In general - if any of CS running PCs doesn't work anymore - the systems front end should not be influenced in any sense.
A startup of any of CS PCs should not change the status of the front end. This means that no tag values can be changed by the system without a confirmation at startup (cold and hot startup)
The front end architecture should be able to manage critical situations on its own (like a trip of the HV in case of SY1527) if possible.
There should be at least 2 levels for CS operations: operator and administrator. Tag limits and some other critical values should be changed only by the administrator.