Search NASA⌕ Search

SEARCH · Search NASA

Results for “system thinking”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

A Science-Driven Mission Concept to An Exoplanet

A concept for a science-driven robotic mission to an exoplanet was developed by a team of scientists and engineers from NASA and academia. The concept and scope were based on key mission and science requirements designed to address the question: “What makes a flight mission to an exoplanet compelling, in terms of science return, compared to what we will be able to learn in the next few decades with large near-Earth telescopes or other remote sensing techniques such as a telescope at the Solar Gravity Lens Focus?” By thinking systematically through mission and science goals and objectives, key requirements were developed that would drive technology developments in all necessary aspects, not just on propulsion. Unique science measurements would be performed en route to the exoplanet, including exploring the environment in the outer regions of our solar system, the Oort Cloud, the local interstellar medium, and the astrospheric environment around the host star. One of the key mission science objectives, and one that addresses why a mission to an exoplanet is compelling, was to confirm and characterize life. This objective is fundamental and drives the need for a precursor exoplanet characterization program to search for Earth-centric biosignatures and also drives key aspects of the mission concept. The team concluded that a direct confirmation of life would require in situ observations and measurements which cannot be performed on a fast (~10% of the speed of light) flyby; thus, the mission would require a method to slow down, orbit, or send a probe to the exoplanet’s surface. This capability drives a trade between interstellar travel velocity, trip duration, and propulsion architecture, as well as a high level of onboard autonomy, including adaptive science data collection, on-board data processing, and analysis. This paper describes our mission concept, the key requirements, and open trades.

Bennett, Gary↗

The role of knowledge structures in fault diagnosis

The use of human memory and knowledge structures to direct fault diagnosis performance was investigated. The performances of 20 pilots with instrument flight ratings were studied in a fault diagnosis task. The pilots were read a scenario which described flight conditions under which the symptoms which are indicative of a problem were detected. They were asked to think out loud as they requested and interpreted various pieces of information to diagnose the cause of the problem. Only 11 of the 20 pilots successfully diagnosed the problem. Pilot performance on this fault diagnosis task was modeled in the use of domain specific knowledge organized in a frame system. Eighteen frames, with a common structure, were necessary to account for the data from all twenty subjects.

Smith, P. J.↗

From where they look to what they think: Determining controller cognitive strategies from oculometer scanning data

The behavior and cognition of air traffic controllers from oculometer scanning data already obtained for another purpose was studied. There was very little work done to develop models of air traffic controllers, much of what was done was done at Langley. One aim of developing such models is to use them as the basis of decision-support or expert-system tools to assist controllers in their tasks. Such tools are more likely to be effective if they incorporate the strategies that controllers actually use, rather than steering them in what might be felt to be unnatural directions.

Cushing, Steven↗

Estimation of high temperature metal-silicate partition coefficients

It has been known for some time that abundances of siderophile elements in the upper mantle of the Earth are far in excess of those expected from equilibrium between metal and silicate at low pressures and temperatures. Murthy (1991) has re-examined this excess of siderophile element problem by estimating liquid metal/liquid silicate partition coefficients reduces from their measured values at a lower temperature, implying that siderophile elements become much less siderophilic at high temperatures. Murthy then draws the important conclusion that metal/silicate equilibrium at high temperatures can account for the abundances of siderophile elements in the Earth's mantle. Of course, his conclusion is critically dependent on the small values of the partition coefficients he calculates. Because the numerical values of most experimentally-determined partition coefficients increase with increasing temperature at both constant oxygen fugacity and at constant redox buffer, we think it is important to try an alternative extrapolation for comparison. We have computed high temperature metal/silicate partition coefficients under a different set of assumptions and show that such long temperature extrapolations yield values which are critically dependent upon the presumed chemical behavior of the siderophile elements in the system.

Jones, John H.↗

Contingency Operations of Americas Next Moon Rocket, Ares V

America has begun the development of a new space vehicle system which will enable humans to return to the moon and reach even farther destinations. The system is called Constellation: it has 2 earth-launch vehicles, Ares I and Ares V; a crew module, Orion; and a lander, Altair with descent and ascent stages. Ares V will launch an Earth Departure Stage (EDS) and Altair into low earth orbit. Ares I will launch the Orion crew module into low earth orbit where it will rendezvous and dock with the Altair and EDS "stack". After rendezvous, the stack will contain four complete rocket systems, each capable of independent operations. Of course this multiplicity of vehicles provides a multiplicity of opportunities for off-nominal behavior and multiple mitigation options for each. Contingency operations are complicated by the issues of crew safety and the possibility of debris from the very large components impacting the ground. This paper examines contingency operations of the EDS in low earth orbit, during the boost to translunar orbit, and after the translunar boost. Contingency operations under these conditions have not been a consideration since the Apollo era and analysis of the possible contingencies and mitigations will take some time to evolve. Since the vehicle has not been designed, much less built, it is not possible to evaluate contingencies from a root-cause basis or from a probability basis; rather they are discussed at an effects level (such as the reaction control system is consuming propellant at a high rate). Mitigations for the contingencies are based on the severity of the off-nominal condition, the time of occurrence, recovery options, options for alternate missions, crew safety, evaluation of the condition (forensics) and future prevention. Some proposed mitigations reflect innovation in thinking and make use of the multiplicity of on-orbit resources including the crew; example: Orion could do a "fly around" to allow the crew to determine the condition and cause of a partially separated payload shroud. Other mitigations are really alternate missions; example, an engine out on during ascent resulted in insufficient propellant for the lunar mission, but the on-orbit vehicle stack is otherwise perfect and can pursue an alternate mission, such as a high ballistic trajectory to test the high-speed atmospheric reentry of Orion. Evaluation and presentation of contingency operations at this early stage of the development of the Ares V rocket will improve the design of the vehicle and lay the groundwork for the exhaustive contingency planning which must be done after the vehicle is built as preparations for operations.

Jaap, John↗

Model for Predicting the Performance of Planetary Suit Hip Bearing Designs

Designing a space suit is very complex and often requires difficult trade-offs between performance, cost, mass, and system complexity. During the development period of the suit numerous design iterations need to occur before the hardware meets human performance requirements. Using computer models early in the design phase of hardware development is advantageous, by allowing virtual prototyping to take place. A virtual design environment allows designers to think creatively, exhaust design possibilities, and study design impacts on suit and human performance. A model of the rigid components of the Mark III Technology Demonstrator Suit (planetary-type space suit) and a human manikin were created and tested in a virtual environment. The performance of the Mark III hip bearing model was first developed and evaluated virtually by comparing the differences in mobility performance between the nominal bearing configurations and modified bearing configurations. Suited human performance was then simulated with the model and compared to actual suited human performance data using the same bearing configurations. The Mark III hip bearing model was able to visually represent complex bearing rotations and the theoretical volumetric ranges of motion in three dimensions. The model was also able to predict suited human hip flexion and abduction maximums to within 10% of the actual suited human subject data, except for one modified bearing condition in hip flexion which was off by 24%. Differences between the model predictions and the human subject performance data were attributed to the lack of joint moment limits in the model, human subject fitting issues, and the limited suit experience of some of the subjects. The results demonstrate that modeling space suit rigid segments is a feasible design tool for evaluating and optimizing suited human performance. Keywords: space suit, design, modeling, performance

Cowley, Matthew S.↗

NASA Archives and Data Stewardship in the Cloud with Cumulus

NASA's Earth Observing System Data and Information System (EOSDIS) houses nearly 30PB (petabytes) of critical Earth Science data and with upcoming missions is expected to balloon to between 200PBs-300PBs over the next seven years. The magnitude of data collected makes it infeasible to download data and process it locally, forcing us to re-think how we store and work with earth science data. NASA has looked to the cloud to address this, building its open source Cumulus software to manage the ingest of diverse data in a wide variety of formats into the cloud and provide services to manage and access the data. In this talk, we will describe how Cumulus provides common features needed to manage a cloud archive in the realm of ingest, data stewardship, and cost-controlled distribution of science data to users and services.

NASA↗

Automatic selection of dynamic data partitioning schemes for distributed memory multicomputers

For distributed memory multicomputers such as the Intel Paragon, the IBM SP-2, the NCUBE/2, and the Thinking Machines CM-5, the quality of the data partitioning for a given application is crucial to obtaining high performance. This task has traditionally been the user's responsibility, but in recent years much effort has been directed to automating the selection of data partitioning schemes. Several researchers have proposed systems that are able to produce data distributions that remain in effect for the entire execution of an application. For complex programs, however, such static data distributions may be insufficient to obtain acceptable performance. The selection of distributions that dynamically change over the course of a program's execution adds another dimension to the data partitioning problem. In this paper, we present a technique that can be used to automatically determine which partitionings are most beneficial over specific sections of a program while taking into account the added overhead of performing redistribution. This system is being built as part of the PARADIGM (PARAllelizing compiler for DIstributed memory General-purpose Multicomputers) project at the University of Illinois. The complete system will provide a fully automated means to parallelize programs written in a serial programming model obtaining high performance on a wide range of distributed-memory multicomputers.

Palermo, Daniel J.↗

From Research to Flight: Thinking About Implementation While Performing Fundamental Research

This slide presentation calls for a strategy to implement new technologies. Such a strategy would allow advanced space transportation technologies to mature for exploration beyond Earth orbit. It discusses the difference between technology push versus technology pull. It also reviews the three basic technology readiness levels (TRL). The presentation traces examples of technology development to flight application: the Space Shuttle Main Engine Advanced Health Management System, the Friction Stir Welding technology the (auto-adjustable pin tool). A couple of technologies currently not in flight, but are being reviewed for potential use are: cryogenic fluid management (CFM), and solar sail propulsion. There is also an attempt to explain why new technologies are so difficult to field.

Johnson, Les↗

The Naturalistic Flight Deck System: An Integrated System Concept for Improved Single-Pilot Operations

This paper reviews current and emerging operational experiences, technologies, and human-machine interaction theories to develop an integrated flight system concept designed to increase the safety, reliability, and performance of single-pilot operations in an increasingly accommodating but stringent national airspace system. This concept, know as the Naturalistic Flight Deck (NFD), uses a form of human-centered automation known as complementary-automation (or complemation) to structure the relationship between the human operator and the aircraft as independent, collaborative agents having complimentary capabilities. The human provides commonsense knowledge, general intelligence, and creative thinking, while the machine contributes specialized intelligence and control, extreme vigilance, resistance to fatigue, and encyclopedic memory. To support the development of the NFD, an initial Concept of Operations has been created and selected normal and non-normal scenarios are presented in this document.

Schutte, Paul C.↗

Exploring the Solar System Activities Outline: Hands-On Planetary Science for Formal Education K-14 and Informal Settings

Activities by NASA scientists and teachers focus on integrating Planetary Science activities with existing Earth science, math, and language arts curriculum. The wealth of activities that highlight missions and research pertaining to the exploring the solar system allows educators to choose activities that fit a particular concept or theme within their curriculum. Most of the activities use simple, inexpensive techniques that help students understand the how and why of what scientists are learning about comets, asteroids, meteorites, moons and planets. With these NASA developed activities students experience recent mission information about our solar system such as Mars geology and the search for life using Mars meteorites and robotic data. The Johnson Space Center ARES Education team has compiled a variety of NASA solar system activities to produce an annotated thematic outline useful to classroom educators and informal educators as they teach space science. An important aspect of the outline annotation is that it highlights appropriate science content information and key science and math concepts so educators can easily identify activities that will enhance curriculum development. The outline contains URLs for the activities and NASA educator guides as well as links to NASA mission science and technology. In the informal setting educators can use solar system exploration activities to reinforce learning in association with thematic displays, planetarium programs, youth group gatherings, or community events. Within formal education at the primary level some of the activities are appropriately designed to excite interest and arouse curiosity. Middle school educators will find activities that enhance thematic science and encourage students to think about the scientific process of investigation. Some of the activities offered are appropriate for the upper levels of high school and early college in that they require students to use and analyze data.

Allen, J. S.↗

Challenges and Lessons Learned in the Application of Autonomy to Space Operations

NASA's Space Operations Management Office (SOMO) is working toward a goal of providing an integrated infrastructure of mission and data services for space missions undertaken by NASA enterprises. A significant portion of this effort is focused on reducing the cost of these services. We are interested in the potential of autonomy to reduce operations costs. SOMO services support space missions, but are not part of the mission objectives; therefore the level of acceptable risk is very low. In fact, SOMO could be effective ly prevented from applying autonomy if customers merely perceive it as adding risk to their mission(s). We are interested in this workshop from the standpoint of understanding what can be done to realize the potential cost savings due to autonomy while maintaining acceptable risk and serving the needs of our customers. We would like to present our lessons learned so far in adopting autonomy and automation, which we think will contribute to clarifying the challenges facing the use of such technology. SOMO provides services to a diverse and ambitious set of mission customers. Many of these missions are groundbreaking missions for which communications, data, and other operations requirements sometimes cannot be clearly articulated early in the program. This motivates a need for systems that are robust in the face of unanticipated situations so that customer missions are not unreasonably constrained or impacted by "shortcomings" in SOMO services. One of SOMO's primary goals is to realize a paradigm in which SOMO acts as a service provider to organizations that fly space missions for NASA, other government agencies, and even the commercial sector. These organizations purchase SOMO services "by the pound" as customers. We have to provide systems that are not experiments themselves, but rather stable bases from which to do bold experiments. To this end, SOMO also seeks to work closely with industry to see that robust autonomy technology gets infused into products and services for the space industry and beyond. The potential for application of these technologies spans space-based communications networks (e.g. TDRSS) and ground-based assets including communication and tracking antenna systems, data networks, and control centers. There are several problems that are candidates for the application of autonomy, if it can be made reliable enough, including: antenna control, antenna scheduling, communication link scheduling and operation, navigation, attitude determination, fault detection, isolation, and reconfiguration (for spacecraft or ground assets), and mission-level planning and scheduling. Some attempts have been made to apply autonomy and automation in these areas in the past with varying degrees of success. We will present relevant case histories and the lessons inferred from them. Combining this past experience with anticipated future needs, we can clarify the challenges that must be met in order to realize the benefits of autonomy.

Forrest, David J.↗

Additive Manufacturing: Disrupting Global Supply Chains and Enabling Sustainable Development

The integration of new materials and innovative manufacturing technologies into product supply chains are critically needed to address human and societal needs and to promote sustainable development and economic competitiveness. Recently, there has been tremendous growth in the additive manufacturing (AM) landscape with the introduction of high- end machines suitable for industrial applications. In addition, availability of desktop 3-D printers as well as open source printers and platforms have also facilitated the large scale growth of distributed manufacturing. The paradigm shift in thinking, where one can turn their design into product on demand, is leading to new business models and challenging traditional models of product development and distribution. In this presentation, an overview of different AM technologies will be provided along with technical challenges and opportunities. Various examples of materials (polymers, ceramics, metals, hybrids, and multi material systems) and structures achieved from utilizing a wide variety of additive manufacturing approaches will be provided. Technical challenges and opportunities for the utilization of additive manufacturing as a powerful enabler for sustainable development and disruptive technological threat to global supply chains for different materials and systems will be presented.

Additive Manufacturing↗

Earth Radiation Imbalance from a Constellation of 66 Iridium Satellites: Climate Science Aspects

The "global warming hiatus" since the 1998 El Nino, highlighted by Meehl et al., and the resulting "missing energy" problem highlighted by Trenberth et al., has opened the door to a more fundamental view of climate change than mere surface air temperature. That new view is based on two variables which are strongly correlated: the rate of change of ocean heat content d(OHC)/dt; and Earth Radiation Imbalance (ERI) at the top of the atmosphere, whose guesstimated range is 0.4 to 0.9 Watts per square meters (this imbalance being mainly due to increasing CO2). The Argo float array is making better and better measurements of OHC. But existing satellite systems cannot measure ERI to even one significant digit. So, climate model predictions of ERI are used in place of real measurements of it, and the satellite data are tuned to the climate model predictions. Some oceanographers say "just depend on Argo for understanding the global warming hiatus and the missing energy", but we don't think this is a good idea because d(OHC)/dt and ERI have different time scales and are never perfectly correlated. We think the ERB community needs to step up to measuring ERI correctly, just as oceanographers have deployed Argo to measure OHC correctly. This talk will overview a proposed constellation of 66 Earth radiation budget instruments, hosted on Iridium satellites, that will actually be able to measure ERI to at least one significant digit, thus enabling a crucial test of climate models. This constellation will also be able to provide ERI at two-hourly time scales and 500-km spatial scales without extrapolations from uncalibrated narrowband geostationary instruments, using the highly successful methods of GRACE to obtain spatial resolution. This high time resolution would make ERI a synoptic variable like temperature, and allow studies of ERI's response to fast-evolving phenomena like dust storms and hurricanes and even brief excursions of Total Solar Irradiance. Time permitting, we will also discuss the emerging view of clear vs. cloudy and its implications for the traditional ERB approach.

Wiscombe, W.↗

Space Transformation -- Localizing the Remote and Connecting the Isolated

In motivating the Space Transformation theme for this year’s 4S symposium, the organizers provided the following context, “Transformation of economies are driven by a change in values and accelerated by new technologies.” These words rang particularly true when I read them at the beginning of the holiday season. Like so many others, I was in the early phases of my Christmas shopping procrastination campaign, and I’d just been reflecting on how Amazon Prime was the transformational tool I’d been waiting for. Basic limiting principles of time and space, supply and demand, were all but erased by the Amazon Prime phenomenon. Coupled with emerging 3D printing and other adaptive manufacturing technologies, a transformation from deliberate planning to “think it … have it” had occurred, empowering me to procrastinate longer than I’d ever dreamed possible. The organizers went on to ponder, “Will space transformation also affect society?”, just as our team at the Air Force Research Lab’s (AFRL) Center for Rapid Innovation (CRI) were working alongside partners within our larger Integrated Capabilities Directorate, NASA’s Flight Opportunities and Small Spacecraft Technology programs, and DARPA’s Luna-10 program to develop technologies and execute demonstration missions that leverage the space domain to genuinely connect even the most remote and austere domains on the timeline of need. Picking apart the miracle that is Amazon prime, where does the model fail, and why? More relevantly to the theme of this year’s symposium, how can the space domain be used to overcome its limitations and minimize its weaknesses? Perhaps it is best assessed in the context of Use Cases. What are the Amazon delivery cost, schedule, and cargo limiters to the Amundsen-Scott South Pole Research Station, or the Lunar South Pole Research Station? This paper will explore enabling infrastructure that allows Amazon prime to thrive and assess the transformational enabling technologies that would be necessary to extend that miracle to the truly remote or the truly austere. Localizing the Remote • First, it will evaluate the ability of the on-going AFRL Rocket Cargo and Space Initiatives Ringside Seats systems, coupled with Astrobotic’s Xodiak and Xogdor capabilities, developed to support the NASA Flight Opportunities Program (FOP), to supply orbital/suborbital delivery to both improved and austere sites on the Earth and Moon. • Then, it will add the surface terminal distribution leg, with an examination of Lunar Outpost’s Mobile Autonomous Prospecting Platform (MAPP), equipped with Mobile Autonomous Robotic Swarm (MARS) software, and Intuitive Machine’s Hopper, developed with support of AFRL and NASA’s Commercial Lunar Payload Services (CLPS) program. Connecting the Isolated From there, it will focus on the destination, asking what implied destination services are required to support highly assured autonomous delivery. • Specifically, it will highlight Astrobotic’s Skymage mesh-networked publish and subscribe communication and navigation service, as well as AFRL’s on-going developments of radioisotope and reactor nuclear-sourced thermoelectric power generation and distribution systems under development under the Joint Emergent Technology Supplying On-orbit Nuclear Power (JETSON) program by Lockheed Martin, Westinghouse, Intuitive Machines, and Zeno Power, to provide the power service to locations well off the grid. • Finally, the paper will connect to the “human machine”. What connects the remote or in-situ human consumer to the remote domain? What connects the diverse international government and commercial services to each other? The former will focus on AFRL’s OraCloud feeding their Space Defense Control and Characterization System (SDCCS) and Lunar Station’s MoonHacker systems, while the latter will focus on the BlueHalo/Tensor LunX Technology Platform for the Cislunar Commodity Marketplace. In 1984, Krafft Ehricke famously remarked that, “If God wanted man to become a spacefaring species, He would have given man a Moon.” This paper is not about the Moon, but is about humans as a spacefaring species, shedding the pesky land/air limitations of the Amazon Prime model … so that we can all live a procrastinator’s “think it … have it” existence.

Charles Finley↗

On dust emissions from the jovian system

As described by Gruen et al., the dust impact detector on the Ulysses spacecraft detected a totally unexpected series of dust streams in the outer solar system near the orbit of Jupiter. Five considerations lead us to believe that the dust streams emanate from the jovian system itself: the dust streams only occur within about 1 AU of the jovian system, with the strongest stream being the one closest to Jupiter (about 550 R(sub J) away); the direction from which they arrive is never far from the line-of-sight direction to Jupiter; the time period between streams is about 28 (+/- 3) days; the impact velocities are very high--mostly around 40 km/s; and we can think of no cometary, asteroidal, or interstellar source that could give rise to the above four phenomena (such streams have never before been detected).

Zook, H. A.↗

Frontier In-Situ Resource Utilization for Enabling Sustained Human Presence on Mars

The currently known resources on Mars are massive, including extensive quantities of water and carbon dioxide and therefore carbon, hydrogen and oxygen for life support, fuels and plastics and much else. The regolith is replete with all manner of minerals. In Situ Resource Utilization (ISRU) applicable frontier technologies include robotics, machine intelligence, nanotechnology, synthetic biology, 3-D printing/additive manufacturing and autonomy. These technologies combined with the vast natural resources should enable serious, pre- and post-human arrival ISRU to greatly increase reliability and safety and reduce cost for human colonization of Mars. Various system-level transportation concepts employing Mars produced fuel would enable Mars resources to evolve into a primary center of trade for the inner solar system for eventually nearly everything required for space faring and colonization. Mars resources and their exploitation via extensive ISRU are the key to a viable, safe and affordable, human presence beyond Earth. The purpose of this paper is four-fold: 1) to highlight the latest discoveries of water, minerals, and other materials on Mars that reshape our thinking about the value and capabilities of Mars ISRU; 2) to summarize the previous literature on Mars ISRU processes, equipment, and approaches; 3) to point to frontier ISRU technologies and approaches that can lead to safe and affordable human missions to Mars; and 4) to suggest an implementation strategy whereby the ISRU elements are phased into the mission campaign over time to enable a sustainable and increasing human presence on Mars.

Moses, Robert W.↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗