4.7.1 In the event of a failure of a computer-based
system, that system should automatically revert to the least hazardous
condition.
4.7.2 The failure and restarting of computer-based
systems should not cause processes to enter undefined or critical
states.
4.7.3 Control, alarm and safety functions should
be arranged such that a single failure will not affect more than one
of these functions.