Search NASA⌕ Search

SEARCH · Search NASA

Results for “Engineering Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Nondeterministic Approaches and Their Potential for Future Aerospace Systems

This document contains the proceedings of the Training Workshop on Nondeterministic Approaches and Their Potential for Future Aerospace Systems held at NASA Langley Research Center, Hampton, Virginia, May 30-3 1, 2001. The workshop was jointly sponsored by Old Dominion University's Center for Advanced Engineering Environments and NASA. Workshop attendees were from NASA, other government agencies, industry, and universities. The objectives of the workshop were to give overviews of the diverse activities in nondeterministic approaches, uncertainty management methodologies, reliability assessment and risk management techniques, and to identify their potential for future aerospace systems.

Ahmed K Noor↗

Anatomy of a Security Operations Center

Many agencies and corporations are either contemplating or in the process of building a cyber Security Operations Center (SOC). Those Agencies that have established SOCs are most likely working on major revisions or enhancements to existing capabilities. As principle developers of the NASA SOC; this Presenters' goals are to provide the GFIRST community with examples of some of the key building blocks of an Agency scale cyber Security Operations Center. This presentation viII include the inputs and outputs, the facilities or shell, as well as the internal components and the processes necessary to maintain the SOC's subsistence - in other words, the anatomy of a SOC. Details to be presented include the SOC architecture and its key components: Tier 1 Call Center, data entry, and incident triage; Tier 2 monitoring, incident handling and tracking; Tier 3 computer forensics, malware analysis, and reverse engineering; Incident Management System; Threat Management System; SOC Portal; Log Aggregation and Security Incident Management (SIM) systems; flow monitoring; IDS; etc. Specific processes and methodologies discussed include Incident States and associated Work Elements; the Incident Management Workflow Process; Cyber Threat Risk Assessment methodology; and Incident Taxonomy. The Evolution of the Cyber Security Operations Center viII be discussed; starting from reactive, to proactive, and finally to proactive. Finally, the resources necessary to establish an Agency scale SOC as well as the lessons learned in the process of standing up a SOC viII be presented.

Wang, John↗

Recommendations on Use of Commercial-Off-The-Shelf (COTS) Electrical, Electronic, and Electromechanical (EEE) Parts for NASA Missions

The NASA Electronic Parts & Packaging Program Manager, requested a NASA Engineering and Safety Center independent assessment to summarize Commercial Crew Program and NASA Centers’ current and best practices, and lessons learned, on use of commercial-off-the-shelf (COTS) for all mission risk classifications, and provide recommendations that could lead to future NASA Electronic Parts and Packaging Program and/or Agency guidance on COTS parts. This document contains the outcome of the assessment.

Commercial-Off-The-Shelf↗

Technical Risks Associated with Heat Melt Compaction Systems

The processing of trash and waste is a welcome and valuable addition to humans living and working in space. Besides the obvious desire to have a pleasant and productive habitation environment, trash management has many practicalbenefits for crew health, resource recovery, and volume reclamation through garbage compaction. The Trash Compaction and Processing System (TCPS), which is a NASA project to develop a trash processing system for long-duration spaceflight, is currently undergoing concept development with engineering prototype validation through two contracted efforts. The development efforts are being supported with activities associated with the NASA Generation 2 Heat Melt Compactor (HMC). The HMC is a facility that compacts trash, recovers water, heats the trash to eliminate biological activity, and manages gas and vapor effluents. The resulting residual processed trash is a compact tile that is free of biological growth and that can be used for augmenting radiation shields. The work being conducted with the HMC focuses on high risk technical areas with respect to operations, subsystem performance, and ISS effluent management interface requirements. This paper gives an overview of the technical risks and the current use of the HMC as a facility for reducing risk.

HMC↗

Cassini Information Management System in Distributed Operations Collaboration and Cassini Science Planning

Launched on October 15, 1997, the Cassini-Huygens spacecraft began its ambitious journey to the Saturnian system with a complex suite of 12 scientific instruments, and another 6 instruments aboard the European Space Agencies Huygens Probe. Over the next 6 1/2 years, Cassini would continue its relatively simplistic cruise phase operations, flying past Venus, Earth, and Jupiter. However, following Saturn Orbit Insertion (SOI), Cassini would become involved in a complex series of tasks that required detailed resource management, distributed operations collaboration, and a data base for capturing science objectives. Collectively, these needs were met through a web-based software tool designed to help with the Cassini uplink process and ultimately used to generate more robust sequences for spacecraft operations. In 2001, in conjunction with the Southwest Research Institute (SwRI) and later Venustar Software and Engineering Inc., the Cassini Information Management System (CIMS) was released which enabled the Cassini spacecraft and science planning teams to perform complex information management and team collaboration between scientists and engineers in 17 countries. Originally tailored to help manage the science planning uplink process, CIMS has been actively evolving since its inception to meet the changing and growing needs of the Cassini uplink team and effectively reduce mission risk through a series of resource management validation algorithms. These algorithms have been implemented in the web-based software tool to identify potential sequence conflicts early in the science planning process. CIMS mitigates these sequence conflicts through identification of timing incongruities, pointing inconsistencies, flight rule violations, data volume issues, and by assisting in Deep Space Network (DSN) coverage analysis. In preparation for extended mission operations, CIMS has also evolved further to assist in the planning and coordination of the dual playback redundancy of highvalue data from targets such as Titan and Enceladus. This paper will outline the critical role that CIMS has played for Cassini in the distributed ops paradigm throughout operations. This paper will also examine the evolution that CIMS has undergone in the face of new science discoveries and fluctuating operational needs. And finally, this paper will conclude with theoretical adaptation of CIMS for other projects and the potential savings in cost and risk reduction that could potentially be tapped into by future missions.

Equils, Douglas J.↗

Reliability and Failure in NASA Missions: Blunders, Normal Accidents, High Reliability, Bad Luck

NASA emphasizes crew safety and system reliability but several unfortunate failures have occurred. The Apollo 1 fire was mistakenly unanticipated. After that tragedy, the Apollo program gave much more attention to safety. The Challenger accident revealed that NASA had neglected safety and that management underestimated the high risk of shuttle. Probabilistic Risk Assessment was adopted to provide more accurate failure probabilities for shuttle and other missions. NASA's "faster, better, cheaper" initiative and government procurement reform led to deliberately dismantling traditional reliability engineering. The Columbia tragedy and Mars mission failures followed. Failures can be attributed to blunders, normal accidents, or bad luck. Achieving high reliability is difficult but possible.

accidents↗

Constraint and Flight Rule Management for Space Mission Operations

The exploration of space is one of the most fascinating domains to study from a human factors perspective. Like other complex work domains such as aviation (Pritchett and Kim, 2008), air traffic management (Durso and Manning, 2008), health care (Morrow, North, and Wickens, 2006), homeland security (Cooke and Winner, 2008), and vehicle control (Lee, 2006), space exploration is a large-scale sociotechnical work domain characterized by complexity, dynamism, uncertainty, and risk in real-time operational contexts (Perrow, 1999; Woods et al, 1994). Nearly the entire gamut of human factors issues - for example, human-automation interaction (Sheridan and Parasuraman, 2006), telerobotics, display and control design (Smith, Bennett, and Stone, 2006), usability, anthropometry (Chaffin, 2008), biomechanics (Marras and Radwin, 2006), safety engineering, emergency operations, maintenance human factors, situation awareness (Tenney and Pew, 2006), crew resource management (Salas et al., 2006), methods for cognitive work analysis (Bisantz and Roth, 2008) and the like -- are applicable to astronauts, mission control, operational medicine, Space Shuttle manufacturing and assembly operations, and space suit designers as they are in other work domains (e.g., Bloomberg, 2003; Bos et al, 2006; Brooks and Ince, 1992; Casler and Cook, 1999; Jones, 1994; McCurdy et al, 2006; Neerincx et aI., 2006; Olofinboba and Dorneich, 2005; Patterson, Watts-Perotti and Woods, 1999; Patterson and Woods, 2001; Seagull et ai, 2007; Sierhuis, Clancey and Sims, 2002). The human exploration of space also has unique challenges of particular interest to human factors research and practice. This chapter provides an overview of those issues and reports on some of the latest research results as well as the latest challenges still facing the field.

Barreiro, J.↗

Human Factors in Space Exploration

The exploration of space is one of the most fascinating domains to study from a human factors perspective. Like other complex work domains such as aviation (Pritchett and Kim, 2008), air traffic management (Durso and Manning, 2008), health care (Morrow, North, and Wickens, 2006), homeland security (Cooke and Winner, 2008), and vehicle control (Lee, 2006), space exploration is a large-scale sociotechnical work domain characterized by complexity, dynamism, uncertainty, and risk in real-time operational contexts (Perrow, 1999; Woods et ai, 1994). Nearly the entire gamut of human factors issues - for example, human-automation interaction (Sheridan and Parasuraman, 2006), telerobotics, display and control design (Smith, Bennett, and Stone, 2006), usability, anthropometry (Chaffin, 2008), biomechanics (Marras and Radwin, 2006), safety engineering, emergency operations, maintenance human factors, situation awareness (Tenney and Pew, 2006), crew resource management (Salas et aI., 2006), methods for cognitive work analysis (Bisantz and Roth, 2008) and the like -- are applicable to astronauts, mission control, operational medicine, Space Shuttle manufacturing and assembly operations, and space suit designers as they are in other work domains (e.g., Bloomberg, 2003; Bos et al, 2006; Brooks and Ince, 1992; Casler and Cook, 1999; Jones, 1994; McCurdy et ai, 2006; Neerincx et aI., 2006; Olofinboba and Dorneich, 2005; Patterson, Watts-Perotti and Woods, 1999; Patterson and Woods, 2001; Seagull et ai, 2007; Sierhuis, Clancey and Sims, 2002). The human exploration of space also has unique challenges of particular interest to human factors research and practice. This chapter provides an overview of those issues and reports on sorne of the latest research results as well as the latest challenges still facing the field.

FROM↗

Digital Assurance for High Consequence Systems: 2024 Mission Campaign White Paper

This Sandia National Laboratories Mission Campaign (MC) seeks to create the technical basis that allows national leaders to efficiently assess and manage the digital assurance of high consequence systems. We will call for transformative research that enables efficient (1) development of provably secure systems and secure integration of untrusted products, (2) intelligent threat mitigation, and (3) digital risk-informed engineering trade-offs. Ultimately, this MC will impact multiple national security missions; it will develop an informed Digital Assurance for High Consequence Systems (DAHCS) community and expand Sandia partnerships to build this national capability.

97 MATHEMATICS AND COMPUTING↗

Report to the NASA Administrator by the Aerospace Safety Advisory Panel on the Space Shuttle Program. Part 1: Observations and Conclusions

Each system was chosen on the basis of its importance with respect to crew safety and mission success. An overview of the systems management is presented. The space shuttle main engine, orbiter thermal protection system, avionics, external tanks and solid rocket boosters were examined. The ground test and ground support equipment programs were studied. Program management was found to have an adequate understanding of the significant ground and flight risks involved.

Source record↗

Making the Hubble Space Telescope servicing mission safe

The implementation of the HST system safety program is detailed. Numerous safety analyses are conducted through various phases of design, test, and fabrication, and results are presented to NASA management for discussion during dedicated safety reviews. Attention is given to the system safety assessment and risk analysis methodologies used, i.e., hazard analysis, fault tree analysis, and failure modes and effects analysis, and to how they are coupled with engineering and test analysis for a 'synergistic picture' of the system. Some preliminary safety analysis results, showing the relationship between hazard identification, control or abatement, and finally control verification, are presented as examples of this safety process.

Bahr, N. J.↗

Making the Hubble Space Telescope servicing mission safe

This paper will detail how the Hubble Space Telescope (HST) system safety program is conducted. Numerous safety analyses are conducted through the various phases of design, test, and fabrication, and results are presented to NASA management for discussion during dedicated safety reviews. This paper will then address the system safety assessment and risk analysis methodologies used (i.e. hazard analysis, fault tree analysis, and failure modes and effects analysis), and how they are coupled with enginering and test analyses for a 'synergistic picture' of the system. Some preliminary safety analysis results, showing the relationship between hazard identification, control or abatement, and finally control verification, will be presented as examples of this safety process.

Bahr, N. J.↗

NEXT Single String Integration Test Results

As a critical part of NASA's Evolutionary Xenon Thruster (NEXT) test validation process, a single string integration test was performed on the NEXT ion propulsion system. The objectives of this test were to verify that an integrated system of major NEXT ion propulsion system elements meets project requirements, to demonstrate that the integrated system is functional across the entire power processor and xenon propellant management system input ranges, and to demonstrate to potential users that the NEXT propulsion system is ready for transition to flight. Propulsion system elements included in this system integration test were an engineering model ion thruster, an engineering model propellant management system, an engineering model power processor unit, and a digital control interface unit simulator that acted as a test console. Project requirements that were verified during this system integration test included individual element requirements ; integrated system requirements, and fault handling. This paper will present the results of these tests, which include: integrated ion propulsion system demonstrations of performance, functionality and fault handling; a thruster re-performance acceptance test to establish baseline performance: a risk-reduction PMS-thruster integration test: and propellant management system calibration checks.

Soulas, George C.↗

Engine management during NTRE start up

The topics are presented in viewgraph form and include the following: total engine system management critical to successful nuclear thermal rocket engine (NTRE) start up; NERVA type engine start windows; reactor power control; heterogeneous reactor cooling; propellant feed system dynamics; integrated NTRE start sequence; moderator cooling loop and efficient NTRE starting; analytical simulation and low risk engine development; accurate simulation through dynamic coupling of physical processes; and integrated NTRE and mission performance.

Bulman, Mel↗

Human Research Program: 2012 Fiscal Year Annual Report

Crew health and performance are critical to successful human exploration beyond low Earth orbit. Risks to health and performance include physiologic effects from radiation, hypogravity, and planetary environments, as well as unique challenges in medical treatment, human factors, and support of behavioral health. The scientists and engineers of the Human Research Program (HRP) investigate and reduce the greatest risks to human health and performance, and provide essential countermeasures and technologies for human space exploration. In its seventh year of operation, the HRP continued to refine its management architecture of evidence, risks, gaps, tasks, and deliverables. Experiments continued on the International Space Station (ISS), on the ground in analog environments that have features similar to those of spaceflight, and in laboratory environments. Data from these experiments furthered the understanding of how the space environment affects the human system. These research results contributed to scientific knowledge and technology developments that address the human health and performance risks. As shown in this report, HRP has made significant progress toward developing medical care and countermeasure systems for space exploration missions which will ultimately reduce risks to crew health and performance.

Effenhauser, Laura↗

Modeling and Analysis of Chill and Fill Processes for the EDU Tank

NASA's future missions may require long-term storage and transfer of cryogenic propellants. The Engineering Development Unit (EDU), a NASA in-house effort supported by both Marshall Space Flight Center (MSFC) and Glenn Research Center (GRC), is a Cryogenic Fluid Management (CFM) test article that primarily serves as a manufacturing pathfinder and a risk reduction task for a future CFM payload. The EDU test article, comprises a flight like tank, internal components, insulation, and attachment struts. The EDU is designed to perform integrated passive thermal control performance testing with liquid hydrogen in a space-like vacuum environment. A series of tests, with liquid hydrogen as a testing fluid, was conducted at Test Stand 300 at MSFC during summer of 2014. The objective of this effort was to develop a thermal/fluid model for evaluating the thermodynamic behavior of the EDU tank during the chill and fill processes. Generalized Fluid System Simulation Program (GFSSP), an MSFC in-house general-purpose computer program for flow network analysis, was utilized to model and simulate the chill and fill portion of the testing. The model contained the liquid hydrogen supply source, feed system, EDU tank, and vent system. The modeling description and comparison of model predictions with the test data will be presented in the final paper.

Hedayat, A.↗

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE↗

Method for Tracking and Communicating Aggregate Risk Through the Use of Model-Based Systems Engineering (MBSE) Tools

Large, complex projects can identify a significant number and variety of risks, throughout the project life cycle. These risks are analyzed, mitigated, closed or accepted as independent uncertainties. Once closed or accepted, it is easy for projects to lose awareness of their impact. In reality, each of these risks contributes some amount to the overall risk posture of the project. The ability to track and effectively communicate this aggregate risk has represented a challenge to project management. There have been previous attempts to create a schema to communicate the aggregate effect of risks, without notable success. Most of these attempts have centered on some additive metric derived from the scoring of likelihood and consequence values. This, in and of itself, is a logical approach, but all too often the scores were then aggregated to a level where all context was lost. One weakness has been a lack of attempt to create linkages or logical groups of the risks upon which useful aggregation could then occur. The overall move to model-based (systems) engineering (MBSE) has opened up a vast frontier of opportunities to better integrate all project data. MBSE provides an underlying layer that links data items to each other. Objectives link to requirements, which then link to functions, functions to physical architecture items, and so on, as far down as projects want to model. While it started with a focus on modeling requirements based on things like use cases, efforts are now underway to integrate safety and mission assurance (S&MA) information and analyses, such as risks. This effort, called Model Based Mission Assurance (MBMA), is yielding models that are more useful and are a more accurate representations of the systems. MBSE models, with this ability to link related items, provide a new means of tracking and communicating aggregate risks. In the proposed method, risks are added into the models as distinct items, having attributes that communicate a scoring derived from the likelihood and consequence values as charted on the standard NASA 5x5 risk matrix. Like earlier efforts, each box in the 5x5 has an associated scoring, which may include both a current score and potential post-mitigation/control score. The risk items are then linked to elements of the model, such as system objectives/goals, requirements, functions, or physical architecture items, with "Risk to" relationships. These risks will then be communicated by use of reports generated from the model, detailing all risks and/or hazards linked to model elements. These reports can include aggregate impacts, including a current scoring and potential future state scoring based on the planned mitigations and/or controls. These reports will show all risks, open, accepted, and closed, linked to project objectives or requirements. When run as part of an upcoming risk acceptance discussion, these reports will serve to remind the team of all previous risks that relate to the effected portion of the system. When included as part of periodic program or project reviews, risk reviews, and safety reviews, this method can improve the overall understanding of the system's true risk posture. This proposed method takes full advantage of the advances that modern modeling techniques provide, with a minimal investment of additional time. Utilizing the model environment also enables a near constant access to current state of aggregate risks.

model based mission assurance↗