Search NASA⌕ Search

SEARCH · Search NASA

Results for “Engineering Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Probing Aircraft Flight Test Hazard Mitigation for the Alternative Fuel Effects on Contrails and Cruise Emissions (ACCESS) Research Team : Appendices - Volume 2

The Alternative Fuel Effects on Contrails and Cruise Emissions (ACCESS) Project Integration Manager requested in July 2012 that the NASA Engineering and Safety Center (NESC) form a team to independently assess aircraft structural failure hazards associated with the ACCESS experiment and to identify potential flight test hazard mitigations to ensure flight safety. The ACCESS Project Integration Manager subsequently requested that the assessment scope be focused predominantly on structural failure risks to the aircraft empennage (horizontal and vertical tail). This report contains the Appendices to Volume I.

Kelly, Michael J.↗

LTF/Fluid and Cryogenic Systems Branch

Functions of the Branch: Cross-Cutting Fluids Engineering; Research and Technology Development of Cryogenic Fluid Management (CFM) Systems; Component and System level; Design, Development Test and Evaluation (DDT&E) for Fluid, CFM, Propellant and Gaseous Systems; Fluid Component Specification and Selection; Code Compliance of Pressurized Systems; Fluid/Cryogenic System Performance Analysis and Trade Studies; Hazards Analysis and Risk Assessment of Fluidic Systems; Fluids Modeling and Simulation Capabilities

Fluid↗

Recommendation for a Medical System Concept of Operations for Gateway Missions

NASA’s exploration missions to cis-lunar space will establish a permanent gateway to future transport missions to Mars. These missions mandate a significant paradigm change for mission planning, spacecraft design, human systems integration, and in-flight medical care due to constraints on mass, volume, power, resupply, and medical evacuation capability. These constraints require medical system development to be tightly integrated with mission and habitat design to provide a sufficient medical infrastructure and enable mission success. This concept of operations provides a vision of medical care needs that will be used to guide the development of a medical system for the cis-lunar Gateway Habitat. This medical system will serve as the precursor to what is implemented in future exploration missions to Mars. This concept of operations documents an overview of the stakeholder needs and system goals of a medical system and provides examples of the types of activities for which the system will be used during the mission. This concept of operations informs the ExMC systems engineering effort to define the Gateway Habitat Medical System by documenting the medical activities and capabilities relevant to Gateway missions, as identified by the ExMC clinician community. In addition, this concept of operations will inform the subsequent systems engineering process of developing technical requirements, system architectures, interfaces, and verification and validation approaches for the medical system. This document supports the closure of ExMC Gap Med01: We do not have a concept of operations for medical care during exploration missions, corresponding to the ExMC-managed human system risk: Risk of Adverse Health Outcomes & Decrements in Performance due to Inflight Medical Conditions.

Rubin, David↗

Modernizing NASA’s Space Flight Safety and Mission Success (S&MS) Assurance Framework In Line With Evolving Acquisition Strategies and Systems Engineering Practices

This paper presents the objectives-driven, case-based safety and mission success (S&MS) assurance framework being developed by the NASA Office of Safety and Mission Assurance (OSMA), including its motivations and its implementation via a S&MS Assurance Standard that is under development, supplemented by supporting standards including an S&MS Analysis Management Standard that is also under development. A need to evolve NASA’s S&MS assurance framework has emerged in recent years, resulting from the need to accommodate new acquisition models; the need to accommodate evolving systems engineering (SE) practices; the need to stipulate acceptable levels of S&MS risk; the need for improved integration of S&MS into SE; and the need for clearer risk acceptance accountability. The objectives-driven, case-based S&MS assurance framework proposed here is responsive to that need. Its key features include: • The establishment, by NASA Acquirers, of fundamental S&MS performance objectives that define limits of acceptability for the likelihoods that mission technical objectives will be accomplished and that people, assets, and environments put at risk by the mission will not be adversely affected; • The development and approval of Providers’ S&MS plans for meeting Acquirers’ S&MS performance objectives, including commitments to support Acquirer audit, investigation, and reporting needs; • The development, by Providers, of S&MS assurance cases that argue, supported by evidence, that the Provider has met, or is on track to meeting, the fundamental S&MS objectives; • The evaluation, throughout the program/project life cycle, of Provider S&MS assurance cases as the primary S&MS-related technical basis for Acquirer risk acceptance and the granting to the Provider of authority to proceed through the program/project life cycle. This proposed S&MS assurance framework is notable for its lack of prescription of traditional S&MS requirements and strategies such as defined failure tolerances, margins, or analysis requirements. Instead, Providers are given latitude to propose their own strategies for meeting the fundamental S&MS performance objectives, subject to independent review and Acquirer approval. The result is a framework for S&MS assurance that is at once both rigorous and flexible.

Assurance Case↗

Application of Objectives-Driven Assurance Cases to System Development in an Evolving Acquisition Model

System properties such as “safety” and “dependability” cannot, in practice, be proven, and must be argued in an “assurance case” aimed at supporting risk-acceptance decisions that have to be made by system acquirers and/or regulatory authorities. The paper is concerned with applications of the “assurance case” idea early in design and development of new systems, when (apart from dedicated testing) the only available operating experience information derives from previous (non-identical) systems. Much of the discussion is based on an evolving acquisition model at the US National Aeronautics and Space Administration; previously, most major systems were developed in-house, but some major systems will now be developed by and acquired from commercial providers. Key points discussed include the following. (1) By promoting a particular kind of focused discussion between acquirers and providers, the use of assurance cases should be particularly valuable under the new acquisition model. (2) In principle, objectives-driven (sometimes called “performance-based”) approaches to assurance of performance have significant advantages in cases where they are applicable. (3) For truly novel systems, completeness of the safety analysis is a significant issue; it is important for the assurance case to include a commitment by the provider (or applicant) to seriously pursue analysis of operating experience, so that previously unrecognized hazards can be identified and addressed. (4) Inquiries into major accidents often point to deficiencies in management oversight in all parts of the life cycle; management processes need to be addressed in the formulation and the implementation of an assurance case. Under the new acquisition model, these considerations imply a serious reconsideration of the way in which the development process is managed by both providers and acquirers.

Objectives-driven↗

Space Program Advocacy Can Distort Project Management and Damage Systems Engineering

Over-optimistic project advocacy often causes exaggerated performance claims and underestimated costs and schedules. This can distort project management and damage systems engineering. NASA projects such as the space shuttle and Hubble are extreme examples. NASA's spectacular success in the Apollo moon landings seems to have produced overconfidence and carelessness, but also to have gained tolerance for unrealistic claims and forgiveness when they were proven wrong. Apollo risk analysis predicted many astronaut fatalities. This was believed but was potentially damaging to the Apollo program, so risk analysis was discontinued. The moon landings beat bad odds because Apollo obsessively reduced risk. Its success seemed to confirm that risk analysis was unreasonably pessimistic and that risk could be overcome by good engineering. This understanding caused risk to be increased during space shuttle engineering and led to an unnecessarily dangerous approach. The shuttle design placed a fragile spacecraft next to the fuel tanks and failed to provide crew escape or launch abort. These design decisions directly caused the Challenger and Columbia tragedies. After Challenger, risk analysis was re-established. The current rocket and capsule design does consider risk and the result strongly resembles Apollo. Apollo advocacy led NASA to abandon risk analysis and this was ultimate cause of the Shuttle tragedies. Excessive advocacy that distorts risk, cost, and schedule could be prevented in an ideal organization that used systems engineering to make rational and fair decisions. However, most real organizations accommodate human and group needs using informal methods often described as "the system." Humans have biases, use innate decision making heuristics, instinctively rely on "gut feel," and establish deviant groups through groupthink. Expecting organizations to become totally rational is impractical, but specific problems such as neglecting risk and underestimating cost and schedule can be directly challenged with some hope of success.

Jones, Harry W.↗

Case Study of the Space Shuttle Cockpit Avionics Upgrade Software

The purpose of the Space Shuttle Cockpit Avionics Upgrade project was to reduce crew workload and improve situational awareness. The upgrade was to augment the Shuttle avionics system with new hardware and software. An early version of this system was used to gather human factor statistics in the Space Shuttle Motion Simulator of the Johnson Space Center for one month by multiple teams of astronauts. The results were compiled by NASA Ames Research Center and it was was determined that the system provided a better than expected increase in situational awareness and reduction in crew workload. Even with all of the benefits nf the system, NASA cancelled the project towards the end of the development cycle. A major success of this project was the validation of the hardware architecture and software design. This was significant because the project incorporated new technology and approaches for the development of human rated space software. This paper serves as a case study to document knowledge gained and techniques that can be applied for future space avionics development efforts. The major technological advances were the use of reflective memory concepts for data acquisition and the incorporation of Commercial off the Shelf (COTS) products in a human rated space avionics system. The infused COTS products included a real time operating system, a resident linker and loader, a display generation tool set, and a network data manager. Some of the successful design concepts were the engineering of identical outputs in multiple avionics boxes using an event driven approach and inter-computer communication, a reconfigurable data acquisition engine, the use of a dynamic bus bandwidth allocation algorithm. Other significant experiences captured were the use of prototyping to reduce risk, and the correct balance between Object Oriented and Functional based programming.

Ferguson, Roscoe C.↗

Layered Systems Engineering Engines

A notation is described for depicting the relationships between multiple, contemporaneous systems engineering efforts undertaken within a multi-layer system-of-systems hierarchy. We combined the concepts of remoteness of activity from the end customer, depiction of activity on a timeline, and data flow to create a new kind of diagram which we call a "Layered Vee Diagram." This notation is an advance over previous notations because it is able to be simultaneously precise about activity, level of granularity, product exchanges, and timing; these advances provide systems engineering managers a significantly improved ability to express and understand the relationships between many systems engineering efforts. Using the new notation, we obtain a key insight into the relationship between project duration and the strategy selected for chaining the systems engineering effort between layers, as well as insights into the costs, opportunities, and risks associated with alternate chaining strategies.

Vee Diagram↗

What Went Wrong: A Survey of Wildfire UAS Mishaps through Named Entity Recognition

Increasingly, unmanned aircraft systems (UAS) are being applied to wildfire incidents for tasks such as mapping, aerial ignition, and delivery. As a result, incident reporting systems for wildfires are beginning to accumulate data related to UAS mishaps in wildfire response. In this research, we apply state-of-the-art natural language processing (NLP) techniques to develop a custom Named Entity Recognition (NER) model which extracts a Failure Modes and Effects Analysis (FMEA)-style survey of wildfire UAS mishaps reported in SAFECOM. The custom NER model is built by fine-tuning an existing (BERT) model, resulting in a generalizable NER model that can extract engineering relevant entities including failure modes, causes, effects, control processes, and recommendations from any failure-relevant text. Similar mishaps are clustered and reported as single rows within the FMEA. For each cluster, frequency, severity, and overall risk are computed. The methodology can be applied as part of a broader safety management system to track trends in mishaps and discover knowledge that can be utilized to improve safety outcomes and system performance.

Machine Learning↗

What Went Wrong: A Survey of Wildfire UAS Mishaps through Named Entity Recognition

Increasingly, unmanned aircraft systems (UAS) are being applied to wildfire incidents for tasks such as mapping, aerial ignition, and delivery. As a result, incident reporting systems for wildfires are beginning to accumulate data related to UAS mishaps in wildfire response. In this research, we apply state-of-the-art natural language processing (NLP) techniques to develop a custom Named Entity Recognition (NER) model which extracts a Failure Modes and Effects Analysis (FMEA)-style survey of wildfire UAS mishaps reported in SAFECOM. The custom NER model is built by fine-tuning an existing (BERT) model, resulting in a generalizable NER model that can extract engineering relevant entities including failure modes, causes, effects, control processes, and recommendations from any failure-relevant text. Similar mishaps are clustered and reported as single rows within the FMEA. For each cluster, frequency, severity, and overall risk are computed. The methodology can be applied as part of a broader safety management system to track trends in mishaps and discover knowledge that can be utilized to improve safety outcomes and system performance.

Machine Learning↗

Predicting the Likelihood of Human-Elephant Conflict and Assessing Patterns in Elephant Movements Over Varying Habitat Conditions in the Kavango-Zambezi Area

In the Kavango-Zambezi area of southern Africa, three million people live within areas frequently traveled by free-ranging elephants. As the region continues to develop rapidly, urban and agricultural settlements further encroach upon the land that these elephants use. As elephants come into more frequent contact with urban and agricultural areas, human populations face financial loss through crop damage and the potential for injury from direct conflict with elephants. Elephant populations are also at risk of injuries from conflict as well as illness related to the consumption of waste. In order to implement human-elephant conflict mitigation strategies, local conservation groups need to be informed on best practices for coexistence. This project aided The Ecoexist Project and Connected Conservation in understanding the ecological factors that drive elephant movement into human settlements and provided Earth observation data to support conflict management in the future. The team used Landsat 5 Thematic Mapper (TM), Landsat 8 Operational Land Imager (OLI) data to create land use land cover maps and calculate vegetation indices, and used TerraClimate data to analyze drought conditions. These classified maps allowed us to display a time series of human settlement from 1990 to the present and were made explorable alongside other environmental variables in an updated Google Earth Engine (GEE) tool. This project also provided heat maps that show the risk of human-elephant conflict based on historical data of HEC locations. This analysis will provide support for conservation experts in determining best practices for future mitigation and prevention of human-elephant conflict.

Ariel Calle↗

Task Load Management in Earth Independent Medical Operations

BACKGROUND: Medical care in spaceflight carries a high task load and can easily overwhelm a small crew. Present day operations in low Earth orbit (LEO) offload most medical tasks to ground teams in mission control. This team includes dozens of flight surgeons, specialists, and engineers and supports the on-orbit crew in monitoring environmental systems, tracking medications, guiding procedures, providing expert advice, and many other tasks. However, the physical limitations of the speed of light and technical limitations of bandwidth, channel capacity, and signal processing mean that missions beyond LEO cannot rely on this level of telemedical support. The further we travel from Earth the more these tasks will fall on the shoulders of the crew and the greater the risk of task saturation to the wellbeing of the crew and the success of the mission. Exploration class space crews will need progressively more robust systems for managing task load as they progress further out in space. OVERVIEW: Medical task management systems will need to assist with two broad categories of tasks; cognitively intensive tasks and procedure execution tasks. In both cases the goal is for the systems to operate in the background with minimal human-in-the-loop intervention. To accomplish this such systems will need to be designed with careful consideration for human factors and human systems integration to maximize efficiency, minimize alarm fatigue, and avoid inadvertently increasing task loads. Finally, the key domains of space medicine tasking can be used to map present day and near future technologies to the areas where they are best suited to support and identify gaps which can be targeted for research and development. DISCUSSION: Task load is a major challenge for Earth Independent Medical Operations to overcome. It will require careful coordination between experts in a variety of fields paying attention to human factors and human systems integration as well as technical and medical expertise. If done well medical task management systems can handle many of the tasks currently run by humans in mission control and enable human crews to maintain terrestrial standards of care in the extraterrestrial environment.

Dana Levin↗

Report to the administrator by the NASA Aerospace Safety Advisory Panel on the Skylab program. Volume 1: Summary report

Contractor and NASA technical management for the development and manufacture of the Skylab modules is reviewed with emphasis on the following management controls: configuration and interface management; vendor control; and quality control of workmanship. A review of the modified two-stage Saturn V launch vehicle which focused on modifications to accommodate the Skylab payload; resolution of prior flight anomalies; and changes in personnel and management systems is presented along with an evaluation of the possible age-life and storage problems for the Saturn 1-B launch vehicle. The NASA program management's visibility and control of contractor operations, systems engineering and integration, the review process for the evaluation of design and flight hardware, and the planning process for mission operations are investigated. It is concluded that the technical management system for development and fabrication of the modules, spacecraft, and launch vehicles, the process of design and hardware acceptance reviews, and the risk assessment activities are satisfactory. It is indicated that checkout activity, integrated testing, and preparations for and execution of mission operation require management attention.

Source record↗

Protecting intellectual property in space; Proceedings of the Aerospace Computer Security Conference, McLean, VA, March 20, 1985

The primary purpose of the Aerospace Computer Security Conference was to bring together people and organizations which have a common interest in protecting intellectual property generated in space. Operational concerns are discussed, taking into account security implications of the space station information system, Space Shuttle security policies and programs, potential uses of probabilistic risk assessment techniques for space station development, key considerations in contingency planning for secure space flight ground control centers, a systematic method for evaluating security requirements compliance, and security engineering of secure ground stations. Subjects related to security technologies are also explored, giving attention to processing requirements of secure C3/I and battle management systems and the development of the Gemini trusted multiple microcomputer base, the Restricted Access Processor system as a security guard designed to protect classified information, and observations on local area network security.

Source record↗

Application of expert systems in project management decision aiding

The feasibility of developing an expert systems-based project management decision aid to enhance the performance of NASA project managers was assessed. The research effort included extensive literature reviews in the areas of project management, project management decision aiding, expert systems technology, and human-computer interface engineering. Literature reviews were augmented by focused interviews with NASA managers. Time estimation for project scheduling was identified as the target activity for decision augmentation, and a design was developed for an Integrated NASA System for Intelligent Time Estimation (INSITE). The proposed INSITE design was judged feasible with a low level of risk. A partial proof-of-concept experiment was performed and was successful. Specific conclusions drawn from the research and analyses are included. The INSITE concept is potentially applicable in any management sphere, commercial or government, where time estimation is required for project scheduling. As project scheduling is a nearly universal management activity, the range of possibilities is considerable. The INSITE concept also holds potential for enhancing other management tasks, especially in areas such as cost estimation, where estimation-by-analogy is already a proven method.

Harris, Regina↗

Compton Gamma Ray Observatory: Lessons Learned in Propulsion

The Compton Gamma Ray Observatory was the second of NASA's Great Observatories. At 17 1/2 tons. it was the heaviest astrophysical payload ever flown at the time of its launch on April 5, 1991 aboard the Space Shuttle. During initial, on-orbit priming of the spacecraft's monopropellant hydrazine propulsion system, a severe waterhammer transient was experienced. At that time, anomalous telemetry readings were received from on-board propulsion system instrumentation. This led to ground analyses and laboratory investigations as to the root cause of the waterhammer, potential damage to system integrity and functionality, and risks for switching from the primary (A-side) propulsion system to the redundant (B-side) system. The switchover to B-side was ultimately performed successfully and the spacecraft completed its basic and extended missions in this configuration. Nine years later, following a critical control gyroscope failure, Compton was safely deorbited and re-entered the Earth's atmosphere on June 4, 2000. Additional risk assessments concerning viability of A- and B-sides were necessary to provide confidence in attitude and delta-V authority and reliability to manage the precisely controlled reentry. This paper summarizes the design and operation of the propulsion system used on the spacecraft and provides "lessons learned" from the system engineering investigations into the propellant loading procedures, the initial priming anomaly, mission operations, and the commanded re-entry following the gyro failure.

Dressler, G. A.↗

Bioastronautics Roadmap: A Risk Reduction Strategy for Human Space Exploration

The Bioastronautics Critical Path Roadmap is the framework used to identify and assess the risks to crews exposed to the hazardous environments of space. It guides the implementation of research strategies to prevent or reduce those risks. Although the BCPR identifies steps that must be taken to reduce the risks to health and performance that are associated with human space flight, the BCPR is not a "critical path" analysis in the strict engineering sense. The BCPR will evolve to accommodate new information and technology development and will enable NASA to conduct a formal critical path analysis in the future. As a management tool, the BCPR provides information for making informed decisions about research priorities and resource allocation. The outcome-driven nature of the BCPR makes it amenable for assessing the focus, progress and success of the Bioastronautics research and technology program. The BCPR is also a tool for communicating program priorities and progress to the research community and NASA management.

Source record↗

Characterization of Evidence for Human System Risk Assessment

Understanding the kinds of evidence available and using the best evidence to answer a question is critical to evidenced-based decision-making, and it requires synthesis of evidence from a variety of sources. Categorization of human system risks in spaceflight, in particular, focuses on how well the integration and interpretation of all available evidence informs the risk statement that describes the relationship between spaceflight hazards and an outcome of interest. A mature understanding and categorization of these risks requires: 1) sufficient characterization of risk, 2) sufficient knowledge to determine an acceptable level of risk (i.e., a standard), 3) development of mitigations to meet the acceptable level of risk, and 4) identification of factors affecting generalizability of the evidence to different design reference missions. In the medical research community, evidence is often ranked by increasing confidence in findings gleaned from observational and experimental research (e.g., "levels of evidence"). However, an approach based solely on aspects of experimental design is problematic in assessing human system risks for spaceflight. For spaceflight, the unique challenges and opportunities include: (1) The independent variables in most evidence are the hazards of spaceflight, such as space radiation or low gravity, which cannot be entirely duplicated in terrestrial (Earth-based) analogs, (2) Evidence is drawn from multiple sources including medical and mission operations, Lifetime Surveillance of Astronaut Health (LSAH), spaceflight research (LSDA), and relevant environmental & terrestrial databases, (3) Risk metrics based primarily on LSAH data are typically derived from available prevalence or incidence data, which may limit rigorous interpretation, (4) The timeframe for obtaining adequate spaceflight sample size (n) is very long, given the small population, (5) Randomized controlled trials are unattainable in spaceflight, (6) Collection of personal and environmental data on the astronaut population may create opportunities for advanced analytics and human-environment modeling that goes beyond that achieved in isolated experimental designs; and (7) Translation of relevant research to operations is a complex, transdisciplinary enterprise in which the approach must apply across the physical, biological, behavioral, and social sciences. The approach to synthesizing evidence must address both source and fidelity of data, and reflect the most general attributes of quality of evidence in science and engineering: reliability and validity. The authors are developing a two-factor approach which includes the various kinds of evidence required to understand risks and for the integrated interpretation of all evidence that is essential to develop standards and countermeasures. A unified framework for aggregating and assessing different kinds of evidence provides a consistent, traceable, evidence-based decision-making process to translate research to operations in an environment where engineers, scientists, physicians, and managers all engage in analyzing the trade space of vehicle design, standards, requirements and solutions for spaceflight.

Steinberg, S. L.↗