Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
I&C Safety Guide DRAFT 20110803.doc
Скачиваний:
13
Добавлен:
01.02.2015
Размер:
720.38 Кб
Скачать

7.60. Failures of I&c components should be detectable by periodic testing or self-revealed by alarm or anomalous indication.

7.61. It is preferred that failures be self-revealing except where this would put the system in an unsafe condition or result in spurious actuation of safety systems.

7.62. Any identified failures that are not detectable by periodic testing, alarm, or anomalous indication should be assumed to exist in conjunction with single failures when evaluating conformance with the single failure criterion.

7.63. Loss of power to any I&C component or failure of an I&C component in any of its predicted failure modes should place the system in a safe condition or into a condition that has been demonstrated to be acceptable on some other defined basis.

7.64. Methods for ensuring that certain failures place a system in a safe condition include, for example, design such that systems go to a safe condition when de-energized or the use of ‘watchdog timers’ to detect that equipment is no longer performing its design function and place the system in a safe condition. Where such practices are applied failures that can occur in the fail-safe design feature itself must also be considered.

7.65. As far as practicable, the more probable failure modes of a component should not cause spurious actuation of safety systems.

7.66. On restart of I&C systems or components the outputs should not automatically change from the predefined safe condition, except in response to valid safety signals.

EQUIPMENT QUALIFICATON

7.67. SSR 2/1 Requirement 30 states that:

A qualification program for equipment shall be implemented to verify that items important to safety at a nuclear power plant are capable of performing their intended functions when necessary, and in the prevailing environmental conditions, throughout their design life, with account taken of plant conditions during maintenance and testing.

7.68. I&C systems and components (including software and HDL code) should be qualified for their intended function during their service life.

7.69. The qualification should provide a degree of confidence commensurate with the system or component’s importance to safety of the system.

7.70. The qualification program(s) should address all topics affecting the suitability of the system or component for its intended functions important to safety, including:

  1. Suitability and correctness of functions and performance,

  2. Environmental qualification,

  3. Qualification for the effects of internal and external hazards, and

  4. Electromagnetic qualification.

7.71. Equipment qualification should be based upon a combination of methods, including:

  1. Use of engineering and manufacturing processes in compliance with recognized standards;

  2. Reliability demonstration;

  3. Past experience in similar applications;

Where operating experience is used, to support equipment qualification it must be shown to relevant to the proposed application and environment of the target application.

  1. Type testing;

  2. Testing of supplied equipment; or

  3. Analysis to extrapolate test results or operating experience under pertinent conditions.

7.72. It is generally not necessary to apply all of the methods mentioned. The specific combination of methods will depend upon the system or component under consideration. For example, the qualification of pre-existing items might place more emphasis on past experience and analysis to compensate for a lack of completely documented verification and validation during engineering and manufacturing.

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]