A system designed in such a way that if a subsystem fails, the entire system changes to a safe condition.