A refinery runs a basic process control system that regulates reactor temperature plus a separate safety instrumented system that trips the feed valve on high temperature. What relationship does IEC 61511 expect between the two?
- A.The SIS is a software partition inside the BPCS with its own tag set
- B.The SIS shares the BPCS controller with one program covering both duties
- C.The trip layer is built on hardware separate from the control layer
- D.The BPCS holds authority to override an SIS trip during process upsets
Why C is correct
IEC 61511 expects the SIS to be independent of the BPCS so a single fault or a single cyber compromise cannot disable both control and protection. Sharing a controller, a software partition or an override path removes that independence.
Know someone studying for OT Security Fundamentals? Send them this one.