Monday, 04 April 2011 18:46

Electrical, Electronic and Programmable Electronic Safety-Related Control Systems

Rate this item
(6 votes)

This article discusses the design and implementation of safety- related control systems which deal with all types of electrical, electronic and programmable-electronic systems (including computer-based systems). The overall approach is in accordance with proposed International Electrotechnical Commission (IEC) Standard 1508 (Functional Safety: Safety-Related 

Systems) (IEC 1993).


During the 1980s, computer-based systems—generically referred to as programmable electronic systems (PESs)—were increasingly being used to carry out safety functions. The primary driving forces behind this trend were (1) improved functionality and economic benefits (particularly considering the total life cycle of the device or system) and (2) the particular benefit of certain designs, which could be realized only when computer technology was used. During the early introduction of computer-based systems a number of findings were made:

    • The introduction of computer control was poorly thought out and planned.
    • Inadequate safety requirements were specified.
    • Inadequate procedures were developed with respect to the validation of software.
    • Evidence of poor workmanship was disclosed with respect to the standard of plant installation.
    • Inadequate documentation was generated and not adequately validated with respect to what was actually in the plant (as distinct from what was thought to be in the plant).
    • Less than fully effective operation and maintenance procedures had been established.
    • There was evidently justified concern about the competence of persons to perform the duties required of them.


                In order to solve these problems, several bodies published or began developing guidelines to enable the safe exploitation of PES technology. In the United Kingdom, the Health and Safety Executive (HSE) developed guidelines for programmable electronic systems used for safety-related applications, and in Germany, a draft standard (DIN 1990) was published. Within the European Community, an important element in the work on harmonized European Standards concerned with safety-related control systems (including those employing PESs) was started in connection with the requirements of the Machinery Directive. In the United States, the Instrument Society of America (ISA) has produced a standard on PESs for use in the process industries, and the Center for Chemical Process Safety (CCPS), a directorate of the American Institute of Chemical Engineers, has produced guidelines for the chemical process sector.

                A major standards initiative is currently taking place within the IEC to develop a generically based international standard for electrical, electronic and programmable electronic (E/E/PES) safety-related systems that could be used by the many applications sectors, including the process, medical, transport and machinery sectors. The proposed IEC international standard comprises seven Parts under the general title IEC 1508. Functional safety of electrical/electronic/programmable electronic safety-related systems. The various Parts are as follows:

                  • Part 1.General requirements
                  • Part 2.Requirements for electrical, electronic and programmable electronic systems
                  • Part 3.Software requirements
                  • Part 4.Definitions
                  • Part 5.Examples of methods for the determination of safety integrity levels
                  • Part 6.Guidelines on the application of Parts 2 and 3
                  • Part 7.Overview of techniques and measures.


                            When finalized, this generically based International Standard will constitute an IEC basic safety publication covering functional safety for electrical, electronic and programmable electronic safety-related systems and will have implications for all IEC standards, covering all application sectors as regards the future design and use of electrical/electronic/programmable electronic safety-related systems. A major objective of the proposed standard is to facilitate the development of standards for the various sectors (see figure 1).

                            Figure 1. Generic and application sector standards


                            PES Benefits and Problems

                            The adoption of PESs for safety purposes had many potential advantages, but it was recognized that these would be achieved only if appropriate design and assessment methodologies were used, because: (1) many of the features of PESs do not enable the safety integrity (that is, the safety performance of the systems carrying out the required safety functions) to be predicted with the same degree of confidence that has traditionally been available for less complex hardware-based (“hardwired”) systems; (2) it was recognized that while testing was necessary for complex systems, it was not sufficient on its own. This meant that even if the PES was implementing relatively simple safety functions, the level of complexity of the programmable electronics was significantly greater than that of the hardwired systems they were replacing; and (3) this rise in complexity meant that the design and assessment methodologies had to be given much more consideration than previously, and that the level of personal competence required to achieve adequate levels of performance of the safety-related systems was subsequently greater.

                            The benefits of computer-based PESs include the following:

                              • the ability to perform on-line diagnostic proof checks on critical components at a frequency significantly higher than would otherwise be the case
                              • the potential to provide sophisticated safety interlocks
                              • the ability to provide diagnostic functions and condition monitoring which can be used to analyse and report on the performance of plant and machinery in real time
                              • the capability of comparing actual conditions of the plant with “ideal” model conditions
                              • the potential to provide better information to operators and hence to improve decision-making affecting safety
                              • the use of advanced control strategies to enable human operators to be located remotely from hazardous or hostile environments
                              • the ability to diagnose the control system from a remote location.


                                          The use of computer-based systems in safety-related applications creates a number of problems which need to be adequately addressed, such as the following:

                                            • The failure modes are complex and not always predictable.
                                            • Testing the computer is necessary but is not sufficient in itself to establish that the safety functions will be performed with the degree of certainty required for the application.
                                            • Microprocessors may have subtle variations between different batches, and therefore different batches may display different behaviour.
                                            • Unprotected computer-based systems are particularly susceptible to electrical interference (radiated interference; electrical “spikes” in the mains supplies, electrostatic discharges, etc.).
                                            • It is difficult and often impossible to quantify the probability of failure of complex safety-related systems incorporating software. Because no method of quantification has been widely accepted, software assurance has been based on procedures and standards which describe the methods to be used in the design, implementation and maintenance of the software.


                                                  Safety Systems under Consideration

                                                  The types of safety-related systems under consideration are electrical, electronic and programmable electronic systems (E/E/PESs). The system includes all elements, particularly signals extending from sensors or from other input devices on the equipment under control, and transmitted via data highways or other communication paths to the actuators or other output devices (see figure 2).

                                                  Figure 2. Electrical, electronic and programmable electronic system (E/E/PES)


                                                  The term electrical, electronic and programmable electronic device has been used to encompass a wide variety of devices and covers the following three chief classes:

                                                    1. electrical devices such as electro-mechanical relays
                                                    2. electronic devices such as solid state electronic instruments and logic systems
                                                    3. programmable electronic devices, which includes a wide variety of computer-based systems such as the following:
                                                          • microprocessors
                                                          • micro-controllers
                                                          • programmable controllers (PCs)
                                                          • application-specific integrated circuits (ASICs)
                                                          • programmable logic controllers (PLCs)
                                                          • other computer-based devices (e.g., “smart” sensors, transmitters and actuators).


                                                                    By definition, a safety-related system serves two purposes:

                                                                      1. It implements the required safety functions necessary to achieve a safe state for the equipment under control or maintains a safe state for the equipment under control. The safety-related system must perform those safety functions that are specified in the safety functions requirements specification for the system. For example, the safety functions requirements specification may state that when the temperature reaches a certain value x, valve y shall open to allow water to enter the vessel.
                                                                      2. It achieves, on its own or with other safety-related systems, the necessary level of safety integrity for the implementation of the required safety functions. The safety functions must be performed by the safety-related systems with the degree of confidence appropriate to the application in order to achieve the required level of safety for the equipment under control.


                                                                        This concept is illustrated in figure 3.

                                                                        Figure 3. Key features of safety-related systems


                                                                        System Failures

                                                                        In order to ensure safe operation of E/E/PES safety-related systems, it is necessary to recognize the various possible causes of safety-related system failure and to ensure that adequate precautions are taken against each. Failures are classified into two categories, as illustrated in figure 4.

                                                                        Figure 4. Failure categories


                                                                          1. Random hardware failures are those failures which result from a variety of normal degradation mechanisms in the hardware. There are many such mechanisms occurring at different rates in different components, and since manufacturing tolerances cause components to fail on account of these mechanisms after different times in operation, failures of a total item of equipment comprising many components occur at unpredictable (random) times. Measures of system reliability, such as the mean time between failures (MTBF), are valuable but are usually concerned only with random hardware failures and do not include systematic failures.
                                                                          2. Systematic failures arise from errors in the design, construction or use of a system which cause it to fail under some particular combination of inputs or under some particular environmental condition. If a system failure occurs when a particular set of circumstances arises, then whenever those circumstances arise in the future there will always be a system failure. Any failure of a safety-related system which does not arise from a random hardware failure is, by definition, a systematic failure. Systematic failures, in the context of E/E/PES safety-related systems, include:
                                                                              • systematic failures due to errors or omissions in the safety functions requirements specification
                                                                              • systematic failures due to errors in the design, manufacture, installation or operation of the hardware. These would include failures arising from environmental causes and human (e.g., operator) error
                                                                              • systematic failures due to faults in the software
                                                                              • systematic failures due to maintenance and modification errors.


                                                                                    Protection of Safety-Related Systems

                                                                                    The terms that are used to indicate the precautionary measures required by a safety-related system to protect against random hardware failures and systematic failures are hardware safety integrity measures and systematic safety integrity measures respectively. Precautionary measures that a safety-related system can bring to bear against both random hardware failures and systematic failures are termed safety integrity. These concepts are illustrated in figure 5.

                                                                                    Figure 5. Safety performance terms


                                                                                    Within the proposed international standard IEC 1508 there are four levels of safety integrity, denoted Safety Integrity Levels 1, 2, 3 and 4. Safety Integrity Level 1 is the lowest safety integrity level and Safety Integrity Level 4 is the highest. The Safety Integrity Level (whether 1, 2, 3 or 4) for the safety-related system will depend upon the importance of the role the safety-related system is playing in achieving the required level of safety for the equipment under control. Several safety-related systems may be necessary—some of which may be based on pneumatic or hydraulic technology.

                                                                                    Design of Safety-Related Systems

                                                                                    A recent analysis of 34 incidents involving control systems (HSE) found that 60% of all cases of failure had been “built in” before the safety-related control system had been put into use (figure 7). Consideration of all the safety life cycle phases is necessary if adequate safety-related systems are to be produced.

                                                                                    Figure 7. Primary cause (by phase) of control system failure


                                                                                    Functional safety of safety-related systems depends not only on ensuring that the technical requirements are properly specified but also in ensuring that the technical requirements are effectively implemented and that the initial design integrity is maintained throughout the life of the equipment. This can be realized only if an effective safety management system is in place and the people involved in any activity are competent with respect to the duties they have to perform. Particularly when complex safety-related systems are involved, it is essential that an adequate safety management system is in place. This leads to a strategy that ensures the following:

                                                                                      • An effective safety management system is in place.
                                                                                      • The technical requirements that are specified for the E/E/PES safety-related systems are sufficient to deal with both random hardware and systematic failure causes.
                                                                                      • The competence of the people involved is adequate for the duties they have to perform.


                                                                                          In order to address all the relevant technical requirements of functional safety in a systematic manner, the concept of the Safety Lifecycle has been developed. A simplified version of the Safety Lifecycle in the emerging international standard IEC 1508 is shown in figure 8. The key phases of the Safety Lifecycle are:

                                                                                          Figure 8. Role of the Safety Lifecycle in achieving functional safety


                                                                                            • specification
                                                                                            • design and implementation
                                                                                            • installation and commissioning
                                                                                            • operation and maintenance
                                                                                            • changes after commissioning.


                                                                                                    Level of Safety

                                                                                                    The design strategy for the achievement of adequate levels of safety integrity for the safety-related systems is illustrated in figure 9 and figure 10. A safety integrity level is based on the role the safety-related system is playing in the achievement of the overall level of safety for the equipment under control. The safety integrity level specifies the precautions that need to be taken into account in the design against both random hardware and systematic failures.

                                                                                                    Figure 9. Role of safety integrity levels in the design process



                                                                                                    Figure 10. Role of the Safety Lifecycle in the specification and design process


                                                                                                    The concept of safety and level of safety applies to the equipment under control. The concept of functional safety applies to the safety-related systems. Functional safety for the safety-related systems has to be achieved if an adequate level of safety is to be achieved for the equipment that is giving rise to the hazard. The specified level of safety for a specific situation is a key factor in the safety integrity requirements specification for the safety-related systems.

                                                                                                    The required level of safety will depend upon many factors—for example, the severity of injury, the number of people exposed to danger, the frequency with which people are exposed to danger and the duration of the exposure. Important factors will be the perception and views of those exposed to the hazardous event. In arriving at what constitutes an appropriate level of safety for a specific application, a number of inputs are considered, which include the following:

                                                                                                      • legal requirements relevant to the specific application
                                                                                                      • guidelines from the appropriate safety regulatory authority
                                                                                                      • discussions and agreements with the different parties involved in the application
                                                                                                      • industry standards
                                                                                                      • national and international standards
                                                                                                      • the best independent industrial, expert and scientific advice.



                                                                                                                When designing and using safety-related systems, it must be remembered that it is the equipment under control that creates the potential hazard. The safety-related systems are designed to reduce the frequency (or probability) of the hazardous event and/or the consequences of the hazardous event. Once the level of safety has been set for the equipment, the safety integrity level for the safety-related system can be determined, and it is the safety integrity level that allows the designer to specify the precautions that need to be built into the design to be deployed against both random hardware and systematic failures.



                                                                                                                Read 11706 times Last modified on Saturday, 30 July 2022 01:46

                                                                                                                " DISCLAIMER: The ILO does not take responsibility for content presented on this web portal that is presented in any language other than English, which is the language used for the initial production and peer-review of original content. Certain statistics have not been updated since the production of the 4th edition of the Encyclopaedia (1998)."


                                                                                                                Safety Applications References

                                                                                                                Arteau, J, A Lan, and J-F Corveil. 1994. Use of Horizontal Lifelines in Structural Steel Erection. Proceedings of the International Fall Protection Symposium, San Diego, California (October 27–28, 1994). Toronto: International Society for Fall Protection.

                                                                                                                Backström, T. 1996. Accident risk and safety protection in automated production. Doctoral thesis. Arbete och Hälsa 1996:7. Solna: National Institute for Working Life.

                                                                                                                Backström, T and L Harms-Ringdahl. 1984. A statistical study of control systems and accidents at work. J Occup Acc. 6:201–210.

                                                                                                                Backström, T and M Döös. 1994. Technical defects behind accidents in automated production. In Advances in Agile Manufacturing, edited by PT Kidd and W Karwowski. Amsterdam: IOS Press.

                                                                                                                —. 1995. A comparison of occupational accidents in industries with of advanced manufacturing technology. Int J Hum Factors Manufac. 5(3). 267–282.

                                                                                                                —. In press. The technical genesis of machine failures leading to occupational accidents. Int J Ind Ergonomics.

                                                                                                                —. Accepted for publication. Absolute and relative frequencies of automation accidents at different kinds of equipment and for different occupational groups. J Saf Res.

                                                                                                                Bainbridge, L. 1983. Ironies of automation. Automatica 19:775–779.

                                                                                                                Bell, R and D Reinert. 1992. Risk and system integrity concepts for safety related control systems. Saf Sci 15:283–308.

                                                                                                                Bouchard, P. 1991. Échafaudages. Guide série 4. Montreal: CSST.

                                                                                                                Bureau of National Affairs. 1975. Occupational Safety and Health Standards. Roll-over Protective Structures for Material Handling Equipment and Tractors, Sections 1926, 1928. Washington, DC: Bureau of National Affairs.

                                                                                                                Corbett, JM. 1988. Ergonomics in the development of human-centred AMT. Applied Ergonomics 19:35–39.

                                                                                                                Culver, C and C Connolly. 1994. Prevent fatal falls in construction. Saf Health September 1994:72–75.

                                                                                                                Deutsche Industrie Normen (DIN). 1990. Grundsätze für Rechner in Systemen mit Sicherheitsauffgaben. DIN V VDE 0801. Berlin: Beuth Verlag.

                                                                                                                —. 1994. Grundsätze für Rechner in Systemen mit Sicherheitsauffgaben Änderung A 1. DIN V VDE 0801/A1. Berlin: Beuth Verlag.

                                                                                                                —. 1995a. Sicherheit von Maschinen—Druckempfindliche Schutzeinrichtungen [Machine safety—Pressure-sensitive protective equipment]. DIN prEN 1760. Berlin: Beuth Verlag.

                                                                                                                —. 1995b. Rangier-Warneinrichtungen—Anforderungen und Prüfung [Commercial vehicles—obstacle detection during reversing—requirements and tests]. DIN-Norm 75031. February 1995.

                                                                                                                Döös, M and T Backström. 1993. Description of accidents in automated materials handling. In Ergonomics of Materials Handling and Information Processing at Work, edited by WS Marras, W Karwowski, JL Smith, and L Pacholski. Warsaw: Taylor and Francis.

                                                                                                                —. 1994. Production disturbances as an accident risk. In Advances in Agile Manufacturing, edited by PT Kidd and W Karwowski. Amsterdam: IOS Press.

                                                                                                                European Economic Community (EEC). 1974, 1977, 1979, 1982, 1987. Council Directives on Rollover Protection Structures of Wheeled Agricultural and Forestry Tractors. Brussels: EEC.

                                                                                                                —. 1991. Council Directive on the Approximation of the Laws of the Member States relating to Machinery. (91/368/EEC) Luxembourg: EEC.

                                                                                                                Etherton, JR and ML Myers. 1990. Machine safety research at NIOSH and future directions. Int J Ind Erg 6:163–174.

                                                                                                                Freund, E, F Dierks and J Roßmann. 1993. Unterschungen zum Arbeitsschutz bei Mobilen Rototern und Mehrrobotersystemen [Occupational safety tests of mobile robots and multiple robot systems]. Dortmund: Schriftenreihe der Bundesanstalt für Arbeitsschutz.

                                                                                                                Goble, W. 1992. Evaluating Control System Reliability. New York: Instrument Society of America.

                                                                                                                Goodstein, LP, HB Anderson and SE Olsen (eds.). 1988. Tasks, Errors and Mental Models. London: Taylor and Francis.

                                                                                                                Gryfe, CI. 1988. Causes and prevention of falling. In International Fall Protection Symposium. Orlando: International Society for Fall Protection.

                                                                                                                Health and Safety Executive. 1989. Health and safety statistics 1986–87. Employ Gaz 97(2).

                                                                                                                Heinrich, HW, D Peterson and N Roos. 1980. Industrial Accident Prevention. 5th edn. New York: McGraw-Hill.

                                                                                                                Hollnagel, E, and D Woods. 1983. Cognitive systems engineering: New wine in new bottles. Int J Man Machine Stud 18:583–600.

                                                                                                                Hölscher, H and J Rader. 1984. Mikrocomputer in der Sicherheitstechnik. Rheinland: Verlag TgV-Reinland.

                                                                                                                Hörte, S-Å and P Lindberg. 1989. Diffusion and Implementation of Advanced Manufacturing Technologies in Sweden. Working paper No. 198:16. Institute of Innovation and Technology.

                                                                                                                International Electrotechnical Commission (IEC). 1992. 122 Draft Standard: Software for Computers in the Application of Industrial Safety-related Systems. IEC 65 (Sec). Geneva: IEC.

                                                                                                                —. 1993. 123 Draft Standard: Functional Safety of Electrical/Electronic/Programmable Electronic Systems; Generic Aspects. Part 1, General requirements Geneva: IEC.

                                                                                                                International Labour Organization (ILO). 1965. Safety & Health in Agricultural Work. Geneva: ILO.

                                                                                                                —. 1969. Safety and Health in Forestry Work. Geneva: ILO.

                                                                                                                —. 1976. Safe Construction and Operation of Tractors. An ILO Code of Practice. Geneva: ILO.

                                                                                                                International Organization for Standardization (ISO). 1981. Agricultural and Forestry Wheeled Tractors. Protective Structures. Static Test Method and Acceptance Conditions. ISO 5700. Geneva: ISO.

                                                                                                                —. 1990. Quality Management and Quality Assurance Standards: Guidelines for the Application of ISO 9001 to the Development, Supply and Maintenance of Software. ISO 9000-3. Geneva: ISO.

                                                                                                                —. 1991. Industrial Automation Systems—Safety of Integrated Manufacturing Systems—Basic Requirements (CD 11161). TC 184/WG 4. Geneva: ISO.

                                                                                                                —. 1994. Commercial Vehicles—Obstacle Detection Device during Reversing—Requirements and Tests. Technical Report TR 12155. Geneva: ISO.

                                                                                                                Johnson, B. 1989. Design and Analysis of Fault Tolerant Digital Systems. New York: Addison Wesley.

                                                                                                                Kidd, P. 1994. Skill-based automated manufacturing. In Organization and Management of Advanced Manufacturing Systems, edited by W Karwowski and G Salvendy. New York: Wiley.

                                                                                                                Knowlton, RE. 1986. An Introduction to Hazard and Operability Studies: The Guide Word Approach. Vancouver, BC: Chemetics.

                                                                                                                Kuivanen, R. 1990. The impact on safety of disturbances in flexible manufacturing systems. In Ergonomics of Hybrid Automated Systems II, edited by W Karwowski and M Rahimi. Amsterdam: Elsevier.

                                                                                                                Laeser, RP, WI McLaughlin and DM Wolff. 1987. Fernsteurerung und Fehlerkontrolle von Voyager 2. Spektrum der Wissenshaft (1):S. 60–70.

                                                                                                                Lan, A, J Arteau and J-F Corbeil. 1994. Protection Against Falls from Above-ground Billboards. International Fall Protection Symposium, San Diego, California, October 27–28, 1994. Proceedings International Society for Fall Protection.

                                                                                                                Langer, HJ and W Kurfürst. 1985. Einsatz von Sensoren zur Absicherung des Rückraumes von Großfahrzeugen [Using sensors to secure the area behind large vehicles]. FB 605. Dortmund: Schriftenreihe der bundesanstalt für Arbeitsschutz.

                                                                                                                Levenson, NG. 1986. Software safety: Why, what, and how. ACM Computer Surveys (2):S. 129–163.

                                                                                                                McManus, TN. N.d. Confined Spaces. Manuscript.

                                                                                                                Microsonic GmbH. 1996. Company communication. Dortmund, Germany: Microsonic.

                                                                                                                Mester, U, T Herwig, G Dönges, B Brodbeck, HD Bredow, M Behrens and U Ahrens. 1980. Gefahrenschutz durch passive Infrarot-Sensoren (II) [Protection against hazards by infrared sensors]. FB 243. Dortmund: Schriftenreihe der bundesanstalt für Arbeitsschutz.

                                                                                                                Mohan, D and R Patel. 1992. Design of safer agricultural equipment: Application of ergonomics and epidemiology. Int J Ind Erg 10:301–310.

                                                                                                                National Fire Protection Association (NFPA). 1993. NFPA 306: Control of Gas Hazards on Vessels. Quincy, MA: NFPA.

                                                                                                                National Institute for Occupational Safety and Health (NIOSH). 1994. Worker Deaths in Confined Spaces. Cincinnati, OH, US: DHHS/PHS/CDCP/NIOSH Pub. No. 94-103. NIOSH.

                                                                                                                Neumann, PG. 1987. The N best (or worst) computer-related risk cases. IEEE T Syst Man Cyb. New York: S.11–13.

                                                                                                                —. 1994. Illustrative risks to the public in the use of computer systems and related technologies. Software Engin Notes SIGSOFT 19, No. 1:16–29.

                                                                                                                Occupational Safety and Health Administration (OSHA). 1988. Selected Occupational Fatalities Related to Welding and Cutting as Found in Reports of OSHA Fatality/Catastrophe Investigations. Washington, DC: OSHA.

                                                                                                                Organization for Economic Cooperation and Development (OECD). 1987. Standard Codes for the Official Testing of Agricultural Tractors. Paris: OECD.

                                                                                                                Organisme professionel de prévention du bâtiment et des travaux publics (OPPBTP). 1984. Les équipements individuels de protection contre les chutes de hauteur. Boulogne-Bilancourt, France: OPPBTP.

                                                                                                                Rasmussen, J. 1983. Skills, rules and knowledge: Agenda, signs and symbols, and other distinctions in human performance models. IEEE Transactions on Systems, Man and Cybernetics. SMC13(3): 257–266.

                                                                                                                Reason, J. 1990. Human Error. New York: Cambridge University Press.

                                                                                                                Reese, CD and GR Mills. 1986. Trauma epidemiology of confined space fatalities and its application to intervention/prevention now. In The Changing Nature of Work and Workforce. Cincinnati, OH: NIOSH.

                                                                                                                Reinert, D and G Reuss. 1991. Sicherheitstechnische Beurteilung und Prüfung mikroprozessorgesteuerter
                                                                                                                Sicherheitseinrichtungen. In BIA-Handbuch. Sicherheitstechnisches Informations-und Arbeitsblatt 310222. Bielefeld: Erich Schmidt Verlag.

                                                                                                                Society of Automotive Engineers (SAE). 1974. Operator Protection for Industrial Equipment. SAE Standard j1042. Warrendale, USA: SAE.

                                                                                                                —. 1975. Performance Criteria for Rollover Protection. SAE Recommended Practice. SAE standard j1040a. Warrendale, USA: SAE.

                                                                                                                Schreiber, P. 1990. Entwicklungsstand bei Rückraumwarneinrichtungen [State of developments for rear area warning devices]. Technische Überwachung, Nr. 4, April, S. 161.

                                                                                                                Schreiber, P and K Kuhn. 1995. Informationstechnologie in der Fertigungstechnik [Information technology in production technique, series of the Federal Institute for Occupational Safety and Health]. FB 717. Dortmund: Schriftenreihe der bundesanstalt für Arbeitsschutz.

                                                                                                                Sheridan, T. 1987. Supervisory control. In Handbook of Human Factors, edited by G. Salvendy. New York: Wiley.

                                                                                                                Springfeldt, B. 1993. Effects of Occupational Safety Rules and Measures with Special Regard to Injuries. Advantages of Automatically Working Solutions. Stockholm: The Royal Institute of Technology, Department of Work Science.

                                                                                                                Sugimoto, N. 1987. Subjects and problems of robot safety technology. In Occupational Safety and Health in Automation and Robotics, edited by K Noto. London: Taylor & Francis. 175.

                                                                                                                Sulowski, AC (ed.). 1991. Fundamentals of Fall Protection. Toronto, Canada: International Society for Fall Protection.

                                                                                                                Wehner, T. 1992. Sicherheit als Fehlerfreundlichkeit. Opladen: Westdeutscher Verlag.

                                                                                                                Zimolong, B, and L Duda. 1992. Human error reduction strategies in advanced manufacturing systems. In Human-robot Interaction, edited by M Rahimi and W Karwowski. London: Taylor & Francis.