Search NASA⌕ Search

SEARCH · Search NASA

Results for “Engineering Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Characterization of Evidence for Human System Risk Assessment

Understanding the kinds of evidence available and using the best evidence to answer a question is critical to evidenced-based decision-making, and it requires synthesis of evidence from a variety of sources. Categorization of human system risks in spaceflight, in particular, focuses on how well the integration and interpretation of all available evidence informs the risk statement that describes the relationship between spaceflight hazards and an outcome of interest. A mature understanding and categorization of these risks requires: 1) sufficient characterization of risk, 2) sufficient knowledge to determine an acceptable level of risk (i.e., a standard), 3) development of mitigations to meet the acceptable level of risk, and 4) identification of factors affecting generalizability of the evidence to different design reference missions. In the medical research community, evidence is often ranked by increasing confidence in findings gleaned from observational and experimental research (e.g., "levels of evidence"). However, an approach based solely on aspects of experimental design is problematic in assessing human system risks for spaceflight. For spaceflight, the unique challenges and opportunities include: (1) The independent variables in most evidence are the hazards of spaceflight, such as space radiation or low gravity, which cannot be entirely duplicated in terrestrial (Earth-based) analogs, (2) Evidence is drawn from multiple sources including medical and mission operations, Lifetime Surveillance of Astronaut Health (LSAH), spaceflight research (LSDA), and relevant environmental & terrestrial databases, (3) Risk metrics based primarily on LSAH data are typically derived from available prevalence or incidence data, which may limit rigorous interpretation, (4) The timeframe for obtaining adequate spaceflight sample size (n) is very long, given the small population, (5) Randomized controlled trials are unattainable in spaceflight, (6) Collection of personal and environmental data on the astronaut population may create opportunities for advanced analytics and human-environment modeling that goes beyond that achieved in isolated experimental designs; and (7) Translation of relevant research to operations is a complex, transdisciplinary enterprise in which the approach must apply across the physical, biological, behavioral, and social sciences. The approach to synthesizing evidence must address both source and fidelity of data, and reflect the most general attributes of quality of evidence in science and engineering: reliability and validity. The authors are developing a two-factor approach which includes the various kinds of evidence required to understand risks and for the integrated interpretation of all evidence that is essential to develop standards and countermeasures. A unified framework for aggregating and assessing different kinds of evidence provides a consistent, traceable, evidence-based decision-making process to translate research to operations in an environment where engineers, scientists, physicians, and managers all engage in analyzing the trade space of vehicle design, standards, requirements and solutions for spaceflight.

Steinberg, S. L.↗

Making or Breaking a Rover: System Engineering Parameters On-Board the Mars 2020 Perseverance Rover

On February 18, 2021, Perseverance, NASA’s Jet Propulsion Laboratory’s (JPL’s) Mars 2020 Rover, successfully landed on Mars with all systems nominal, despite the risk surrounding the over 200,000 internal flight parameters that had to be properly configured. The Perseverance team defines these parameters as software variables that are configurable, commandable and retrievable from Earth. In 2015, the Mars 2020 project leaders focused on improving systems engineering of parameters based on their experiences from parameter management on previous Mars rovers (Curiosity, Opportunity, Spirit, and Pathfinder) and parameter failures of past missions, such as the mission-ending parameter of the Mars Climate Orbiter. The new rigorous development process allowed for efficient certification and effective implementation of the parameters, allowing the rover to approach and land on the red planet (the most challenging phase of the mission) with zero parameter issues. Although successful, the Perseverance team learned many lessons for how to better manage parameters for the continued surface operations of the Mars 2020 mission and future missions. This paper will discuss eight parameter-management topics for the Perseverance Mission. The first is parameter definition: how we define parameters on our mission, where they are physically located on the vehicle, and why we have so many of them. The second topic is the updated parameter flight software module from Curiosity, including details on the 99% reduction in parameter commands, new bulk configuration capabilities, and improved parameter traceability. The third topic is parameter selection for different mission phases; this includes improving and tweaking our preferred parameter settings until they become certification candidates and managing parameter configurations based on test venue throughout the mission life cycle. The fourth topic is our flight certification process; this includes certification of flight values for four different epochs in the mission: Launch, Entry Decent and Landing (EDL) - 6days, Landing + 5 Sols (Martian Days, still on Cruise Flight Software), and once are on Surface Flight Software (FSW). The fifth topic covers in-flight command implementation, along with details on testing, validation, and verification of those commands. In the sixth section, we will explain our use of open-source management tools, including how we used GitHub for version control and management approvals. The seventh topic will describe the ground tools used in operations, including capabilities of the in-house built tool called Parasol. The eighth and final topic will dig into lessons learned for improving parameter management in the future of this mission and others.

Roth, Brian↗

Making or Breaking a Rover- Systems Engineering Parameters On-Board the Mars 2020 Perseverance Rover

On February 18, 2021, Perseverance, NASA’s Jet Propulsion Laboratory’s (JPL’s) Mars 2020 Rover, successfully landed on Mars with all systems nominal, despite the risk surrounding the over 200,000 internal flight parameters that had to be properly configured. The Perseverance team defines these parameters as software variables that are configurable, commandable and retrievable from Earth. In 2015, the Mars 2020 project leaders focused on improving systems engineering of parameters based on their experiences from parameter management on previous Mars rovers (Curiosity, Opportunity, Spirit, and Pathfinder) and parameter failures of past missions, such as the mission-ending parameter of the Mars Climate Orbiter. The new rigorous development process allowed for efficient certification and effective implementation of the parameters, allowing the rover to approach and land on the red planet (the most challenging phase of the mission) with zero parameter issues. Although successful, the Perseverance team learned many lessons for how to better manage parameters for the continued surface operations of the Mars 2020 mission and future missions. This paper will discuss eight parameter-management topics for the Perseverance Mission. The first is parameter definition: how we define parameters on our mission, where they are physically located on the vehicle, and why we have so many of them. The second topic is the updated parameter flight software module from Curiosity, including details on the 99% reduction in parameter commands, new bulk configuration capabilities, and improved parameter traceability. The third topic is parameter selection for different mission phases; this includes improving and tweaking our preferred parameter settings until they become certification candidates and managing parameter configurations based on test venue throughout the mission life cycle. The fourth topic is our flight certification process; this includes certification of flight values for four different epochs in the mission: Launch, Entry Decent and Landing (EDL) - 6days, Landing + 5 Sols (Martian Days, still on Cruise Flight Software), and once are on Surface Flight Software (FSW). The fifth topic covers in-flight command implementation, along with details on testing, validation, and verification of those commands. In the sixth section, we will explain our use of open-source management tools, including how we used GitHub for version control and management approvals. The seventh topic will describe the ground tools used in operations, including capabilities of the in-house built tool called Parasol. The eighth and final topic will dig into lessons learned for improving parameter management in the future of this mission and others.

Roth, Brian↗

Assessment of Electrical, Electronic, and Electromechanical (EEE) Parts Copper Wire Bonds for Space Programs

The NASA Electronic Parts and Packaging Program co-manager, requested the NASA Engineering and Safety Center (NESC) to compile a body of publicly available knowledge on copper (Cu) wire bonds and perform reliability testing and analysis on these bonds, including environment tests, sample destructive physical analysis, and bond pull/shear tests during environment test intervals. The goal was to understand the risks of using Cu wire bonds for space applications and develop guidelines on Cu bond pull/shear limits for NASA applications. This document contains the results of the NESC assessment.

Electrical, Electronic, and Electromechanical↗

Requirements Flowdown for Prognostics and Health Management

Prognostics and Health Management (PHM) principles have considerable promise to change the game of lifecycle cost of engineering systems at high safety levels by providing a reliable estimate of future system states. This estimate is a key for planning and decision making in an operational setting. While technology solutions have made considerable advances, the tie-in into the systems engineering process is lagging behind, which delays fielding of PHM-enabled systems. The derivation of specifications from high level requirements for algorithm performance to ensure quality predictions is not well developed. From an engineering perspective some key parameters driving the requirements for prognostics performance include: (1) maximum allowable Probability of Failure (PoF) of the prognostic system to bound the risk of losing an asset, (2) tolerable limits on proactive maintenance to minimize missed opportunity of asset usage, (3) lead time to specify the amount of advanced warning needed for actionable decisions, and (4) required confidence to specify when prognosis is sufficiently good to be used. This paper takes a systems engineering view towards the requirements specification process and presents a method for the flowdown process. A case study based on an electric Unmanned Aerial Vehicle (e-UAV) scenario demonstrates how top level requirements for performance, cost, and safety flow down to the health management level and specify quantitative requirements for prognostic algorithm performance.

video acuity↗

Hydrodynamic Test Requirements Process Improvements

Hydrodynamic testing at Los Alamos National Laboratory would benefit from a process improvement for the requirements process. Cameo was used as a digital solution for requirements management to allow Lead Engineers to track requirements more effectively. This was identified as a process improvement throughout this Capstone project. This report includes a project proposal, business case, literature review, methodology, project plan, data analysis, decision-making report, financial analysis report, discussion, and conclusion. Initially, this project focused on figuring out a solution for the hydrotest requirement process improvements. The scope narrowed to focus on the use of Cameo for requirement capture and management. During this Capstone, four tests had digital models produced for requirements management in Cameo. The initial model was the baseline, with core requirements used across the tests. Commonalities in tests were used and the core requirements allowed for process efficiencies. In the data analysis, it was seen that overall, the implementation of using Cameo for requirements resulted in a decreasing trend for both schedule and normalized cost. Tests have different complexity levels which is also a factor in how long the requirements process will take. Additional data is needed to continue analyzing process improvements. Through decisionmaking and financial analysis, the recommendation was to use Cameo for requirements process improvement. Multiple experts provided feedback for requirements that were then captured within models. Numerous tangible and intangible benefits were identified with this process improvement. For return on investment, the metric of success was schedule reduction, which was overall seen. Four tests were analyzed, so future analysis will be needed. There is also not a great financial risk because the main cost would be purchasing more licenses. Individuals must generate requirements whether using this software or not. Overall, training is needed to help improve the skillsets of Lead Engineers but is already being supported on a regular frequency. A desktop guide was started associated with explaining the process, however, it is a work in progress. The team plans on adding additional information in the digital models to help status when requirements are met using verification methods and artifacts. From working on this project an improved understanding of Cameo and requirements was the result. There are future opportunities to extend the usage for requirements management and progress will continue after this project.

99 GENERAL AND MISCELLANEOUS↗

Annual report to the NASA Administrator by the Aerospace Safety Advisory Panel. Part 2: Space shuttle program. Section 1: Observations and conclusions

The NASA and contractor management systems, including policies, practices, and procedures for the development of critical systems, subsystems and integration of the program elements, were investigated. The technical development status of critical systems, subsystems, and interfaces is presented. Space shuttle elements were qualified as to potential risks and hazards. The elements included the orbiter, external tanks, main engine, solid rocket boosters, and the ground support facilities.

Source record↗

Missions/Planning Panel

A panel discussion was held to develop a viewpoint of space power technology needs and state of readiness for future mission scenarios. Among the points made in the discussion, it was agreed that missions, particularly the far term ones, do serve to drive technology; however, as the missions become nearer term, issues of schedule and cost severely limit the willingness to accept risk. There are, in fact, no rewards to a mission manager for introducing new technology. Mission downscaling is the usual response to technology limitations. All panelists agreed that there exists a serious gap between when technologists feel their job is done and what mission managers need for decision. Typically a two to three year engineering development gap exists. It is essential to take technologies to the engineering model level and conduct a flight demonstration to close this gap. All agreed that increased effort should be made to achieve stronger interactions between planners and technologists and that workshops like the present one are a step in the right direction. Technologists need mission credibility and vice versa.

Fordyce, J. S.↗

Integration of Evidence Base into a Probabilistic Risk Assessment

INTRODUCTION: A probabilistic decision support model such as the Integrated Medical Model (IMM) utilizes an immense amount of input data that necessitates a systematic, integrated approach for data collection, and management. As a result of this approach, IMM is able to forecasts medical events, resource utilization and crew health during space flight. METHODS: Inflight data is the most desirable input for the Integrated Medical Model. Non-attributable inflight data is collected from the Lifetime Surveillance for Astronaut Health study as well as the engineers, flight surgeons, and astronauts themselves. When inflight data is unavailable cohort studies, other models and Bayesian analyses are used, in addition to subject matters experts input on occasion. To determine the quality of evidence of a medical condition, the data source is categorized and assigned a level of evidence from 1-5; the highest level is one. The collected data reside and are managed in a relational SQL database with a web-based interface for data entry and review. The database is also capable of interfacing with outside applications which expands capabilities within the database itself. Via the public interface, customers can access a formatted Clinical Findings Form (CLiFF) that outlines the model input and evidence base for each medical condition. Changes to the database are tracked using a documented Configuration Management process. DISSCUSSION: This strategic approach provides a comprehensive data management plan for IMM. The IMM Database s structure and architecture has proven to support additional usages. As seen by the resources utilization across medical conditions analysis. In addition, the IMM Database s web-based interface provides a user-friendly format for customers to browse and download the clinical information for medical conditions. It is this type of functionality that will provide Exploratory Medicine Capabilities the evidence base for their medical condition list. CONCLUSION: The IMM Database in junction with the IMM is helping NASA aerospace program improve the health care and reduce risk for the astronauts crew. Both the database and model will continue to expand to meet customer needs through its multi-disciplinary evidence based approach to managing data. Future expansion could serve as a platform for a Space Medicine Wiki of medical conditions.

Saile, Lyn↗

Assessing Seismic Risk for CO2 Geologic Storage: Comparative Analysis of the Delaware Basin and Basin and Range Province Projects

ABSTRACT: Effective management of induced seismicity is critical for safe and sustainable CO2 storage. This study evaluates fault slippage risks in the Delaware Basin (Texas) and Basin and Range Province (Utah), integrating geological, operational, and geomechanical parameters to assess fault stability and seismic hazard mitigation. In the Delaware Basin, two sites were analyzed under an injection rate of 20,000 bbl/day over 25 years. One site showed low fault slip risk, while the other exhibited higher reactivation potential due to proximity to critically stressed faults. Sensitivity analysis revealed that increased pore pressure significantly heightened slip potential, highlighting the necessity of precise pressure control and real-time monitoring. In the Basin and Range Province, fault stability was evaluated at Neck of the Desert, Escalante Desert, Parowan, and Beaver sites under injection rates of 8,750 bbl/day per site over 30 years. Minimal fault slip risk was observed at Neck of the Desert and Escalante Desert sites, whereas Parowan and Beaver sites exhibited elevated slip potential due to semi-critically stressed faults sensitive to modest pore pressure increases. The findings demonstrate that fault slippage analysis, combined with sensitivity analysis of pore pressure and friction coefficients, is essential for understanding seismic risks. Continuous monitoring, adaptive injection management, and rigorous geomechanical analysis are key strategies for minimizing induced seismicity in CO2 sequestration projects.

58 GEOSCIENCES↗

Tool Use Within NASA Software Quality Assurance

As space mission software systems become larger and more complex, it is increasingly important for the software assurance effort to have the ability to effectively assess both the artifacts produced during software system development and the development process itself. Conceptually, assurance is a straightforward idea - it is the result of activities carried out by an organization independent of the software developers to better inform project management of potential technical and programmatic risks, and thus increase management's confidence in the decisions they ultimately make. In practice, effective assurance for large, complex systems often entails assessing large, complex software artifacts (e.g., requirements specifications, architectural descriptions) as well as substantial amounts of unstructured information (e.g., anomaly reports resulting from testing activities during development). In such an environment, assurance engineers can benefit greatly from appropriate tool support. In order to do so, an assurance organization will need accurate and timely information on the tool support available for various types of assurance activities. In this paper, we investigate the current use of tool support for assurance organizations within NASA, and describe on-going work at JPL for providing assurance organizations with the information about tools they need to use them effectively.

software assurance↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Contrast and Predictability of Island‐Scale El Niño Influences on Hawaii Wave Climate

Abstract The El Niño‐Southern Oscillation (ENSO) influences ocean wave activity across the Pacific, but its effects on island shores are modulated by local weather and selective sheltering of multi‐modal seas. Utilizing 41 years of high‐resolution wave hindcasts, we decipher the season‐ and locality‐dependent connections between ENSO and wave patterns around the Hawaiian Islands. The north and west‐facing shores, exposed to energetic northwest swells during boreal winters, experience the most pronounced ENSO‐related variability, with increased high‐surf activity during El Niño years. While the year‐round trade wind waves exhibit moderate correlation with ENSO, the basin‐wide climate influence is masked by locally accelerated trade winds in channels and around large headlands. The remarkable global‐to‐local pathway through the high‐resolution hindcast enables development of an ENSO‐based semi‐empirical wave model to statistically describe and predict severe wave conditions on vulnerable shores with potential application in coastal risk management and hazard mitigation for Pacific Islands and beyond.

Zhao, Sen [Department of Atmospheric Sciences Scho↗

The Apollo Experience Lessons Learned for Constellation Lunar Dust Management

Lunar dust will present significant challenges to NASA's Lunar Exploration Missions. The challenges can be overcome by using best practices in system engineering design. For successful lunar surface missions, all systems that come into contact with lunar dust must consider the effects throughout the entire design process. Interfaces between all these systems with other systems also must be considered. Incorporating dust management into Concept of Operations and Requirements development are the best place to begin to mitigate the risks presented by lunar dust. However, that is only the beginning. To be successful, every person who works on NASA's Constellation lunar missions must be mindful of this problem. Success will also require fiscal responsibility. NASA must learn from Apollo the root cause of problems caused by dust, and then find the most cost-effective solutions to address each challenge. This will require a combination of common sense existing technologies and promising, innovative technical solutions

Wagner, Sandra↗

A Proposal for Standardized MMOD Shielding for Robotic Spacecraft

NASA robotic spacecraft are required to assess the potential for small debris induced failure for all disposal-critical components. Additional shielding might then be necessary in order to meet the acceptable risk requirement for the overall mission. Traditionally this requirement had been met with little or no additional shielding. Since the introduction of a high density debris population in ORDEM 3.0, some missions, especially those in higher portions of Low Earth Orbit, have needed additional MMOD-specific shielding in order for the mission to meet the requirement. This is a costly design effort when performed late in the project life cycle, which adds unexpected mass to the spacecraft components during the integration phase, and could disrupt thermal management.A proposal is discussed to develop a more cost-effective approach to MMOD-shielding, which can be employed earlier in the hardware design phase. The development and adoption of standardized shielding assemblies allows early tailoring of the shielding around a component, so that the mass is accounted for, as well as the small particle penetration risk, at a point in the design phase when the cost and schedule impact are more manageable. A set of several assemblies can be developed with a range of protection thresholds, in order to control mass where less shielding is needed. Such shielding assemblies would be developed in collaboration with blanket assembly specialists and thermal control engineers to ensure manufacturability and thermal performance challenges are known and acceptable. One clear benefit of such an approach is that hypervelocity testing can be performed on each of the standard shield assemblies to refine and confirm their performance prior to use.The challenges inherent in designing supplemental MMOD shielding will be discussed, including variations in the orbital debris environment and performance prediction. The benefits of a standardized shielding approach and example applications will also be presented.

Hull, Scott M.↗

A Proposal for Standardized MMOD Shielding for Robotic Spacecraft

NASA robotic spacecraft are required to assess the potential for small debris induced failure for all disposal-critical components. Additional shielding might then be necessary in order to meet the acceptable risk requirement for the overall mission. Traditionally this requirement had been met with little or no additional shielding. Since the introduction of a high density debris population in ORDEM 3.0, some missions, especially those in higher portions of Low Earth Orbit, have needed additional MMOD-specific shielding in order for the mission to meet the requirement. This is a costly design effort when performed late in the project life cycle, which adds unexpected mass to the spacecraft components during the integration phase, and could disrupt thermal management. A proposal is discussed to develop a more cost-effective approach to MMOD-shielding, which can be employed earlier in the hardware design phase. The development and adoption of standardized shielding assemblies allows early tailoring of the shielding around a component, so that the mass is accounted for, as well as the small particle penetration risk, at a point in the design phase when the cost and schedule impact are more manageable. A set of several assemblies can be developed with a range of protection thresholds, in order to control mass where less shielding is needed. Such shielding assemblies would be developed in collaboration with blanket assembly specialists and thermal control engineers to ensure manufacturability and thermal performance challenges are known and acceptable. One clear benefit of such an approach is that hypervelocity testing can be performed on each of the standard shield assemblies to refine and confirm their performance prior to use.The challenges inherent in designing supplemental MMOD shielding will be discussed, including variations in the orbital debris environment and performance prediction. The benefits of a standardized shielding approach and example applications will also be presented.

Hull, Scott M.↗

Cost effective management of space venture risks

The development of a model for the cost-effective management of space venture risks is discussed. The risk assessment and control program of insurance companies is examined. A simplified system development cycle which consists of a conceptual design phase, a preliminary design phase, a final design phase, a construction phase, and a system operations and maintenance phase is described. The model incorporates insurance safety risk methods and reliability engineering, and testing practices used in the development of large aerospace and defense systems.

Giuntini, Ronald E.↗

Strategies for Information Retrieval and Virtual Teaming to Mitigate Risk on NASA's Missions

Following the loss of NASA's Space Shuttle Columbia in 2003, it was determined that problems in the agency's organization created an environment that led to the accident. One component of the proposed solution resulted in the formation of the NASA Engineering Network (NEN), a suite of information retrieval and knowledge sharing tools. This paper describes the implementation of this set of search, portal, content management, and semantic technologies, including a unique meta search capability for data from distributed engineering resources. NEN's communities of practice are formed along engineering disciplines where users leverage their knowledge and best practices to collaborate and take informal learning back to their personal jobs and embed it into the procedures of the agency. These results offer insight into using traditional engineering disciplines for virtual teaming and problem solving.

communities of practices↗