Search NASASearch

SEARCH · Search NASA

Results for “Security risk analysis system engineering”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

33 records · Page 2

DeepLynx Ecosystem 2025

Poor data integration and governance continue to plague complex engineering projects, resulting in missed cost, schedule, and performance targets. Departments operate in isolated systems with manual data exchange, creating fragmented information that compounds errors and leads to significant delays and cost overruns. The DeepLynx ecosystem addresses these challenges through an open-source, modular data management platform that transforms fragmented project data into an integrated digital thread. Built on a federated microservice architecture, the ecosystem comprises seven specialized tools centered around DeepLynx Nexus, a unified data catalog with hierarchical organization and graph-based navigation capabilities. The ecosystem includes: DeepLynx Stream for real-time timeseries data ingestion from industrial sources; DeepLynx Ingest for governed data uploads with formal review workflows; DeepLynx Lattice for ontology-based entity and relationship extraction; DeepLynx Run for workflow orchestration and secure AI/ML compute; DeepLynx Visualize for 3D digital twin visualization; and DeepLynx Insight for AI-assisted document analysis with traceable, grounded responses. Deployable in cloud, on-premise, or hybrid environments using containerized Docker applications and Helm charts, the DeepLynx ecosystem provides flexible infrastructure that adapts to organizational requirements. By consolidating project data into a unified data lake with role-based access controls and OAuth2 authentication, DeepLynx enables digital thread and digital twin capabilities that improve decision-making, reduce risk, and support complex engineering workflows throughout the project lifecycle.

42 - ENGINEERING

Mission Assurance Modeling and Simulation: A Cyber Security Roadmap

This paper proposes a cyber security modeling and simulation roadmap to enhance mission assurance governance and establish risk reduction processes within constrained budgets. The term mission assurance stems from risk management work by Carnegie Mellon's Software Engineering Institute in the late 19905. By 2010, the Defense Information Systems Agency revised its cyber strategy and established the Program Executive Officer-Mission Assurance. This highlights a shift from simply protecting data to balancing risk and begins a necessary dialogue to establish a cyber security roadmap. The Military Operations Research Society has recommended a cyber community of practice, recognizing there are too few professionals having both cyber and analytic experience. The authors characterize the limited body of knowledge in this symbiotic relationship. This paper identifies operational and research requirements for mission assurance M&S supporting defense and homeland security. M&S techniques are needed for enterprise oversight of cyber investments, test and evaluation, policy, training, and analysis.

Gendron, Gerald

Facilitating Data Collection of Maintenance Events to Populate the Hydrogen Component Reliability Database (HyCReD)

The Hydrogen Component Reliability Database (HyCReD) is a collaborative project between the National Renewable Energy Laboratory, the University of Maryland, and hydrogen stakeholders to improve safety and reliability for hydrogen facilities by implementing component reliability data taxonomies that support hydrogen infrastructure failure rate analysis. The project aims to quantify failure rates of hydrogen components through high-quality data collection and analysis on root causes and maintenance needed. HyCReD provides a common database for cataloging hydrogen component failures which exists for reliability research in many other mature industries [2]. The database fills a gap for the hydrogen community by providing a scientifically rigorous approach to quantitative risk assessment (QRA), prognostic health management (PHM), and reliability-centered maintenance (RCM) analysis. High level results will be aggregated and anonymized to protect company sensitive information; detailed results will be used to help address issues of hydrogen components. These advanced analytics will support accelerated deployment of hydrogen infrastructure by enabling better: design and safety of projects (safety codes and standards development), infrastructure reliability and cost (component failure rates, maintenance protocols), and component R&D needs (robust supply chain). A key to a successful HyCReD implementation is facilitating the ease of reporting and data quality in the database that can be used for analysis. Maintenance data was a previously identified gap in initial efforts to populate and validate the database taxonomies [3]. Collection of maintenance data will be instrumental in identifying failure modes and rates, identifying incipient component failures or reduced performance, cataloging best practices for maintenance routines and methods for prognostic health management, and quantifying the risk and effect of different failure modes. Several key priorities are identified for streamlined data collection to achieve quality and detailed failure data: Applicability, Ease of Use, Accessibility, and Information Security. The HyCReD team has now begun deployment of the database to several companies and groups that have signed non-disclosure agreements to facilitate the data collection of failures in industry hydrogen refueling station infrastructure. This paper will provide an update into the process of HyCReD deployment including the development of a coding guide for facility personnel to reference and ensure data quality and consistency from one station to another as well as implementation of contextually dependent data fields of system taxonomy and formatted entries to provide ease of use. The goal is to communicate the lessons learned from the roll-out to technicians and engineers in the field, and the addition of need for high level of security to protect all stakeholders.

29 ENERGY PLANNING, POLICY, AND ECONOMY

AUTOMATIC GENERATION OF EVENT TREES AND FAULT TREES: A MODEL-BASED APPROACH

In the past few decades, increasing complexity in modern engineering systems has been driven by the integration of a large number of components and by the fact that the system operations involve many disciplines (e.g., thermal-hydraulics, plant operations, cyber-security). Current safety/reliability modeling approaches to such systems are labor intensive, difficult to learn, and rely heavily on simplistic Boolean logic to depict failure propagation and accident progression. While these methods serve well for simple systems (i.e., linear causal systems with limited small inter- and intra-system interactions), their results are difficult to verify when modeling complex systems (typically performed through the extensive use of modeling assumptions). The development of new methods is addressed to meet these challenges through a model-based system engineering (MBSE) lens. Under MBSE philosophy, every aspect of the system (form or function) is represented by a model that completely characterizes its architecture or behavior. MBSE approach greatly improves the management of design, analysis and verification of complex systems. An integration of Dynamic Probabilistic Risk Assessment (DPRA) methods with MBSE models is proposed to perform safety/reliability analyses of engineering systems. In particular, MBSE representation of the system (performed using Systems Modeling Language [SysML]) is coupled with DPRA methods to automatically generate event trees and fault trees.

97 - MATHEMATICS AND COMPUTING

Cyber Informed Engineering Cie Analysis Tool

Main Benefits: • Collaborate on assessment via the web and access and share assessments on your mobile device. • Helps you maximize your cybersecurity investment and resources • Saves you significant time and money by eliminating the requirement to research each government and industry standard in order to understand your cybersecurity posture • Contains easy to follow, step by step instructions to guide you through the process of identifying the cybersecurity posture of your organization • Provides a place to begin with cybersecurity improvement and a way to prioritize your tasks and budgets. • Covers all major cyber relevant topic areas for a comprehensive assessment of your organization’s cybersecurity posture. • Dives deep into the details of each topic area. • Contributes to the organization's risk management and decision-making process • Highlights vulnerabilities and gaps in your organization's IT and control systems. • Raises awareness and facilitates discussion on cybersecurity within your organization • Educates the controls system community on cyber security.

Hansen, Barry [Idaho National Laboratory (INL), Id

STS-114: Discovery Post MMT Press Conference

Bruce Buckingham of NASA Public Affairs hosted this press conference. Wayne Hill, Space Shuttle Deputy Program Manager; John Muratore, Shuttle Systems and Integration Manager; Mike Wetmore, Director for Shuttle Processing were present. Wayne started with a video from Shuttle Logistics Depot showing details of a point sensor box commonly named the black box. Work with the trouble shooting continues on a day to day basis, no definite launching date is set. John reports that they are in a mission support mode all over the country until the sensor problem is solved. Mike reports his team will complete scrub and securing tasks through the next day, restore the facility to its normal mode, and will start to a four day process of getting back to launch once trouble shooting is completed. Tanking test, thermal environment, problem identification, engine cut-off sensor problems, sensors, risk, design reviews, test and analysis, correlation of the problem with Columbia, are some of the topics covered with the News media.

Source record

C-Band Airport Surface Communications System Engineering-Initial High-Level Safety Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed C-band (5091- to 5150-MHz) airport surface communication system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents an initial high-level safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the C-band communication system after the profile is finalized and system rollout timing is determined. A security risk assessment has been performed by NASA as a parallel activity. While safety analysis is concerned with a prevention of accidental errors and failures, the security threat analysis focuses on deliberate attacks. Both processes identify the events that affect operation of the system; and from a safety perspective the security threats may present safety risks.

Zelkin, Natalie

Interstage Flammability Analysis Approach

The Interstage of the Ares I launch platform houses several key components which are on standby during First Stage operation: the Reaction Control System (ReCS), the Upper Stage (US) Thrust Vector Control (TVC) and the J-2X with the Main Propulsion System (MPS) propellant feed system. Therefore potentially dangerous leaks of propellants could develop. The Interstage leaks analysis addresses the concerns of localized mixing of hydrogen and oxygen gases to produce deflagration zones in the Interstage of the Ares I launch vehicle during First Stage operation. This report details the approach taken to accomplish the analysis. Specified leakage profiles and actual flammability results are not presented due to proprietary and security restrictions. The interior volume formed by the Interstage walls, bounding interfaces with the Upper and First Stages, and surrounding the J2-X engine was modeled using Loci-CHEM to assess the potential for flammable gas mixtures to develop during First Stage operations. The transient analysis included a derived flammability indicator based on mixture ratios to maintain achievable simulation times. Validation of results was based on a comparison to Interstage pressure profiles outlined in prior NASA studies. The approach proved useful in the bounding of flammability risk in supporting program hazard reviews.

Little, Jeffrey K.

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a framework for consequence-driven applied risk analysis, enabling utilities to prioritize and mitigate potential threats effectively, and responsibly deploy cloud applications. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY

Multisectoral analysis of drought impacts and management responses to the 2008–2015 record drought in the Colorado Basin, Texas

Abstract. Drought has long posed an existential threat to society. Engineering and technological advancements have enabled the development of complex, interconnected water supply systems that buffer societies from the impacts of drought, enabling growth and prosperity. However, increasing water demand from population growth and economic development, combined with more extreme and prolonged droughts due to climate change, poses significant challenges for governments in the 21st century. Improved understanding of the cascading multisectoral impacts and adaptive responses resulting from extreme drought can aid in adaptive planning and highlight key processes in modeling drought impacts. The record drought spanning 2008 to 2015 in the Colorado Basin in the state of Texas, United States, serves as an outstanding illustration to assess multisectoral impacts and responses to severe, multi-year drought. The basin faces similar water security challenges to those across the western US, such as groundwater depletion and sustainability, resource competition between agriculture and growing urban populations, limited options for additional reservoir expansion, and the heightened risk of more severe and frequent droughts due to climate change. By analyzing rich, high-quality data sourced from nine different local, state, and federal sources, we demonstrate that characterizing regional multisector dynamics is crucial to predicting and understanding future vulnerability and possible approaches to reduce impacts to human and natural systems in the face of extreme drought conditions. This review reveals that, despite the severe hydrometeorological conditions of the drought, the region's advanced economy and existing water infrastructure effectively mitigated economic and societal impacts.

54 ENVIRONMENTAL SCIENCES

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN

Extended Duration: The SIRIUS 21 Crew Perspective

The SIRIUS (Scientific International Research In a Unique terrestrial Station) missions represent a collaborative effort between NASA and Russia’s Institute for Biomedical Problems (IBMP) to conduct a series of long duration isolation and confinement spaceflight analog missions. Three missions of 17-day, 4-month, and 8-month duration (SIRIUS 17, 19, and 21) have been completed at IBMP’s Ground-Based Experimental Complex / Nazemnyy eksperimental'nyy kompleks (NEK) in Moscow, Russia. The international SIRIUS 21 crew comprising representatives from the United States, United Arab Emirates and Russia recently completed the 8-month analog lunar mission. The extended duration mission included simulated lunar transit, orbital, and surface operations with corresponding deep space communication delay, during which the crew participated in nearly 70 studies, eight of which were sponsored by NASA’s Human Research Program. The studies examined the effect of isolation and confinement on the behavioral health of research subjects, and investigated medical countermeasures, team performance, crew dynamics, crew autonomy, food system risks, consequences of confinement and associated physiological stressors. SIRIUS 21 crewmembers also participated in operational tasks such as Rover and CubeSat assembly, simulated lunar sample assessment, VR activities, robotic arm training, environmental systems monitoring, exercise, greenhouse maintenance and 3D printing. Communication with Mission Control was limited to 30-minute periods every two hours. Since access to the internet and email was restricted, simulated ground support provided the Crew’s primary source of daily news and mission information. This panel discussion will include presentations from the US SIRIUS 21 crewmembers – William Brown and Ashley Kowalski – about their experience participating in the mission and science. A facilitated question and answer session will follow with attendees encouraged to ask questions and join in discussion with the SIRIUS 21 crewmembers about their experiences. William Brown came to SIRIUS 21 with experience spread across multiple industries, including the military, defense contracting, healthcare consulting, software engineering, and logistics. He has lived in the Middle East, Central Asia, and Russia. A former Boren Scholar, Brown is fluent in Russian. He holds a Master of International Business degree from the University of South Carolina’s Darla Moore School of Business. Prior to that, he earned a bachelor’s degree in Russian language, literature, and culture from the University of South Carolina. There, he also completed additional undergraduate coursework in computer science. Ashley Kowalski is a Project Leader in The Aerospace Corporation’s International Partnerships Department, where she works with, represents, and provides technical support to the the U.S. Space Force Space Systems Command International Affairs (SSC/IA) office. Through her numerous national and international assignments (Russia, China, and Germany), she has worked on topics related to international space systems, national security space systems, civil systems (including human spaceflight and civil launch projects), space policy, satellite industry analysis, and satellite manufacturing start-ups. She is proficient in Russian and German, and fluent in Polish. Kowalski received her Bachelor of Science and Master of Science degrees in mechanical and aerospace engineering from George Washington University in 2011 and 2012, respectively.

S. E. Whiting

Digital Droplet PCR and Mesocosm-Based Methods to Evaluate Biocontainment Strategies in a Native Soil Ecosystem

Genetically modified industrial production microbes and their associated bioproducts have emerged as an integral component of a sustainable bioeconomy. However, the rapid development of these innovative technologies raises biosecurity concerns, namely, the risk of environmental escape. Thus, the realization of a bioeconomy hinges not only on the development and deployment of microbial production hosts, but also on the development of secure biosystems and biocontainment designs. Current laboratory-based biocontainment testing systems do not accurately reflect the complexities found in natural environments, necessitating an environmentally relevant analysis pipeline that allows for the detection of rare escapees within a complex soil microbiome and differentiation between closely related strains. To this end, we have developed an approach that utilizes soil mesocosms and integrated digital droplet PCR (ddPCR) system to evaluate the efficacy of novel biocontainment strategies. We demonstrate the utility of this approach by modeling contamination with industrial microbial chasses versus their biocontained counterparts. Here we demonstrate the broad utility of this system by highlighting findings from strains of Saccharomyces cerevisiae that are contained with an inducible toxin anti-toxin system, strains of Synechocystis sp. PCC 6803 contained via gene knockout or toxin anti-toxin system, and strains of Escherichia coli that are contained via genomic recoding. We also show that ddPCR can be used to detect gene copies from E. coli equal to those counted by traditional spot plating assays. The resultant data demonstrates that this system has broad utility across diverse microbial chassis and biocontainment strategies and enables researchers to track the fate of our contaminating microbe with high sensitivity in the soil. The findings presented here support the use of this mesocosm-based approach to assess the environmental impact of industrial microbes and to validate biocontainment strategies.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH

Technology Benefit Estimator (T/BEST): User's Manual

The Technology Benefit Estimator (T/BEST) system is a formal method to assess advanced technologies and quantify the benefit contributions for prioritization. T/BEST may be used to provide guidelines to identify and prioritize high payoff research areas, help manage research and limited resources, show the link between advanced concepts and the bottom line, i.e., accrued benefit and value, and to communicate credibly the benefits of research. The T/BEST software computer program is specifically designed to estimating benefits, and benefit sensitivities, of introducing new technologies into existing propulsion systems. Key engine cycle, structural, fluid, mission and cost analysis modules are used to provide a framework for interfacing with advanced technologies. An open-ended, modular approach is used to allow for modification and addition of both key and advanced technology modules. T/BEST has a hierarchical framework that yields varying levels of benefit estimation accuracy that are dependent on the degree of input detail available. This hierarchical feature permits rapid estimation of technology benefits even when the technology is at the conceptual stage. As knowledge of the technology details increases the accuracy of the benefit analysis increases. Included in T/BEST's framework are correlations developed from a statistical data base that is relied upon if there is insufficient information given in a particular area, e.g., fuel capacity or aircraft landing weight. Statistical predictions are not required if these data are specified in the mission requirements. The engine cycle, structural fluid, cost, noise, and emissions analyses interact with the default or user material and component libraries to yield estimates of specific global benefits: range, speed, thrust, capacity, component life, noise, emissions, specific fuel consumption, component and engine weights, pre-certification test, mission performance engine cost, direct operating cost, life cycle cost, manufacturing cost, development cost, risk, and development time. Currently, T/BEST operates on stand-alone or networked workstations, and uses a UNIX shell or script to control the operation of interfaced FORTRAN based analyses. T/BEST's interface structure works equally well with non-FORTRAN or mixed software analysis. This interface structure is designed to maintain the integrity of the expert's analyses by interfacing with expert's existing input and output files. Parameter input and output data (e.g., number of blades, hub diameters, etc.) are passed via T/BEST's neutral file, while copious data (e.g., finite element models, profiles, etc.) are passed via file pointers that point to the expert's analyses output files. In order to make the communications between the T/BEST's neutral file and attached analyses codes simple, only two software commands, PUT and GET, are required. This simplicity permits easy access to all input and output variables contained within the neutral file. Both public domain and proprietary analyses codes may be attached with a minimal amount of effort, while maintaining full data and analysis integrity, and security. T/BESt's sotware framework, status, beginner-to-expert operation, interface architecture, analysis module addition, and key analysis modules are discussed. Representative examples of T/BEST benefit analyses are shown.

Generazio, Edward R.

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING