Search NASA⌕ Search

SEARCH · Search NASA

Results for “Mitigation Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Joint inference of multiplicative and additive systematics in galaxy density fluctuations and clustering measurements

Galaxy clustering measurements are a key probe of the matter density field in the Universe. With the era of precision cosmology upon us, surveys rely on precise measurements of the clustering signal for meaningful cosmological analysis. However, the presence of systematic contaminants can bias the observed galaxy number density, and thereby bias the galaxy two-point statistics. As the statistical uncertainties get smaller, correcting for these systematic contaminants becomes increasingly important for unbiased cosmological analysis. We present and validate a new method for understanding and mitigating both additive and multiplicative systematics in galaxy clustering measurements (two-point function) by joint inference of contaminants in the galaxy overdensity field (one-point function) using a maximum-likelihood estimator (MLE). We test this methodology with Kilo-Degree Survey-like mock galaxy catalogues and synthetic systematic template maps. We estimate the cosmological impact of such mitigation by quantifying uncertainties and possible biases in the inferred relationship between the observed and the true galaxy clustering signal. Our method robustly corrects the clustering signal to the sub-percent level and reduces numerous additive and multiplicative systematics from 1.5σ to less than 0.1σ for the scenarios we tested. In addition, we provide an empirical approach to identifying the functional form (additive, multiplicative, or other) by which specific systematics contaminate the galaxy number density. Even though this approach is tested and geared towards systematics contaminating the galaxy number density, the methods can be extended to systematics mitigation for other two-point correlation measurements.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

NASA CARA Prelaunch Analysis and Process

NASA implemented an official Procedural Requirement (NPR) 8079.1 in June 2023, establishing the minimum collision avoidance requirements and associated operational protocols for NASA space flight programs, projects, and spacecraft to protect the space environment by reducing the risk of collision to an acceptable level. Part of the requirement employs a two-fold approach to analyze the satellite design process with conjunction assessment and risk mitigation in mind, during the pre-launch process, led by the Conjunction Assessment Risk Analysis (CARA) Program for non-Human Space Flight (HSF) Missions. This presentation outlines CARA coordination with missions, informed by the NPR, that spans early mission development to operations. CARA is an Agency-level resource that provides support to all NASA non-HSF missions. CARA protects the orbital environment from collision between NASA non-HSF missions and other tracked on-orbit objects. During the pre-formulation and formulation phases, NASA missions undergo a series of conjunction assessment analyses captured in the Orbital Collision Avoidance Plan (OCAP) prior to transitioning to the implementation phase (typically at the Preliminary Design Review (PDR) or equivalent). The OCAP analyses consist of a thorough review of the spacecraft(s) orbit selection and placement, deployment, cataloguing performance, trackability, ephemeris generation, conjunction mitigation options, autonomous maneuvering, and risk assessment parameters which are performed by a dedicated CARA Analysis Team. The results of these analyses, CARA’s formal recommendations, and the mission’s methods for implementing them, are documented in the OCAP. The intent of engaging in this process so early in the mission design phase, is to ensure that conjunction assessment is considered from the outset, thus mitigating costly design changes and operational risks down the road. NASA missions are also required to coordinate their operational processes and conjunction mitigation procedures with CARA in a Conjunction Assessment Operations Implementation Agreement (CAOIA). The aim of this process is to document the conjunction assessment screening process, conjunction risk assessment parameters, conjunction mitigation steps, flight dynamics operations concepts and maneuvers, and the communication and coordination process between the mission’s project manager and CARA. The intent of the CAOIA document is for it to be completed iteratively, and as missions update these elements, corresponding changes are made in the CAOIA. With this process in place, the engagement and coordination between the missions and CARA from early in the design process into mission operations, helps to ensure that missions not only have a robust conjunction assessment concept of operations to reduce conjunction risk for space sustainability, but are also able to achieve their science goals and have a successful mission.

conjunction assessment↗

NASA CARA Prelaunch Analysis and Process

NASA implemented an official Procedural Requirement (NPR) 8079.1 in June 2023, establishing the minimum collision avoidance requirements and associated operational protocols for NASA space flight programs, projects, and spacecraft to protect the space environment by reducing the risk of collision to an acceptable level. Part of the requirement employs a two-fold approach to analyze the satellite design process with conjunction assessment and risk mitigation in mind, during the pre-launch process, led by the Conjunction Assessment Risk Analysis (CARA) Program for non-Human Space Flight (HSF) Missions. This presentation outlines CARA coordination with missions, informed by the NPR, that spans early mission development to operations. CARA is an Agency-level resource that provides support to all NASA non-HSF missions. CARA protects the orbital environment from collision between NASA non-HSF missions and other tracked on-orbit objects. During the pre-formulation and formulation phases, NASA missions undergo a series of conjunction assessment analyses captured in the Orbital Collision Avoidance Plan (OCAP) prior to transitioning to the implementation phase (typically at the Preliminary Design Review (PDR) or equivalent). The OCAP analyses consist of a thorough review of the spacecraft(s) orbit selection and placement, deployment, cataloguing performance, trackability, ephemeris generation, conjunction mitigation options, autonomous maneuvering, and risk assessment parameters which are performed by a dedicated CARA Analysis Team. The results of these analyses, CARA’s formal recommendations, and the mission’s methods for implementing them, are documented in the OCAP. The intent of engaging in this process so early in the mission design phase, is to ensure that conjunction assessment is considered from the outset, thus mitigating costly design changes and operational risks down the road. NASA missions are also required to coordinate their operational processes and conjunction mitigation procedures with CARA in a Conjunction Assessment Operations Implementation Agreement (CAOIA). The aim of this process is to document the conjunction assessment screening process, conjunction risk assessment parameters, conjunction mitigation steps, flight dynamics operations concepts and maneuvers, and the communication and coordination process between the mission’s project manager and CARA. The intent of the CAOIA document is for it to be completed iteratively, and as missions update these elements, corresponding changes are made in the CAOIA. With this process in place, the engagement and coordination between the missions and CARA from early in the design process into mission operations, helps to ensure that missions not only have a robust conjunction assessment concept of operations to reduce conjunction risk for space sustainability, but are also able to achieve their science goals and have a successful mission.

conjunction assessment↗

Performance and Stability Characterization of the ICARUS Light Detection System

The ICARUS detector, a key component of the Short Baseline Neutrino (SBN) Program at Fermilab, consists of two identical T300 modules filled with liquid argon. It is equipped with a Light Detection System (LDS) based on 360 8-inch Hamamatsu R5912-MOD photomultiplier tubes (PMTs) arranged behind the wire planes to collect Vacuum Ultraviolet (VUV, $\sim$ 128 nm) scintillation light. Operating under cryogenic conditions ( $\sim$ 87 K), the LDS is essential for determining the event start time (t0) with nanosecond precision for beam spill synchronization, improving longitudinal spatial resolution, and contributing to the event trigger and cosmic-ray mitigation. The performance of the LDS was investigated addressing both hardware and data analysis aspects. Following a progressive degradation in PMT gain observed during operations at FNAL, systematic gain measurements were first carried out from room temperature down to low temperatures. The results show stable performance at room temperature but a significant, irreversible reduction in gain at low temperatures. Based on these findings, a series of mitigation strategies were implemented in the ICARUS detector to preserve PMT performance and ensure reliable cryogenic operation. Currently, ongoing waveform analysis of the PMT signals is being performed to characterize signal shape, charge integration, and timing properties, aiming to refine and improve the agreement between experimental data and Monte Carlo simulations.

Saia, Clara [U. Catania (main); INAF, Catania; Cat↗

Segregation Evolution and Diffusion of Titanium in Directed Energy Deposited NASA HR-1

Titanium segregation in single-pass directed energy deposited (DED) NASA HR-1 is very difficult to control because grain size varies considerably and many large grains (>100 μm) are present. Therefore, homogenization kinetic analysis was performed to see how the homogenization process should be adjusted to mitigate titanium segregation. A basic model for titanium diffusion in NASA HR-1 was developed to project titanium segregation as a function of homogenization temperature, time, and grain size. The homogenization kinetic analysis provides a valuable reference on how the homogenization treatment should be adjusted to reduce titanium segregation to a very low level for DED NASA HR-1.

liquid rocket engine↗

A Twin Circuit Theory-Based Framework for Oscillation Event Analysis in Inverter-Dominated Power Systems With Case Study for Kaua‘i System

Here, this paper proposes a real-world oscillation event analysis framework for power systems that include inverter-based resources together with synchronous generators. Specifically, the proposed framework combines both measurement-and model-based techniques to readily identify potential oscillation sources, replay the oscillation event with numerical simulation, unveil the underlying oscillation mechanism, and suggest mitigation methods for a wide range of oscillation events. To strengthen the theoretical foundation of our analysis framework, this paper proposes a twin circuit theory that provides theoretical support for one key utilized but not well-proven measurement-based oscillation source identification method-Dissipating Energy Flow. Our twin circuit theory also shows that adopting well-tuned grid-forming inverters can be a potential mitigation method for oscillation events. Finally, the effectiveness of our proposed oscillation event analysis framework is demonstrated by addressing a real-world 18-20 Hz oscillation event in Kaua‘i's power system on November 21, 2021.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Risk Analysis Tool for Estimating the Risk of Electrical Failures Due to Human Induced Defects

Aerospace electrical systems are required to withstand and adequately operate in extremely harsh environments that include, for example, high radiation exposure, temperature extremes, intense vibrational stress and drastic temperature cycling. The nature of aerospace electronics also demands high reliability since, with very few exceptions, there is no chance for hardware servicing or repairs. Common risk mitigation techniques for this type of situation are to perform a Reliability Analysis of the system throughout the development cycle, and to use electrical components that are regarded as “high reliability” because of additional controls and requirements applied in their design, manufacturing and testing. Unfortunately, studies have shown that even though these techniques are used, many systems fail to meet mission requirements well before the predicted lifetimes. This paper presents the analysis of failures of electrical parts, experienced during various stages of system development, at NASA Goddard Space Flight Center, Greenbelt MD, between the years 2001 and 2013. These components were subjected to qualification, screening and testing in which the goal was to ensure that the components would survive the stresses of the mission. The analysis categorizes failures by part type and failure mechanisms. One of the results of the analysis was the realization that a surprising proportion of failures experienced during system integration and testing were caused by human error (i.e. human induced defect). Further analysis included the determination of root failure mechanisms and any influencing factors contributing to these failures. The major causes of these defects were attributed to electrostatic damage (ESD), electrical overstress (EOS), mechanical overstress (MOS), and thermal overstress (TOS). Finally, the study proposes a risk analysis tool which incorporates these major causes for the failures, termed error-producing conditions (EPCs), and a proportionality factor representing the number of each type of failure that has occurred at the facility under study. These factors are quantified and used to communicate the risk of human induced defects for the assembly, integration and testing of space hardware based on the system’s electrical parts list. The new risk identification can trigger risk-mitigating actions more effectively, based on the presence of component categories or other hazardous conditions that have a history of failure due to human error.

Majewicz, Peter J.↗

An Abstract Interpretation Framework for the Round-Off Error Analysis of Floating-Point Programs

This paper presents an abstract interpretation framework for the round-off error analysis of floating-point programs. This framework defines a parametric abstract analysis that computes, for each combination of ideal and floating-point execution path of the program, a sound over-approximation of the accumulated floating-point round-off error that may occur. In addition, a Boolean expression that characterizes the input values leading to the computed error approximation is also computed. An abstraction on the control flow of the program is proposed to mitigate the explosion of the number of elements generated by the analysis. Additionally, a widening operator is defined to ensure the convergence of recursive functions and loops. An instantiation of this framework is implemented in the prototype tool PRECiSA that generates formal proof certificates stating the correctness of the computed round-off errors.

Titolo, Laura↗

Bundling measures for food systems transformation: a global, multimodel assessment

Background Current food systems leave one in ten individuals at risk of hunger while driving unsustainable environmental impacts. Inaction risks further exacerbating negative impacts on both human and planetary health. These challenges emerge from complex system interactions, requiring approaches that engage with this complexity and consider how transformation measures interact across food systems. We aimed to quantify the magnitude and uncertainty of the impacts of key food systems transformation measures both individually and in a bundle using an ensemble of global economic models. Methods In this global multimodel assessment, we applied an ensemble of ten state-of-the-art global economic models to evaluate the potential of four key measures in transforming food systems: increasing agricultural productivity, halving food loss and waste, shifting towards healthier diets, and economy-wide climate mitigation policies aligned with limiting warming to 1·5°C. The scenarios used a middle-of-the-road shared socioeconomic pathway for population and gross domestic product growth, climate impact data from Jägermeyr and colleagues, Thornton and colleagues, and Nelson and colleagues, and dietary targets based on the EAT–Lancet healthy reference diet, with model simulations conducted from 2020 to 2050. We then assessed the effect of these measures in isolation and in combination in a bundled scenario. To further understand the interactions between these measures, we conducted a decomposition analysis that distinguishes between the individual effects of a measure (effect when implemented alone), total effects (its contribution within the bundle), and interaction effects (the difference between total and individual effects). This approach aimed to show complementarities and trade-offs that emerge when multiple measures are implemented simultaneously. Findings Our analysis showed that individual measures in isolation are insufficient to achieve high-level environmental objectives and might generate unintended consequences. In contrast, bundling measures produces co-benefits: avoiding 50% of projected agricultural greenhouse gas emissions by 2050 and almost 20% of anticipated land conversion, while moderating food price increases associated with ambitious climate change mitigation policies. Our decomposition analysis further shows that measures can have varying effects across different dimensions. Although dietary shifts and climate mitigation policies are the largest drivers of environmental benefits (each contributing to a median decline of >10 percentage points in non-CO 2 emissions and 5 percentage points in agricultural land use globally), productivity improvements and reducing food loss and waste play essential roles in moderating price increases (each contributing to a median decline of >5 percentage points in average prices). Interpretation This study highlights the importance of implementing coordinated approaches to food system transformation and climate change mitigation rather than relying on isolated interventions. Comprehensive transformation requires understanding how supply-side and demand-side changes can interact with climate mitigation policies, enabling policy makers to design intervention packages that maximise benefits while minimising trade-offs across environmental, economic, and social dimensions.

Sundiang, Marina [Cornell Univ., Ithaca, NY (Unite↗

ISHM Decision Analysis Tool: Operations Concept

The state-of-the-practice Shuttle caution and warning system warns the crew of conditions that may create a hazard to orbiter operations and/or crew. Depending on the severity of the alarm, the crew is alerted with a combination of sirens, tones, annunciator lights, or fault messages. The combination of anomalies (and hence alarms) indicates the problem. Even with much training, determining what problem a particular combination represents is not trivial. In many situations, an automated diagnosis system can help the crew more easily determine an underlying root cause. Due to limitations of diagnosis systems,however, it is not always possible to explain a set of alarms with a single root cause. Rather, the system generates a set of hypotheses that the crew can select from. The ISHM Decision Analysis Tool (IDAT) assists with this task. It presents the crew relevant information that could help them resolve the ambiguity of multiple root causes and determine a method for mitigating the problem. IDAT follows graphical user interface design guidelines and incorporates a decision analysis system. I describe both of these aspects.

Source record↗

The Chandra X-Ray Observatory Radiation Environmental Model Update

CRMFLX (Chandra Radiation Model of ion FLUX) is a radiation environment risk mitigation tool for use as a decision aid in planning the operation times for Chandra's Advanced CCD Imaging Spectrometer (ACIS) detector. The accurate prediction of the proton flux environment with energies of 100 - 200 keV is needed in order to protect the ACIS detector against proton degradation. Unfortunately, protons of this energy are abundant in the region of space where Chandra must operate. In addition, on-board particle detectors do not measure proton flux levels of the required energy range. CRMFLX is an engineering environment model developed to predict the proton flux in the solar wind, magnetosheath, and magnetosphere phenomenological regions of geospace. This paper describes the upgrades to the ion flux databases for the magnetosphere, magnetosheath, and solar wind regions. These data files were created by using Geotail and Polar spacecraft flux measurements only when the Advanced Composition Explorer (ACE) spacecraft's 0.14 MeV particle flux was below a threshold value. This new database allows for CRMFLX output to be correlated with both the geomagnetic activity level, as represented by the Kp index, as well as with solar proton events. Also, reported in this paper are results of analysis leading to a change in Chandra operations that successfully mitigates the false trigger rate for autonomous radiation events caused by relativistic electron flux contamination of proton channels.

Blackwell, William C.↗

Methodology for Designing Fault-Protection Software

A document describes a methodology for designing fault-protection (FP) software for autonomous spacecraft. The methodology embodies and extends established engineering practices in the technical discipline of Fault Detection, Diagnosis, Mitigation, and Recovery; and has been successfully implemented in the Deep Impact Spacecraft, a NASA Discovery mission. Based on established concepts of Fault Monitors and Responses, this FP methodology extends the notion of Opinion, Symptom, Alarm (aka Fault), and Response with numerous new notions, sub-notions, software constructs, and logic and timing gates. For example, Monitor generates a RawOpinion, which graduates into Opinion, categorized into no-opinion, acceptable, or unacceptable opinion. RaiseSymptom, ForceSymptom, and ClearSymptom govern the establishment and then mapping to an Alarm (aka Fault). Local Response is distinguished from FP System Response. A 1-to-n and n-to- 1 mapping is established among Monitors, Symptoms, and Responses. Responses are categorized by device versus by function. Responses operate in tiers, where the early tiers attempt to resolve the Fault in a localized step-by-step fashion, relegating more system-level response to later tier(s). Recovery actions are gated by epoch recovery timing, enabling strategy, urgency, MaxRetry gate, hardware availability, hazardous versus ordinary fault, and many other priority gates. This methodology is systematic, logical, and uses multiple linked tables, parameter files, and recovery command sequences. The credibility of the FP design is proven via a fault-tree analysis "top-down" approach, and a functional fault-mode-effects-and-analysis via "bottoms-up" approach. Via this process, the mitigation and recovery strategy(s) per Fault Containment Region scope (width versus depth) the FP architecture.

Barltrop, Kevin↗

Analysis of Thrust Vectoring Capabilities for the Jupiter Icy Moons Orbiter

A strategy to mitigate the impact of the trajectory design of the Jupiter Icy Moons Orbiter (JIMO) on the attitude control design is described in this paper. This paper shows how the thrust vectoring control torques, i.e. the torques required to steer the vehicle, depend on various parameters (thrust magnitude, thrust pod articulation angles, and thrust moment arms). Rather than using the entire reaction control system (RCS) system to steer the spacecraft, we investigate the potential utilization of only thrust vectoring of the main ion engines for the required attitude control to follow the representative trajectory. This study has identified some segments of the representative trajectory where the required control torque may exceed the designed ion engine capability, and how the proposed mitigation strategy succeeds in reducing the attitude control torques to within the existing capability.

low thrust↗

Characterizing Fractures Across the Astronaut Corps: Preliminary Findings from Population-Level Analysis

Despite evidence of bone loss during spaceflight and the implementation of countermeasures to mitigate this loss, the subsequent risk of fracture among astronauts is not known. Multiple factors such as age, sex, fracture history, and others may combine to increase fracture risk. The purpose of this study was to describe fractures among the astronaut population and generate questions for future occupational surveillance studies.

Rossi, Meredith M.↗

Environmental DNA as a tool for hydropower impact assessments: current status, special considerations, and future integration

Globally there is an urgent need to find sustainable solutions to balance energy production with the protection of vulnerable species and conservation of biodiversity. This is particularly critical for freshwater ecosystems, habitats, and species that may be impacted by hydropower development and operations needed to meet energy grid demands. Reliable and accurate environmental impact assessments (EIAs) that identify the biological, physical, or social impacts of hydropower are key to ensure biodiversity, ecosystem, and societal sustainability. The analysis of environmental DNA (eDNA) has the potential to transform hydropower EIAs, management and mitigation planning, and decision-making procedures. Further, the incorporation of eDNA surveys into EIAs during both hydropower planning and continued operations may streamline regulatory processes by improving our understanding of potentially impacted biota and habitats and evaluating environmental impacts mitigation. Here, we: (i) highlight current understanding and use of eDNA in freshwater environments; (ii) examine critical considerations for eDNA integration into hydropower EIAs and biological monitoring; (iii) identify knowledge gaps in eDNA analysis and applications unique to hydropower-regulated systems; and (iv) discuss future opportunities to bolster the incorporation of eDNA into hydropower research including regulatory acceptance and public engagement. While we acknowledge that there are several factors that may complicate the broad adoption of eDNA as a tool for assessing the impacts of hydropower, we anticipate that growing confidence in eDNA through hydropower-specific protocols, calibrations, and validations will overcome these inherent uncertainties.

aquatic biodiversity↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 ENGINEERING↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 - ENGINEERING↗

Gateway Program Safety and Mission Assurance Integration - the Future of Safe Deep Space Human Exploration

As a foundational element of the National Aeronautics and Space Administration (NASA) Artemis Campaign, the Gateway is an incrementally built cislunar spacecraft that will serve as a platform for deep space human exploration, science, and technology demonstration. The Gateway will be a unifying catalyst for international partners around the world to establish sustained deep space scientific investigations, lunar surface access, and missions to Mars. As human exploration moves farther away from Earth, spacecraft designs must prioritize and optimize mass and volume allocations, while minimizing human and spacecraft risk. To accomplish this objective, the Gateway Program Safety and Mission Assurance functions develop, implement, and ensure compliance with requirements, in concert with the accurate characterization and transparent communication of residual hazard risks, for integrated safety, reliability and maintainability and quality assurance. Safety and Mission Assurance was a key contributor during Gateway program pre-formulation and formulation activities where safety and reliability analysis was embedded in the Gateway Systems Engineering and Integration team. During these early program stages, a preliminary Gateway Integrated Hazard Analysis and Preliminary Gateway Probabilistic Risk Assessment assisted in Gateway architectural and operational definition as part of a risk-informed design process. As the deep space architecture has matured, the integrated Safety and Mission Assurance analyses have matured, new safety review processes have been developed, and requirements have been refined to ensure compliance with integrated safety and mission assurance objectives. The Gateway Program is currently concluding the preliminary design review informed milestone, where the primary objectives included: - Ensured completeness and consistency of the preliminary design, including the meeting of all requirements within appropriate margins and acceptable risk posture. - Identification of any major issues moving forward to the Critical Design phase. At this milestone, Safety and Mission Assurance provided numerous products, including Gateway Top Risks and Risk Mitigation Plans, updated integrated hazard analyses, updated probabilistic risk assessment, Crew Survival Analysis Report, and updated Safety and Mission Assurance Requirements and Plans. These products provide a many-faceted perspective on the inherent risk and available mitigations involved in flying the current proposed vehicle design and anticipated stack configurations. In addition, Safety and Mission Assurance identified top technical, process and workforce concerns to be addressed as the program progresses toward the critical design phase. This paper will detail the evolution of the Gateway Program Safety and Mission Assurance integration functions, provide its current status and lessons learned for future human spaceflight programs. Throughout this paper the key tenets of the Gateway Program Safety and Mission Assurance will be discussed: - Application of a risk-informed approach to identify and mitigate areas of highest risk. - Leverage of valuable processes and lessons learned from earlier spaceflight programs. - Development of Safety and Mission Assurance products to inform design risk trades. - Utilization of common Safety and Mission Assurance practices to identify safety risks for multiple perspectives: top-down, bottom-up, and across lines of integration. - Approval of safety hazards at the appropriate level of authority, keeping most deliberation closest to design expertise and elevating risks of greatest concern for program-level consideration. - Championing of Safety and Mission Assurance processes and forums to foster a pervasive safety culture that is transparent, inclusive, and collaborative between all partners. These tenets have allowed the Gateway Safety and Mission Assurance function to play a key role in optimized vehicle design evolution, and early identification and mitigation of Gateway program and Artemis mission risk.

Helen Vaccaro↗