Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
I&C Safety Guide DRAFT 20110803.doc
Скачиваний:
13
Добавлен:
01.02.2015
Размер:
720.38 Кб
Скачать

Control of access to systems important to safety

7.128. SSR 2/1 Requirement 39 states that:

Unauthorized access to the nuclear power plant or unauthorized interference with items important to safety, including computer hardware and software, shall be prevented.

7.129. IAEA Nuclear Security Series No. 4 [30], and 13 [32] give guidance on security for nuclear power plants and the coordination of nuclear safety and security.

7.130. Access to equipment in I&c systems should be limited to prevent unauthorized access and to reduce the possibility of error.

7.131. Unauthorized access poses risks to both personnel safety and equipment integrity.

7.132. Effective methods include appropriate combinations of administrative measures and physical security, e.g., locked enclosures, locked rooms, alarms on enclosure doors.

7.133. Two areas of particular concern for I&C are access to setpoint adjustments and calibration adjustments, because of their importance to preventing degraded system performance due to potential errors in operation or maintenance.

7.134. Paragraphs 8.121-8.133 provide additional guidance for control of electronic access to computer-based systems.

Testing and testability during operation

7.135. SSR 2/1 Requirement 29 states:

Items important to safety for a nuclear power plant shall be designed to be calibrated, tested, maintained, repaired or replaced, inspected and monitored as required to ensure their capability of performing their functions and to maintain their integrity in all conditions specified in their design basis.

7.136. SSR 2/1 Paragraph 6.35 states:

Safety systems shall be designed to permit periodic testing of their functionality when the plant is in operation, including the possibility of testing channels independently for the detection of failures and losses of redundancy that may have occurred. The design shall permit all aspects of functionality testing for the sensor, the input signal, the final actuator and the display.

Test provisions

7.137. I&C systems should include provisions for testing, including built-in test capabilities.

7.138. Testing and calibration of safety system equipment should be possible in all modes of normal operations, including power operation, while retaining the capability of the safety systems to accomplish their safety functions.

7.139. Periodic tests during plant operation will normally be needed to achieve the reliability required of safety systems, however it is sometimes desirable to avoid testing during operation if it puts at risk normal or safe plant operation. The capability for testing and calibration during power operation is not necessary if doing so would adversely affect the safety or operability of the plant.

7.140. Where the ability to test a safety system or component during power operation is not provided:

  1. The reliability of the functions affected should be shown to be acceptable,

  2. The accuracy and stability of the untested components should be shown to meet design basis requirements over the interval between tests,

  3. Consideration should be given to providing means for comparing measurements of untested instrument channels with other devices (for example, to compare neutron power with thermal power), and

  4. The capability to test the untested components during shutdown should be provided.

Automatic testing

7.141. I&C systems should have self-checking features.

7.142. It is necessary to balance the provision of self-checking features and the need for simplicity.

7.143. Built-in test facilities should themselves be capable of being checked at regular intervals to ensure continued correct operation.

7.144. Test facilities include both hardware provided to perform testing and the associated test sequences regardless of whether they are initiated manually or automatically.

7.145. Paragraph 8.70-8.74 give guidance for self-diagnostic functions in digital systems.

Preserving I&C functions during testing

7.146. SSR 2/1 paragraph 5.46 states:

Where items important to safety are planned to be calibrated, tested or maintained during power operation, the respective systems shall be designed for performing such tasks with no significant reduction in the reliability of performance of the safety functions. Provisions for calibration, testing, maintenance, repair, replacement or inspection of items important to safety during shutdown shall be included in the design so that such tasks can be performed with no significant reduction in the reliability of performance of the safety functions.

7.147. The design of the test provisions for I&C systems should minimize the possibility of spurious initiation of safety actions and other adverse effects of the tests on the availability of the plant.

7.148. It is important to consider if use of the test facilities or failure of the test could cause plant upsets or impair the ability of safety systems to perform safety functions.

7.149. Test facilities that are permanently connected to safety systems are themselves safety systems unless they meet the independence guidance of paragraphs 7.21-7.47 and 8.100-8.111.

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]