Search NASA⌕ Search

SEARCH · Search NASA

Results for “Risk acceptability”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Ground Data System Risk Mitigation Techniques for Faster, Better, Cheaper Missions

With the advent of faster, cheaper, and better missions, NASA Projects acknowledged that a higher level of risk was inherent and accepted with this approach. It was incumbent however upon each component of the Project whether spacecraft, payload, launch vehicle, or ground data system to ensure that the mission would nevertheless be an unqualified success. The Small Explorer (SMEX) program's ground data system (GDS) team developed risk mitigation techniques to achieve these goals starting in 1989. These techniques have evolved through the SMEX series of missions and are practiced today under the Triana program. These techniques are: (1) Mission Team Organization--empowerment of a closeknit ground data system team comprising system engineering, software engineering, testing, and flight operations personnel; (2) Common Spacecraft Test and Operational Control System--utilization of the pre-launch spacecraft integration system as the post-launch ground data system on-orbit command and control system; (3) Utilization of operations personnel in pre-launch testing--making the flight operations team an integrated member of the spacecraft testing activities at the beginning of the spacecraft fabrication phase; (4) Consolidated Test Team--combined system, mission readiness and operations testing to optimize test opportunities with the ground system and spacecraft; and (5). Reuse of Spacecraft, Systems and People--reuse of people, software and on-orbit spacecraft throughout the SMEX mission series. The SMEX ground system development approach for faster, cheaper, better missions has been very successful. This paper will discuss these risk management techniques in the areas of ground data system design, implementation, test, and operational readiness.

Catena, John J.↗

The NASA Continuous Risk Management Process

As an intern this summer in the GRC Risk Management Office, I have become familiar with the NASA Continuous Risk Management Process. In this process, risk is considered in terms of the probability that an undesired event will occur and the impact of the event, should it occur (ref., NASA-NPG: 7120.5). Risk management belongs in every part of every project and should be ongoing from start to finish. Another key point is that a risk is not a problem until it has happened. With that in mind, there is a six step cycle for continuous risk management that prevents risks from becoming problems. The steps are: identify, analyze, plan, track, control, and communicate & document. Incorporated in the first step are several methods to identify risks such as brainstorming and using lessons learned. Once a risk is identified, a risk statement is made on a risk information sheet consisting of a single condition and one or more consequences. There can also be a context section where the risk is explained in more detail. Additionally there are three main goals of analyzing a risk, which are evaluate, classify, and prioritize. Here is where a value is given to the attributes of a risk &e., probability, impact, and timeframe) based on a multi-level classification system (e.g., low, medium, high). It is important to keep in mind that the definitions of these levels are probably different for each project. Furthermore the risks can be combined into groups. Then, the risks are prioritized to see what risk is necessary to mitigate first. After the risks are analyzed, a plan is made to mitigate as many risks as feasible. Each risk should be assigned to someone in the project with knowledge in the area of the risk. Then the possible approaches to choose from are: research, accept, watch, or mitigate. Next, all risks, mitigated or not, are tracked either individually or in groups. As the plan is executed, risks are re-evaluated, and the attribute values are adjusted as necessary. Metrics are established and monitored as tools for risk tracking. Also a trigger or threshold should be set on the metric data that indicates when an action is needed. Results of this tracking are usually evaluated and reported in a relevant format at weekly or monthly meetings. Choosing controls is the subsequent step, which involves the effects of the tracking. The three basic controls are: close, continue tracking, and re- plan. Finally communicate & document is the last step, but occurs throughout the process. It is vital that main risks, plans, changes, and progress are known by everyone in the project. A good way to keep everyone updated and inform other projects of common issues is by thoroughly documenting project risks. NASA sees value in risk management and believes that projects have greater probability or success by using the NASA Continuous Risk Management Process.

Pokorny, Frank M.↗

Engineering risk reduction in satellite programs

Methods developed in planning and executing system safety engineering programs for Lockheed satellite integration contracts are presented. These procedures establish the applicable safety design criteria, document design compliance and assess the residual risks where non-compliant design is proposed, and provide for hazard analysis of system level test, handling and launch preparations. Operations hazard analysis identifies product protection and product liability hazards prior to the preparation of operational procedures and provides safety requirements for inclusion in them. The method developed for documenting all residual hazards for the attention of program management assures an acceptable minimum level of risk prior to program deployment. The results are significant for persons responsible for managing or engineering the deployment and production of complex high cost equipment under current product liability law and cost/time constraints, have a responsibility to minimize the possibility of an accident, and should have documentation to provide a defense in a product liability suit.

Dean, E. S., Jr.↗

NASA Occupant Protection Standards Development

Historically, spacecraft landing systems have been tested with human volunteers, because analytical methods for estimating injury risk were insufficient. These tests were conducted with flight-like suits and seats to verify the safety of the landing systems. Currently, NASA uses the Brinkley Dynamic Response Index to estimate injury risk, although applying it to the NASA environment has drawbacks: (1) Does not indicate severity or anatomical location of injury (2) Unclear if model applies to NASA applications. Because of these limitations, a new validated, analytical approach was desired. Leveraging off of the current state of the art in automotive safety and racing, a new approach was developed. The approach has several aspects: (1) Define the acceptable level of injury risk by injury severity (2) Determine the appropriate human surrogate for testing and modeling (3) Mine existing human injury data to determine appropriate Injury Assessment Reference Values (IARV). (4) Rigorously Validate the IARVs with sub-injurious human testing (5) Use validated IARVs to update standards and vehicle requirement

Somers, Jeffrey↗

Independent Review of U.S. and Russian Probabilistic Risk Assessments for the International Space Station Mini Research Module #2 Micrometeoroid and Orbital Debris Risk

The Mini-Research Module-2 (MRM-2), a Russian module on the International Space Station, does not meet its requirements for micrometeoroid and orbital debris probability of no penetration (PNP). To document this condition, the primary Russian Federal Space Agency ISS contractor, S.P. Korolev Rocket and Space Corporation-Energia (RSC-E), submitted an ISS non-compliance report (NCR) which was presented at the 5R Stage Operations Readiness Review (SORR) in October 2009. In the NCR, RSC-E argued for waiving the PNP requirement based on several factors, one of which was the risk of catastrophic failure was acceptably low at 1 in 11,100. However, NASA independently performed an assessment of the catastrophic risk resulting in a value of 1 in 1380 and believed that the risk at that level was unacceptable. The NASA Engineering and Safety Center was requested to evaluate the two competing catastrophic risk values and determine which was more accurate. This document contains the outcome of the assessment.

Squire, Michael D.↗

Guidelines for contingency planning NASA (National Aeronautics and Space Administration) ADP security risk reduction decision studies

Guidance is presented to NASA Computer Security Officials for determining the acceptability or unacceptability of ADP security risks based on the technical, operational and economic feasibility of potential safeguards. The risk management process is reviewed as a specialized application of the systems approach to problem solving and information systems analysis and design. Reporting the results of the risk reduction analysis to management is considered. Report formats for the risk reduction study are provided.

Tompkins, F. G.↗

Systems Engineering Lessons Learned for Class D Missions

One of NASA's goals within human exploration is to determine how to get humans to Mars safely and to live and work on the Martian surface. To accomplish this goal, several smaller missions act as stepping-stones to the larger end goal. NASA uses these smaller missions to develop new technologies and learn about how to survive outside of Low Earth Orbit for long periods. Additionally, keeping a cadence of these missions allows the team to maintain proficiency in the complex art of bringing spacecraft to fruition. Many of these smaller missions are robotic in nature and have smaller timescales, whereas there are others that involve crew and have longer mission timelines. Given the timelines associated with these various missions, different levels of risk and rigor need to be implemented to be more in line with what is appropriate for the mission. Thus, NASA has four different classifications that range from Class A to Class D based on the mission details. One of these projects is the Resource Prospector (RP) Mission, which is a multi-center and multi-institution collaborative project to search for volatiles in the polar regions of the Moon. The RP mission is classified as a Class D mission and as such, has the opportunity to more tightly manage, and therefore accept, greater levels of risk. The requirements for Class D missions were at the forefront of the design and thus presented unique challenges in vehicle development and systems engineering processes. This paper will discuss the systems engineering process at NASA and how that process is tailored for Class D missions, specifically the RP mission.

Rojdev, Kristina↗

High Data Rate Architecture (HiDRA)

One of the greatest challenges in developing new space technology is in navigating the transition from ground based laboratory demonstration at Technology Readiness Level 6 (TRL-6) to conducting a prototype demonstration in space (TRL-7). This challenge is com- pounded by the relatively low availability of new spacecraft missions when compared with aeronautical craft to bridge this gap, leading to the general adoption of a low-risk stance by mission management to accept new, unproven technologies into the system. Also in consideration of risk, the limited selection and availability of proven space-grade components imparts a severe limitation on achieving high performance systems by current terrestrial technology standards. Finally from a space communications point of view the long duration characteristic of most missions imparts a major constraint on the entire space and ground network architecture, since any new technologies introduced into the system would have to be compliant with the duration of the currently deployed operational technologies, and in some cases may be limited by surrounding legacy capabilities. Beyond ensuring that the new technology is verified to function correctly and validated to meet the needs of the end users the formidable challenge then grows to additionally include: carefully timing the maturity path of the new technology to coincide with a feasible and accepting future mission so it flies before its relevancy has passed, utilizing a limited catalog of available components to their maximum potential to create meaningful and unprecedented new capabilities, designing and ensuring interoperability with aging space and ground infrastructures while simultaneously providing a growth path to the future. The International Space Station (ISS) is approaching 20 years of age. To keep the ISS relevant, technology upgrades are continuously taking place. Regarding communications, the state-of-the-art communication system upgrades underway include high-rate laser terminals. These must interface with the existing, aging data infrastructure. The High Data Rate Architecture (HiDRA) project is designed to provide networked store, carry, and forward capability to optimize data flow through both the existing radio frequency (RF) and new laser communications terminal. The networking capability is realized through the Delay Tolerant Networking (DTN) protocol, and is used for scheduling data movement as well as optimizing the performance of existing RF channels. HiDRA is realized as a distributed FPGA memory and interface controller that is itself controlled by a local computer running DTN software. Thus HiDRA is applicable to other arenas seeking to employ next-generation communications technologies, e.g. deep space. In this paper, we describe HiDRA and its far-reaching research implications.

DTN↗

Updates to NASA’s Break-in-Prebreathe Rules Due to Type II Decompression Sickness Risk Considerations

INTRODUCTION. Investigation of a central neurological decompression sickness (DCS) case during ground testing at Johnson Space Center identified a break-in-prebreathe (BIP) 13 minutes prior to depressurization as the leading credible cause despite applicable prebreathe payback rules being followed. Applicable NASA rules, for ground and flight, directed 2:1 payback of breaks up to 10 mins in duration, regardless of when a break occurs relative to depress. Full restart of prebreathe is directed following breaks > 10 min. The adequacy of NASA’s BIP rules was evaluated prior to resuming hypobaric ground testing or ISS extravehicular activities. METHODS. The following information sources were reviewed prior to formulating recommendations: i) Type II DCS case report and investigation findings; ii) documented rationale for existing flight rules, iii) consultations with subject matter experts involved in definition of existing flight rules (several of whom had since left NASA), iv) relevant published literature, v) model estimates of tissue on-gassing and off-gassing, and vi) NASA’s operational experience with late breaks in prebreathe. RESULTS. NASA’s nominal prebreathe protocols are validated via extensive ground testing to ensure DCS risk is reduced to within acceptable limits. Conversely, there exists a paucity of data, no validated models, and limited documentation regarding BIP risk for NASA prebreathe protocols. Flight rules implemented for shuttle and later ISS are based primarily on expert opinion and an assumption of symmetric on-gassing and off-gassing, which would make 2:1 payback a conservative mitigation for a BIP. Assumption of exponential gas kinetics makes late breaks higher risk, or require greater payback, than earlier breaks. Two BIPs have occurred using the current ISS prebreathe protocol, each of which was followed by greater than 2:1 payback and at least 59 minutes of 100% O2 pre-depress. No DCS cases have been reported during shuttle or ISS EVA operations. DISCUSSION. Interim changes were implemented to protect against late breaks during ground and flight prebreathes by ensuring negligible difference in conservatively modeled ppN2 pre-depress compared to nominal validated protocols. Additional documentation and literature review as well as chamber test planning are ongoing with the objective of further ground and flight rule updates and validation of a BIP risk model.

Prebreathe↗

Updates to NASA’s Break-in-Prebreathe Rules Due to Type II Decompression Sickness Risk Considerations

INTRODUCTION. Investigation of a central neurological decompression sickness (DCS) case during ground testing at Johnson Space Center identified a break-in-prebreathe (BIP) 13 minutes prior to depressurization as the leading credible cause despite applicable prebreathe payback rules being followed. Applicable NASA rules, for ground and flight, directed 2:1 payback of breaks up to 10 mins in duration, regardless of when a break occurs relative to depress. Full restart of prebreathe is directed following breaks > 10 min. The adequacy of NASA’s BIP rules was evaluated prior to resuming hypobaric ground testing or ISS extravehicular activities. METHODS. The following information sources were reviewed prior to formulating recommendations: i) Type II DCS case report and investigation findings; ii) documented rationale for existing flight rules, iii) consultations with subject matter experts involved in definition of existing flight rules (several of whom had since left NASA), iv) relevant published literature, v) model estimates of tissue on-gassing and off-gassing, and vi) NASA’s operational experience with late breaks in prebreathe. RESULTS. NASA’s nominal prebreathe protocols are validated via extensive ground testing to ensure DCS risk is reduced to within acceptable limits. Conversely, there exists a paucity of data, no validated models, and limited documentation regarding BIP risk for NASA prebreathe protocols. Flight rules implemented for shuttle and later ISS are based primarily on expert opinion and an assumption of symmetric on-gassing and off-gassing, which would make 2:1 payback a conservative mitigation for a BIP. Assumption of exponential gas kinetics makes late breaks higher risk, or require greater payback, than earlier breaks. Two BIPs have occurred using the current ISS prebreathe protocol, each of which was followed by greater than 2:1 payback and at least 59 minutes of 100% O2 pre-depress. No DCS cases have been reported during shuttle or ISS EVA operations. DISCUSSION. Interim changes were implemented to protect against late breaks during ground and flight prebreathes by ensuring negligible difference in conservatively modeled ppN2 pre-depress compared to nominal validated protocols. Additional documentation and literature review as well as chamber test planning are ongoing with the objective of further ground and flight rule updates and validation of a BIP risk model.

Prebreathe↗

Recommended Screening Practices for Launch Collision Aviodance

The objective of this document is to assess the value of launch collision avoidance (COLA) practices and provide recommendations regarding its implementation for NASA robotic missions. The scope of this effort is limited to launch COLA screens against catalog objects that are either spacecraft or debris. No modifications to manned safety COLA practices are considered in this effort. An assessment of the value of launch COLA can be broken down into two fundamental questions: 1) Does collision during launch represent a significant risk to either the payload being launched or the space environment? 2) Can launch collision mitigation be performed in a manner that provides meaningful risk reduction at an acceptable level of operational impact? While it has been possible to piece together partial answers to these questions for some time, the first attempt to comprehensively address them is documented in reference (a), Launch COLA Operations: an Examination of Data Products, Procedures, and Thresholds, Revision A. This report is the product of an extensive study that addressed fundamental technical questions surrounding launch collision avoidance analysis and practice. The results provided in reference (a) will be cited throughout this document as these two questions are addressed. The premise of this assessment is that in order to conclude that launch COLA is a value-added activity, the answer to both of these questions must be affirmative. A "no" answer to either of these questions points toward the conclusion that launch COLA provides little or no risk mitigation benefit. The remainder of this assessment will focus on addressing these two questions.

recommended screening practicies luanch collision ↗

An Assessment of the Efficacy of Launch Collision Avoidance Analysis in Providing Risk Reduction for NASA

The objective of this document is to assess the value of collision on launch assessment (COLA, often referred to as “launch COLA”) practices and provide recommendations regarding its implementation for NASA robotic missions. The scope of this effort is limited to launch COLA screens against catalog objects that are either spacecraft or debris. No modifications to manned safety launch COLA practices are considered in this effort. An assessment of the value of launch COLA can be broken down into two fundamental questions: 1) Does collision during launch represent a significant risk to either the payload being launched or the space environment? 2) Can launch collision mitigation be performed in a manner that provides meaningful risk reduction at an acceptable level of operational impact? While it has been possible to piece together partial answers to these questions for some time, the first attempt to comprehensively address them is documented in reference (a), Launch COLA Operations: an Examination of Data Products, Procedures, and Thresholds, Revision A. This report is the product of an extensive study that addressed fundamental technical questions surrounding launch collision avoidance analysis and practice. The results provided in reference (a) will be cited throughout this document as these two questions are addressed. The premise of this assessment is that in order to conclude that launch COLA is a value-added activity, the answer to both of these questions must be affirmative. A “no” answer to either of these questions points toward the conclusion that launch COLA provides little or no risk mitigation benefit. The remainder of this assessment will focus on addressing these two questions.

launch COLA↗

An Evidenced-Based Approach for Estimating Decompression Sickness Risk in Aircraft Operations

Estimating the risk of decompression Sickness (DCS) in aircraft operations remains a challenge, making the reduction of this risk through the development of operationally acceptable denitrogenation schedules difficult. In addition, the medical recommendations which are promulgated are often not supported by rigorous evaluation of the available data, but are instead arrived at by negotiation with the aircraft operations community, are adapted from other similar aircraft operations, or are based upon the opinion of the local medical community. We present a systematic approach for defining DCS risk in aircraft operations by analyzing the data available for a specific aircraft, flight profile, and aviator population. Once the risk of DCS in a particular aircraft operation is known, appropriate steps can be taken to reduce this risk to a level acceptable to the applicable aviation community. Using this technique will allow any aviation medical community to arrive at the best estimate of DCS risk for its specific mission and aviator population and will allow systematic reevaluation of the decisions regarding DCS risk reduction when additional data are available.

Robinson, Ronald R.↗

A decade of progress in understanding and managing legacy well integrity for geologic carbon storage

This study reviews a decade of research progress in legacy well integrity and risk management for geologic carbon storage (GCS) to commemorate the 20 th anniversary of the Intergovernmental Panel on Climate Change’s 2005 Special Report on Carbon Capture and Storage. In the past ten years, legacy well research has benefited from global efforts to constrain emissions from abandoned oil and gas wells, a continued focus on well materials performance in the presence of CO 2 -rich fluids, and practical experience gained through GCS implementation. Field measurements of abandoned well emissions show that leakage is not universal or catastrophic but forms a continuum of low-to-moderate fluxes that depend on isolation integrity and environmental attenuation. Materials research has constrained the conditions under which Portland cements exhibit self-sealing and non-sealing behaviors, and has identified the impact of geomechanical properties, non-uniform pathway apertures, multi-phase flow, and impurities in the CO 2 stream, on leakage pathways as important new areas for investigation. GCS projects at brownfield sites have inspired the creation of new workflows that integrate various tools and technologies to manage legacy well leakage risks. GCS implementation has also motivated a push towards scenario-based well modeling that directly informs permit applications. These advances inspire new research questions for the coming decade, particularly around the level of legacy well leakage risk that is environmentally acceptable and tolerable to stakeholders when sequestering millions of tonnes of CO 2 annually.

Carbon capture and storage↗

Addressing Human System Risks to Future Space Exploration

NASA is contemplating future human exploration missions to destinations beyond low Earth orbit, including the Moon, deep-space asteroids, and Mars. While we have learned much about protecting crew health and performance during orbital space flight over the past half-century, the challenges of these future missions far exceed those within our current experience base. To ensure success in these missions, we have developed a Human System Risk Board (HSRB) to identify, quantify, and develop mitigation plans for the extraordinary risks associated with each potential mission scenario. The HSRB comprises research, technology, and operations experts in medicine, physiology, psychology, human factors, radiation, toxicology, microbiology, pharmacology, and food sciences. Methods: Owing to the wide range of potential mission characteristics, we first identified the hazards to human health and performance common to all exploration missions: altered gravity, isolation/confinement, increased radiation, distance from Earth, and hostile/closed environment. Each hazard leads to a set of risks to crew health and/or performance. For example the radiation hazard leads to risks of acute radiation syndrome, central nervous system dysfunction, soft tissue degeneration, and carcinogenesis. Some of these risks (e.g., acute radiation syndrome) could affect crew health or performance during the mission, while others (e.g., carcinogenesis) would more likely affect the crewmember well after the mission ends. We next defined a set of design reference missions (DRM) that would span the range of exploration missions currently under consideration. In addition to standard (6-month) and long-duration (1-year) missions in low Earth orbit (LEO), these DRM include deep space sortie missions of 1 month duration, lunar orbital and landing missions of 1 year duration, deep space journey and asteroid landing missions of 1 year duration, and Mars orbital and landing missions of 3 years duration. We then assessed the likelihood and consequences of each risk against each DRM, using three levels of likelihood (Low: less than or equal to 0.1%; Medium: 0.1%–1.0%; High: greater than or equal to 1.0%) and four levels of consequence ranging from Very Low (temporary or insignificant) to High (death, loss of mission, or significant reduction to length or quality of life). Quantitative evidence from clinical, operational, and research sources were used whenever available. Qualitative evidence was used when quantitative evidence was unavailable. Expert opinion was used whenever insufficient evidence was available. Results: A set of 30 risks emerged that will require further mitigation efforts before being accepted by the Agency. The likelihood by consequence risk assessment process provided a means of prioritizing among the risks identified. For each of the high priority risks, a plan was developed to perform research, technology, or standards development thought necessary to provide suitable reduction of likelihood or consequence to allow agency acceptance. Conclusion: The HSRB process has successfully identified a complete set of risks to human space travelers on planned exploration missions based on the best evidence available today. Risk mitigation plans have been established for the highest priority risks. Each risk will be reassessed annually to track the progress of our risk mitigation efforts.

Paloski, W. H.↗

Evaluating Technology Adoption Risks in Early-Stage Materials Research

Development of new technologies often begins with fundamental materials science research. Decisions at this stage can shape factors related to the eventual adoption readiness of the technology, such as process scalability or materials availability. Here we present the early-Stage Technology Evaluation for Adoption Risks (STEAR) framework as a method for qualitatively assessing metrics spanning four categories of adoption risks: value proposition, market acceptance, resource maturity, and license to operate. We conduct a case study applying STEAR to different methanol production processes at a range of technology readiness levels and demonstrate how the assessment identifies key challenges related to adoption readiness. Finally, we discuss efforts to expand the applicability and utility of STEAR, including focus group feedback and complementary quantitative analysis methods.

36 MATERIALS SCIENCE↗

The selection of imaging systems for planetary photography from space vehicles.

Discussion of the selection of a type of imaging system for a specific mission which will maximize the return of scientific data while keeping development risk and cost to acceptable limits. A representative example is given which shows that the parameters of the optimizing process range from the scientific objectives through the engineering and programming constraints of the spacecraft and mission, to the characteristics of the types of systems. The selections for all planetary missions flown to date have been imaging systems using image tube cameras. Film cameras and mechanical scan cameras, however, have unique advantages which should find application in planetary exploration.

Smokler, M. I.↗

Report to the administrator by the NASA Aerospace Safety Advisory Panel on the Skylab program. Volume 1: Summary report

Contractor and NASA technical management for the development and manufacture of the Skylab modules is reviewed with emphasis on the following management controls: configuration and interface management; vendor control; and quality control of workmanship. A review of the modified two-stage Saturn V launch vehicle which focused on modifications to accommodate the Skylab payload; resolution of prior flight anomalies; and changes in personnel and management systems is presented along with an evaluation of the possible age-life and storage problems for the Saturn 1-B launch vehicle. The NASA program management's visibility and control of contractor operations, systems engineering and integration, the review process for the evaluation of design and flight hardware, and the planning process for mission operations are investigated. It is concluded that the technical management system for development and fabrication of the modules, spacecraft, and launch vehicles, the process of design and hardware acceptance reviews, and the risk assessment activities are satisfactory. It is indicated that checkout activity, integrated testing, and preparations for and execution of mission operation require management attention.

Source record↗