This paper discusses the Primary Integrity Parameters (PIPs) - design
attributes that, as a group, determine the level of safety integrity a
chieved by a Programmable Electronic System (PES). These parameters in
clude redundancy level, failure rates and modes, diagnostic coverage f
actor, common cause failure rates, on-line manual test interval/durati
on, maintainability and security. The paper demonstrates that the leve
l of safety provided by a PES is not simply a factor of any one of the
se attributes, but is determined by the total combination of the PIPs.
Examples are given to show the dependency of the system safety on eac
h of the parameters.