IEC 61508 Functional Safety
Functional-safety standards define how safety-critical protective functions are engineered to a target integrity.
Safety as an engineered function
IEC 61508 (with sector standard IEC 61511) is the framework for functional safety of electrical, electronic, and programmable systems. It treats safety as a function that must be engineered to a defined Safety Integrity Level (SIL), based on the risk it guards against, and verified through the whole lifecycle from hazard analysis to operation.
How it shapes plant protection
- Protective functions (fast shutdown, quench protection, tritium isolation) are identified and assigned integrity targets.
- Safety functions are kept independent of normal control, so a control fault cannot disable protection.
- Failure rates and diagnostic coverage are quantified against the SIL target, not assumed.
- The whole lifecycle is documented, so integrity is auditable.
Independence is the key idea
The most important functional-safety principle is separation: the systems that make the plant work and the systems that make it safe are distinct, so a single failure or a cyber compromise of control cannot also defeat safety. This principle links directly to the I&C architecture and to cybersecurity, and it is what allows a fusion plant to be operated with confidence even while its performance is still being demonstrated in early units.