety.
Functional safety Risksafety = probability of a damage * potential of the damage
World
Sys.
+Cyber security Risksecurity = threat * vulnerability * potential of the damage
World
Sys.
Safety
World
Sys.
3333
Compartmentalize.
Avoid universal
access. Enterprise
Plant DMZ
Control
Center
SIS BPCS
Plant
Conduit
Conduit
Conduit
Internet
3434
Security is a process.
Risk
analysis
Protect
Detect
React
Security is a process to reduce the risk
of damage due to external influence.
This process can be supported by
technical measures.
Source: IEC 62443-3-3
Both the IEC 61511 (safety) and the
draft of the IEC 62 443 (security)
demand to build systems in multiple
layers of protection. (Defense in the
Depth)
Enterprise
Plant DMZ
Control
Center
SIS BPCS
Plant
Conduit
Conduit
Conduit
Internet
3535
Segregation of non safe networks.
Besides the usage of VLAN HIMax offers a
complete segregation. This interference free
implementation guarantees segregated
networks even for non safe protocols.
Max. Safety (SIL3).
Max. Availability for safeethernet.
Max. Availability for non safe
communication.
X-CPU
X-SB
RJ45
Safety-Net
X-COM
RJ45
Field Net
X-COM
RJ45
DCS-Net
3636
Security is supported by HIMA Products:
High quality development process
HIMA products are developed for safety following the four eyes principle
Only documented ports for communication available no backdoor
Minimal attack surface, only required services are integrated.
Systematic use
separate system supports the avoidance of common cause failures and the
multi-layer protection concept.
Products with Security Features
Segregation of safety network (CPU) and non safety network (COM)
Standard Ethernet protocols can be used with any firewall.
blocking of control function via key switch
Display of program changes in the DCS system via CRC
Unused physical ports can be closed by using port-based VLAN.
High-quality programming environment
SILworX checks all software components prior to use.
Code comparison to detect changes in the user program.
2-level user management
Simple Project backup (one file)
User access in Windows is sufficient.
Secure OPC Server
runs as a service, no login to Windows is required.
3737
Be reluctant to trust.
… even vendors of secure products have to admit failures.
3838
Always the right solution ?
38
HIMA can help you getting the right solution and
have the right safety system you need!
Maximum security and availability

More Related Content

What's hot

Functional safety standards_for_machinery
Functional safety standards_for_machineryFunctional safety standards_for_machinery
Functional safety standards_for_machinery
ie-net ingenieursvereniging vzw
 
Safety life cycle seminar IEC61511
Safety life cycle seminar IEC61511Safety life cycle seminar IEC61511
Safety life cycle seminar IEC61511
Luis Atencio
 
Safety system
Safety systemSafety system
Safety system
jafarhosseini123
 
SIL.ppt
SIL.pptSIL.ppt
SIL.ppt
Krishna Yadav
 
The bow tie method
The bow tie methodThe bow tie method
The bow tie method
John Baker
 
Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts
Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts
Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts Mike Boudreaux
 
Safety instrumented systems angela summers
Safety instrumented systems angela summers Safety instrumented systems angela summers
Safety instrumented systems angela summers Ahmed Gamal
 
Safety instrumented systems
Safety instrumented systemsSafety instrumented systems
Safety instrumented systemsMowaten Masry
 
Understanding Safety Level Integrity Levels (SIL)
Understanding Safety Level Integrity Levels (SIL)Understanding Safety Level Integrity Levels (SIL)
Understanding Safety Level Integrity Levels (SIL)
Power Specialties, Inc.
 
ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles
ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous VehiclesISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles
ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles
Intland Software GmbH
 
14 Tips for Process Safety Management
14 Tips for Process Safety Management14 Tips for Process Safety Management
14 Tips for Process Safety Management
Verde Ventures Pvt. Ltd.
 
Understanding sil
Understanding silUnderstanding sil
Understanding sil
rajesh kumar ramaswamy
 
Elements of Process Safety Management
Elements of Process Safety ManagementElements of Process Safety Management
Elements of Process Safety Management
Shirazeh arghami
 
W09 safety risk-assessments-pls-and-sils
W09 safety risk-assessments-pls-and-silsW09 safety risk-assessments-pls-and-sils
W09 safety risk-assessments-pls-and-sils
Vo Quoc Hieu
 
Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...
Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...
Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...
Intland Software GmbH
 
Functional safety by FMEA/FTA
Functional safety by FMEA/FTAFunctional safety by FMEA/FTA
Functional safety by FMEA/FTA
mehmor
 
Delta v emerson_getting_started
Delta v emerson_getting_startedDelta v emerson_getting_started
Delta v emerson_getting_started
JoseLuisPallyZegarra
 

What's hot (20)

Functional safety standards_for_machinery
Functional safety standards_for_machineryFunctional safety standards_for_machinery
Functional safety standards_for_machinery
 
Safety life cycle seminar IEC61511
Safety life cycle seminar IEC61511Safety life cycle seminar IEC61511
Safety life cycle seminar IEC61511
 
Safety system
Safety systemSafety system
Safety system
 
SIL.ppt
SIL.pptSIL.ppt
SIL.ppt
 
The bow tie method
The bow tie methodThe bow tie method
The bow tie method
 
Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts
Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts
Safety Lifecycle Management - Emerson Exchange 2010 - Meet the Experts
 
Safety instrumented systems angela summers
Safety instrumented systems angela summers Safety instrumented systems angela summers
Safety instrumented systems angela summers
 
Safety instrumented systems
Safety instrumented systemsSafety instrumented systems
Safety instrumented systems
 
Understanding Safety Level Integrity Levels (SIL)
Understanding Safety Level Integrity Levels (SIL)Understanding Safety Level Integrity Levels (SIL)
Understanding Safety Level Integrity Levels (SIL)
 
Safety Integrity Levels
Safety Integrity LevelsSafety Integrity Levels
Safety Integrity Levels
 
LAYER OF PROTECTION ANALYSIS
LAYER OF PROTECTION ANALYSISLAYER OF PROTECTION ANALYSIS
LAYER OF PROTECTION ANALYSIS
 
ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles
ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous VehiclesISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles
ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles
 
14 Tips for Process Safety Management
14 Tips for Process Safety Management14 Tips for Process Safety Management
14 Tips for Process Safety Management
 
Understanding sil
Understanding silUnderstanding sil
Understanding sil
 
Elements of Process Safety Management
Elements of Process Safety ManagementElements of Process Safety Management
Elements of Process Safety Management
 
HIPPS
HIPPSHIPPS
HIPPS
 
W09 safety risk-assessments-pls-and-sils
W09 safety risk-assessments-pls-and-silsW09 safety risk-assessments-pls-and-sils
W09 safety risk-assessments-pls-and-sils
 
Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...
Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...
Advanced System Engineering in the Automotive Industry - Dr Alain Pfouga (pro...
 
Functional safety by FMEA/FTA
Functional safety by FMEA/FTAFunctional safety by FMEA/FTA
Functional safety by FMEA/FTA
 
Delta v emerson_getting_started
Delta v emerson_getting_startedDelta v emerson_getting_started
Delta v emerson_getting_started
 

Similar to Why SIL3 (ENG)

0 safety presentation master v1
0 safety presentation master v10 safety presentation master v1
0 safety presentation master v1confidencial
 
10. industrial networks safety and security tom hammond
10. industrial networks safety and security   tom hammond10. industrial networks safety and security   tom hammond
10. industrial networks safety and security tom hammond
PROFIBUS and PROFINET InternationaI - PI UK
 
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
AlgoSec
 
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Cisco Firepower Migration | Cisco and AlgoSec Joint WebinarCisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
AlgoSec
 
SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...
SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...
SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...
Gaurav Singh Rajput
 
Securing Industrial Control System
Securing Industrial Control SystemSecuring Industrial Control System
Securing Industrial Control System
Hemanth M
 
Sil explained in valve actuators
Sil explained in valve actuatorsSil explained in valve actuators
Sil explained in valve actuators
John Kingsley
 
Functional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling IndustryFunctional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling Industry
Lloyd's Register Energy
 
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy ManagementCisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
AlgoSec
 
Deltav sis-system-overview-brochure-data
Deltav sis-system-overview-brochure-dataDeltav sis-system-overview-brochure-data
Deltav sis-system-overview-brochure-data
Nhựt Bằng Nguyễn
 
Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...
Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...
Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...David Sidhu
 
CyberSecurity Best Practices for the IIoT
CyberSecurity Best Practices for the IIoTCyberSecurity Best Practices for the IIoT
CyberSecurity Best Practices for the IIoT
Creekside Marketing Group, LLC
 
Smart Manufacturing
Smart ManufacturingSmart Manufacturing
Smart Manufacturing
CSA Group
 
Key Considerations for Scoping Reinstrumentation Projects
Key Considerations for Scoping Reinstrumentation ProjectsKey Considerations for Scoping Reinstrumentation Projects
Key Considerations for Scoping Reinstrumentation Projects
Yokogawa1
 
Industrial Security.pdf
Industrial Security.pdfIndustrial Security.pdf
Industrial Security.pdf
AhmedRKhan
 
Industrial networks safety & security - e+h june 2018 ben murphy
Industrial networks safety & security - e+h june 2018   ben murphyIndustrial networks safety & security - e+h june 2018   ben murphy
Industrial networks safety & security - e+h june 2018 ben murphy
PROFIBUS and PROFINET InternationaI - PI UK
 
5 things you didnt know you could do with security policy management
5 things you didnt know you could do with security policy management5 things you didnt know you could do with security policy management
5 things you didnt know you could do with security policy management
AlgoSec
 
Safety and security in distributed systems
Safety and security in distributed systems Safety and security in distributed systems
Safety and security in distributed systems
Einar Landre
 

Similar to Why SIL3 (ENG) (20)

lenner.pptx
lenner.pptxlenner.pptx
lenner.pptx
 
0 safety presentation master v1
0 safety presentation master v10 safety presentation master v1
0 safety presentation master v1
 
10. industrial networks safety and security tom hammond
10. industrial networks safety and security   tom hammond10. industrial networks safety and security   tom hammond
10. industrial networks safety and security tom hammond
 
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
 
CI_SCS_Intro
CI_SCS_IntroCI_SCS_Intro
CI_SCS_Intro
 
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Cisco Firepower Migration | Cisco and AlgoSec Joint WebinarCisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
 
SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...
SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...
SIL Awareness | Introduction to Safety Life-Cycle | IEC - 61508 & IEC- 61511 ...
 
Securing Industrial Control System
Securing Industrial Control SystemSecuring Industrial Control System
Securing Industrial Control System
 
Sil explained in valve actuators
Sil explained in valve actuatorsSil explained in valve actuators
Sil explained in valve actuators
 
Functional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling IndustryFunctional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling Industry
 
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy ManagementCisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
 
Deltav sis-system-overview-brochure-data
Deltav sis-system-overview-brochure-dataDeltav sis-system-overview-brochure-data
Deltav sis-system-overview-brochure-data
 
Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...
Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...
Zones IoT Substation Protection and Security Solution NERC CIPv5-014 Overview...
 
CyberSecurity Best Practices for the IIoT
CyberSecurity Best Practices for the IIoTCyberSecurity Best Practices for the IIoT
CyberSecurity Best Practices for the IIoT
 
Smart Manufacturing
Smart ManufacturingSmart Manufacturing
Smart Manufacturing
 
Key Considerations for Scoping Reinstrumentation Projects
Key Considerations for Scoping Reinstrumentation ProjectsKey Considerations for Scoping Reinstrumentation Projects
Key Considerations for Scoping Reinstrumentation Projects
 
Industrial Security.pdf
Industrial Security.pdfIndustrial Security.pdf
Industrial Security.pdf
 
Industrial networks safety & security - e+h june 2018 ben murphy
Industrial networks safety & security - e+h june 2018   ben murphyIndustrial networks safety & security - e+h june 2018   ben murphy
Industrial networks safety & security - e+h june 2018 ben murphy
 
5 things you didnt know you could do with security policy management
5 things you didnt know you could do with security policy management5 things you didnt know you could do with security policy management
5 things you didnt know you could do with security policy management
 
Safety and security in distributed systems
Safety and security in distributed systems Safety and security in distributed systems
Safety and security in distributed systems
 

More from ie-net ingenieursvereniging vzw

Ultrasoon_Clamp-on.pdf
Ultrasoon_Clamp-on.pdfUltrasoon_Clamp-on.pdf
Ultrasoon_Clamp-on.pdf
ie-net ingenieursvereniging vzw
 
Elektromagnetische_debietmeters.pdf
Elektromagnetische_debietmeters.pdfElektromagnetische_debietmeters.pdf
Elektromagnetische_debietmeters.pdf
ie-net ingenieursvereniging vzw
 
SGS Skybase (NL) .pdf
SGS Skybase (NL) .pdfSGS Skybase (NL) .pdf
SGS Skybase (NL) .pdf
ie-net ingenieursvereniging vzw
 
VEGA-Radar vs US-26APR2022-NL.pdf
VEGA-Radar vs US-26APR2022-NL.pdfVEGA-Radar vs US-26APR2022-NL.pdf
VEGA-Radar vs US-26APR2022-NL.pdf
ie-net ingenieursvereniging vzw
 
From process to emission
From process to emissionFrom process to emission
From process to emission
ie-net ingenieursvereniging vzw
 
Contactloos volume flow meting op transportbanden (ENG.)
Contactloos volume flow meting op transportbanden (ENG.)Contactloos volume flow meting op transportbanden (ENG.)
Contactloos volume flow meting op transportbanden (ENG.)
ie-net ingenieursvereniging vzw
 
Connecting fieldbus power and knowledge
Connecting fieldbus power and knowledgeConnecting fieldbus power and knowledge
Connecting fieldbus power and knowledge
ie-net ingenieursvereniging vzw
 
Frequentieregelaars
FrequentieregelaarsFrequentieregelaars
Frequentieregelaars
ie-net ingenieursvereniging vzw
 
Breekplaten beademingsmachines vlamdover (NED.)
Breekplaten beademingsmachines vlamdover (NED.)Breekplaten beademingsmachines vlamdover (NED.)
Breekplaten beademingsmachines vlamdover (NED.)
ie-net ingenieursvereniging vzw
 
Veiligheden rond de tank
Veiligheden rond de tankVeiligheden rond de tank
Veiligheden rond de tank
ie-net ingenieursvereniging vzw
 
Veiligheden rond de tank
Veiligheden rond de tankVeiligheden rond de tank
Veiligheden rond de tank
ie-net ingenieursvereniging vzw
 
Hima cyber security
Hima cyber securityHima cyber security
Hima cyber security
ie-net ingenieursvereniging vzw
 
Vik g.haekens-atex risico evaluatie
Vik g.haekens-atex risico evaluatieVik g.haekens-atex risico evaluatie
Vik g.haekens-atex risico evaluatie
ie-net ingenieursvereniging vzw
 
Hoe maak ik de omgeving van mijn opslagtank veilig efficient
Hoe maak ik de omgeving van mijn opslagtank veilig  efficientHoe maak ik de omgeving van mijn opslagtank veilig  efficient
Hoe maak ik de omgeving van mijn opslagtank veilig efficient
ie-net ingenieursvereniging vzw
 
Checklist tankcontrole 2018 bacd
Checklist tankcontrole 2018 bacdChecklist tankcontrole 2018 bacd
Checklist tankcontrole 2018 bacd
ie-net ingenieursvereniging vzw
 
Controle en ingebruikname van uw opslagtank
Controle en ingebruikname van uw opslagtankControle en ingebruikname van uw opslagtank
Controle en ingebruikname van uw opslagtank
ie-net ingenieursvereniging vzw
 
Certainly not explosive (Eng)
Certainly not explosive (Eng)Certainly not explosive (Eng)
Certainly not explosive (Eng)
ie-net ingenieursvereniging vzw
 
Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)
ie-net ingenieursvereniging vzw
 
Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)
ie-net ingenieursvereniging vzw
 
Tuev sued-drives-and-controls-2014-presentation
Tuev sued-drives-and-controls-2014-presentationTuev sued-drives-and-controls-2014-presentation
Tuev sued-drives-and-controls-2014-presentation
ie-net ingenieursvereniging vzw
 

More from ie-net ingenieursvereniging vzw (20)

Ultrasoon_Clamp-on.pdf
Ultrasoon_Clamp-on.pdfUltrasoon_Clamp-on.pdf
Ultrasoon_Clamp-on.pdf
 
Elektromagnetische_debietmeters.pdf
Elektromagnetische_debietmeters.pdfElektromagnetische_debietmeters.pdf
Elektromagnetische_debietmeters.pdf
 
SGS Skybase (NL) .pdf
SGS Skybase (NL) .pdfSGS Skybase (NL) .pdf
SGS Skybase (NL) .pdf
 
VEGA-Radar vs US-26APR2022-NL.pdf
VEGA-Radar vs US-26APR2022-NL.pdfVEGA-Radar vs US-26APR2022-NL.pdf
VEGA-Radar vs US-26APR2022-NL.pdf
 
From process to emission
From process to emissionFrom process to emission
From process to emission
 
Contactloos volume flow meting op transportbanden (ENG.)
Contactloos volume flow meting op transportbanden (ENG.)Contactloos volume flow meting op transportbanden (ENG.)
Contactloos volume flow meting op transportbanden (ENG.)
 
Connecting fieldbus power and knowledge
Connecting fieldbus power and knowledgeConnecting fieldbus power and knowledge
Connecting fieldbus power and knowledge
 
Frequentieregelaars
FrequentieregelaarsFrequentieregelaars
Frequentieregelaars
 
Breekplaten beademingsmachines vlamdover (NED.)
Breekplaten beademingsmachines vlamdover (NED.)Breekplaten beademingsmachines vlamdover (NED.)
Breekplaten beademingsmachines vlamdover (NED.)
 
Veiligheden rond de tank
Veiligheden rond de tankVeiligheden rond de tank
Veiligheden rond de tank
 
Veiligheden rond de tank
Veiligheden rond de tankVeiligheden rond de tank
Veiligheden rond de tank
 
Hima cyber security
Hima cyber securityHima cyber security
Hima cyber security
 
Vik g.haekens-atex risico evaluatie
Vik g.haekens-atex risico evaluatieVik g.haekens-atex risico evaluatie
Vik g.haekens-atex risico evaluatie
 
Hoe maak ik de omgeving van mijn opslagtank veilig efficient
Hoe maak ik de omgeving van mijn opslagtank veilig  efficientHoe maak ik de omgeving van mijn opslagtank veilig  efficient
Hoe maak ik de omgeving van mijn opslagtank veilig efficient
 
Checklist tankcontrole 2018 bacd
Checklist tankcontrole 2018 bacdChecklist tankcontrole 2018 bacd
Checklist tankcontrole 2018 bacd
 
Controle en ingebruikname van uw opslagtank
Controle en ingebruikname van uw opslagtankControle en ingebruikname van uw opslagtank
Controle en ingebruikname van uw opslagtank
 
Certainly not explosive (Eng)
Certainly not explosive (Eng)Certainly not explosive (Eng)
Certainly not explosive (Eng)
 
Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (Nl.)
 
Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)
Elektrische installaties in ruimtes met stofexplosiegevaar (1.3 Mb) (Nl.)
 
Tuev sued-drives-and-controls-2014-presentation
Tuev sued-drives-and-controls-2014-presentationTuev sued-drives-and-controls-2014-presentation
Tuev sued-drives-and-controls-2014-presentation
 

Recently uploaded

Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTSHeap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Soumen Santra
 
Water billing management system project report.pdf
Water billing management system project report.pdfWater billing management system project report.pdf
Water billing management system project report.pdf
Kamal Acharya
 
MCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdfMCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdf
Osamah Alsalih
 
Recycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part IIIRecycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part III
Aditya Rajan Patra
 
NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...
NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...
NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...
ssuser7dcef0
 
DESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABS
DESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABSDESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABS
DESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABS
itech2017
 
Final project report on grocery store management system..pdf
Final project report on grocery store management system..pdfFinal project report on grocery store management system..pdf
Final project report on grocery store management system..pdf
Kamal Acharya
 
Forklift Classes Overview by Intella Parts
Forklift Classes Overview by Intella PartsForklift Classes Overview by Intella Parts
Forklift Classes Overview by Intella Parts
Intella Parts
 
DfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributionsDfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributions
gestioneergodomus
 
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdfGoverning Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
WENKENLI1
 
Design and Analysis of Algorithms-DP,Backtracking,Graphs,B&B
Design and Analysis of Algorithms-DP,Backtracking,Graphs,B&BDesign and Analysis of Algorithms-DP,Backtracking,Graphs,B&B
Design and Analysis of Algorithms-DP,Backtracking,Graphs,B&B
Sreedhar Chowdam
 
RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...
RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...
RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...
thanhdowork
 
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Dr.Costas Sachpazis
 
Literature Review Basics and Understanding Reference Management.pptx
Literature Review Basics and Understanding Reference Management.pptxLiterature Review Basics and Understanding Reference Management.pptx
Literature Review Basics and Understanding Reference Management.pptx
Dr Ramhari Poudyal
 
Unbalanced Three Phase Systems and circuits.pptx
Unbalanced Three Phase Systems and circuits.pptxUnbalanced Three Phase Systems and circuits.pptx
Unbalanced Three Phase Systems and circuits.pptx
ChristineTorrepenida1
 
Swimming pool mechanical components design.pptx
Swimming pool  mechanical components design.pptxSwimming pool  mechanical components design.pptx
Swimming pool mechanical components design.pptx
yokeleetan1
 
KuberTENes Birthday Bash Guadalajara - K8sGPT first impressions
KuberTENes Birthday Bash Guadalajara - K8sGPT first impressionsKuberTENes Birthday Bash Guadalajara - K8sGPT first impressions
KuberTENes Birthday Bash Guadalajara - K8sGPT first impressions
Victor Morales
 
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdfTop 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Teleport Manpower Consultant
 
Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...
Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...
Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...
AJAYKUMARPUND1
 
Harnessing WebAssembly for Real-time Stateless Streaming Pipelines
Harnessing WebAssembly for Real-time Stateless Streaming PipelinesHarnessing WebAssembly for Real-time Stateless Streaming Pipelines
Harnessing WebAssembly for Real-time Stateless Streaming Pipelines
Christina Lin
 

Recently uploaded (20)

Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTSHeap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
 
Water billing management system project report.pdf
Water billing management system project report.pdfWater billing management system project report.pdf
Water billing management system project report.pdf
 
MCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdfMCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdf
 
Recycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part IIIRecycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part III
 
NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...
NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...
NUMERICAL SIMULATIONS OF HEAT AND MASS TRANSFER IN CONDENSING HEAT EXCHANGERS...
 
DESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABS
DESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABSDESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABS
DESIGN AND ANALYSIS OF A CAR SHOWROOM USING E TABS
 
Final project report on grocery store management system..pdf
Final project report on grocery store management system..pdfFinal project report on grocery store management system..pdf
Final project report on grocery store management system..pdf
 
Forklift Classes Overview by Intella Parts
Forklift Classes Overview by Intella PartsForklift Classes Overview by Intella Parts
Forklift Classes Overview by Intella Parts
 
DfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributionsDfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributions
 
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdfGoverning Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
 
Design and Analysis of Algorithms-DP,Backtracking,Graphs,B&B
Design and Analysis of Algorithms-DP,Backtracking,Graphs,B&BDesign and Analysis of Algorithms-DP,Backtracking,Graphs,B&B
Design and Analysis of Algorithms-DP,Backtracking,Graphs,B&B
 
RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...
RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...
RAT: Retrieval Augmented Thoughts Elicit Context-Aware Reasoning in Long-Hori...
 
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
 
Literature Review Basics and Understanding Reference Management.pptx
Literature Review Basics and Understanding Reference Management.pptxLiterature Review Basics and Understanding Reference Management.pptx
Literature Review Basics and Understanding Reference Management.pptx
 
Unbalanced Three Phase Systems and circuits.pptx
Unbalanced Three Phase Systems and circuits.pptxUnbalanced Three Phase Systems and circuits.pptx
Unbalanced Three Phase Systems and circuits.pptx
 
Swimming pool mechanical components design.pptx
Swimming pool  mechanical components design.pptxSwimming pool  mechanical components design.pptx
Swimming pool mechanical components design.pptx
 
KuberTENes Birthday Bash Guadalajara - K8sGPT first impressions
KuberTENes Birthday Bash Guadalajara - K8sGPT first impressionsKuberTENes Birthday Bash Guadalajara - K8sGPT first impressions
KuberTENes Birthday Bash Guadalajara - K8sGPT first impressions
 
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdfTop 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
 
Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...
Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...
Pile Foundation by Venkatesh Taduvai (Sub Geotechnical Engineering II)-conver...
 
Harnessing WebAssembly for Real-time Stateless Streaming Pipelines
Harnessing WebAssembly for Real-time Stateless Streaming PipelinesHarnessing WebAssembly for Real-time Stateless Streaming Pipelines
Harnessing WebAssembly for Real-time Stateless Streaming Pipelines
 

Why SIL3 (ENG)

  • 1. Why SIL3? Josse Brys TUV Engineer j.brys@hima.com
  • 2. 22 Agenda • Functional Safety • Good planning if specifications are not right? • What is the difference between a normal safety and SIL3 loop? • How do systems achieve safety? • Layers of protection • Are you safe if you buy a SIL3 PLC? • Safety & non safety in one application or separate safety and non-safety • Cyber security
  • 4. 44 HIMA: Safety Systems Others: Safety is small part of their business HIMA SIS SIS Others Introduction HIMA HIMA is focused on Safety Systems
  • 5. 55 SIL 3, SIL4 Safety PLC’s Railways TMC BCS ESD F&G HIPPS Pipeline Logistics Nuclear HIMA solutions for Introduction HIMA
  • 6. 66 Safety ? Why should we invest in safety? ‣ You think safety is expensive, try an accident… ‣ Today an accident cost more than 10x the investment in the process ‣ We have had terrible accidents in the past ‣ We learned, but accidents with serious impact still happen today
  • 8. 88 Safety Integrity Level - SIL SIL is how we measure the performance of safety functions carried out by safety instrumented systems SIL has 3 sides to the story ‣ Process owners: Which safety functions do I need and how much SIL do I need? ‣ Engineering companies, system integrators, product developers: How do I build SIL compliant safety devices, functions or systems? ‣ Process operators: How do I operate, maintain and repair safety functions and systems to maintain the identified SIL levels?
  • 10. 1010 SIL levels Most famous SIL requirement is the Probability of Failure on Demand PFDavg = Probability of Failure on Demand average
  • 11. 1111 Functional Safety A safety instrumented system is 100% functionally safe if All random, common cause and systematic failures do not lead to malfunctioning of the safety system and do not result in ‣ Injury or death of humans ‣ Spills to the environment ‣ Loss of equipment or production ‣ 100% functional safety does not exist but SIL 1, 2, 3 or 4 does
  • 12. 1212 Common cause does not happen? Complete plant flooded because of heavy rainfall, bad drainage and dike
  • 13. 1313 Good planning if specifications are not right? IEC 61508 Lifecycle Concept
  • 14. 1414 Good planning if specifications are not right? Lifecycle & Frequency of Failures
  • 15. 1515 Good planning if specifications are not right? Think the following: Your specifications = a red car with a horse What would you get?
  • 16. 1616 A red car with a horse
  • 17. 1717 A red car with a horse
  • 18. 1818 What is the difference between a normal safety and SIL3 loop? • SIL 1 Typically easy to achieve using standard components • Through the selection of certified components, can achieve SIL 2 with single channel sensing or final elements • Still need to consider the systematic capability for the devices, however these are less stringent for SIL 1 or 2 • Lifecycle cost typically the same as a normal BPCS loop. NORMAL LOOP BPCS = Basic Process Control System
  • 19. 1919 • Redundancy requirements for sensing and final elements Required by Tables 2 and 3 of 61508-2. Based on SFF Safe Failure Fraction = A measure of the effectiveness of the fail safe design and/or the built-in diagnostic tests Depending on the logic solver, can be single channel • Proof Test Coverage can be a limiting factor • Systematic requirements higher Requires careful selection of devices to ensure this is achieved. May rule out your normal supplier • Life cycle cost much higher What is the difference between a normal safety and SIL3 loop? SIL 3 LOOP
  • 20. 2020 • The higher the SIL the more techniques and measures are required to detect, control and avoid human error • SIL 1 Typically easy to achieve using a standard QMS system with added competence requirements • SIL 2 requires an “advanced” system with competence management and reliance on testing • SIL 3 has stringent requirements governing diversity in design, competence of a high order and stringent testing requirements What is the difference between a normal safety and SIL3 loop?
  • 21. 2121 How do systems achieve safety? Safety Instrumented System
  • 22. 2222 How do systems achieve safety? 1oo3
  • 23. 2323 How do systems achieve safety? Input Output 2oo3 A B C Voting systems 2oo3 Voting 1oo2D Diagnostic systems Diagnostics Diagnostics Input Output µP µP Diag. Diagnostics Diagnostics Diagnostics
  • 24. 2424 How do systems achieve safety?
  • 25. 2525 Layers of protection Increase safety and cyber security prevent mitigate
  • 26. 2626 Layers of protection Specific • must be specifically designed to be capable of preventing the consequences of the potentially hazardous event Independent • must be completely independent from all other protection layers Dependable • must be capable of acting dependably to prevent the consequence from occurring (systematic and random faults) Auditable • must be tested and maintained to ensure risk reduction is continually achieved
  • 27. 2727 Layers of protection – The 3 “ENOUGHS” • Big Enough • Must be big enough to cope the with the potential hazard • Fast Enough • Must be fast enough to sense and react to prevent the potential • Strong Enough • Must be able to survive all arising situations when preventing the hazardous event.
  • 28. 2828 Are you safe if you buy a SIL3 PLC? • NO!!! • Need to consider Sensing and final elements • Need to consider Systematic Capability This applies to the integrator of the Logic Solver – important to look at their quality system Apples to the installer of the Safety Integrated Functions – important to look at their quality system • Need to carefully consider Proof Test Intervals and Proof test coverage Short proof test intervals should be avoided as the testing requirements often require plant shutdown Incorrect to assume that the proof test is perfect This can have a profound effect on the result because we are dealing with very small numbers
  • 29. 2929 Safety & non safety in one application or separate safety and non-safety • Considerations for separating: Hazards are caused by the non safety application Risk assessment not able to separate the causes Required by Buncefield recommendation 3 – “physical and electrical independence” Need for Cyber security • Considerations for systematic capability!!! Often the same person programming the non-safety will be programming the safety!
  • 30. 3030 Safety & non safety in one application or separate safety and non-safety prevent mitigate
  • 31. 3131 Safety & non safety in one application or separate safety and non-safety The risk we talk about is related to a hazard ‣ Risk is a combination of ‣ The severity of consequences (C) ‣ The frequency of occurrence (F) ‣ Risk = C x F Risksafety = probability of a damage * potential of the damage
  • 32. 3232 Security is a foundation for safety. Functional safety Risksafety = probability of a damage * potential of the damage World Sys. +Cyber security Risksecurity = threat * vulnerability * potential of the damage World Sys. Safety World Sys.
  • 33. 3333 Compartmentalize. Avoid universal access. Enterprise Plant DMZ Control Center SIS BPCS Plant Conduit Conduit Conduit Internet
  • 34. 3434 Security is a process. Risk analysis Protect Detect React Security is a process to reduce the risk of damage due to external influence. This process can be supported by technical measures. Source: IEC 62443-3-3 Both the IEC 61511 (safety) and the draft of the IEC 62 443 (security) demand to build systems in multiple layers of protection. (Defense in the Depth) Enterprise Plant DMZ Control Center SIS BPCS Plant Conduit Conduit Conduit Internet
  • 35. 3535 Segregation of non safe networks. Besides the usage of VLAN HIMax offers a complete segregation. This interference free implementation guarantees segregated networks even for non safe protocols. Max. Safety (SIL3). Max. Availability for safeethernet. Max. Availability for non safe communication. X-CPU X-SB RJ45 Safety-Net X-COM RJ45 Field Net X-COM RJ45 DCS-Net
  • 36. 3636 Security is supported by HIMA Products: High quality development process HIMA products are developed for safety following the four eyes principle Only documented ports for communication available no backdoor Minimal attack surface, only required services are integrated. Systematic use separate system supports the avoidance of common cause failures and the multi-layer protection concept. Products with Security Features Segregation of safety network (CPU) and non safety network (COM) Standard Ethernet protocols can be used with any firewall. blocking of control function via key switch Display of program changes in the DCS system via CRC Unused physical ports can be closed by using port-based VLAN. High-quality programming environment SILworX checks all software components prior to use. Code comparison to detect changes in the user program. 2-level user management Simple Project backup (one file) User access in Windows is sufficient. Secure OPC Server runs as a service, no login to Windows is required.
  • 37. 3737 Be reluctant to trust. … even vendors of secure products have to admit failures.
  • 38. 3838 Always the right solution ? 38 HIMA can help you getting the right solution and have the right safety system you need! Maximum security and availability