4) The hydrogen generation plant shall be designed such that the single failure of
a safety control circuit component shall not cascade into a hazardous situation.
To prevent cascade failure, the following shall include but are not limited to :
‐ Protective devices in the machine (e.g. interlocking guards, trip devices)
‐ Protective interlocking of the electrical circuit
‐ Use of proven techniques and components
‐ Provision of partial or complete redundancy or diversity
‐ Provision for functional tests.