Search NASA⌕ Search

SEARCH · Search NASA

Results for “risk-informed”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Exploring the fusion power plant design space: comparative analysis of positive and negative triangularity tokamaks through optimization

The optimal configuration choice between positive triangularity (PT) and negative triangularity (NT) tokamaks for fusion power plants hinges on navigating different operational constraints rather than achieving specific plasma performance metrics. This study presents a systematic comparison using constrained multi-objective optimization with the integrated FUsion Synthesis Engine (FUSE) framework. Over 200 000 integrated design evaluations were performed exploring the trade-offs between capital cost minimization and operational reliability (maximizing q 95 ) while satisfying engineering constraints including 250 ± 50 MW net electric power, tritium breeding ratio > 1.1, power exhaust limits and an hour flattop time. Both configurations achieve similar cost-performance Pareto fronts through contrasting design philosophies. PT, while demonstrating resilience to pedestal degradation (compensating for up to 40% reduction), are constrained to larger machines (R 0 > 6.5 m) by the narrow operational window between L–H threshold requirements and the research-established power exhaust limit (P sol /R < 15 MW m –1 ). This forces optimization through comparatively reduced magnetic field (∼8 T). NT configurations exploit their freedom from these constraints to access compact, high-field designs (R 0 ~ 5.5 m, B 0 >12 T), creating natural synergy with advancing HTS technology. Sensitivity analyses reveal that PT’s economic viability depends critically on uncertainties in L–H threshold scaling and power handling limits. Notably, a 50% variation in either could eliminate viable designs or enable access to the compact design space. These results suggest configuration selection should be risk-informed: PT offers the lowest-cost path when operational constraints can be confidently predicted, while NT is robust to large variations in constraints and physics uncertainties.

FUSE framework↗

Failure Analysis–Informed Risk Assessment Framework for Geological Carbon Storage Using Numerical Simulation and Machine Learning

Geological carbon storage (GCS) is recognized as a critical technology for achieving large-scale reductions in anthropogenic carbon dioxide (CO 2 ) emissions. Ensuring long-term containment and safety requires robust risk assessment frameworks that account for geological uncertainty and identify potential failure scenarios. Among various indicators, the area of review (AoR) serves as a key metric for evaluating storage performance, regulatory compliance, and monitoring design, as it delineates the spatial extent impacted by pressure buildup and plume migration. However, conventional AoR-based risk assessments typically perturb parameters within narrow uncertainty bounds, potentially overlooking rare but high-impact events arising from extreme geological conditions. In this study, we present a failure analysis–informed risk assessment framework for large-scale GCS projects to improve site prescreening and monitoring design. A suite of 300 numerical simulations was generated using stochastic geological models that vary five key parameters: net-to-gross ratio, anisotropy azimuth, porosity multiplier, permeability multiplier, and vertical-to-horizontal permeability ratio. Among these, 200 realizations represent normal geological uncertainty, while 100 additional cases explore extreme yet plausible conditions for failure-case analysis. The AoR was simulated and computed from pressure and CO 2 saturation fields, where the baseline AoR boundary, representing the extent predicted under typical geological uncertainty, was defined as the union of 200 normal-range simulations, and failure was identified when extreme-range cases exceeded this baseline. Results show that incorporating broader parameter uncertainty produces significantly larger AoR extents, underscoring the potential underestimation of risk under conventional uncertainty ranges. Furthermore, spatial probability maps derived from failure-induced AoR exceedance identify regions requiring enhanced monitoring attention. Various machine learning (ML)–based classifiers were developed to predict failure occurrence from geological parameters, with the random forest model achieving the highest performance (F1-score of 0.986). Consistent findings from correlation coefficient, feature importance, and Sobol sensitivity analyses reveal that low net-to-gross ratios and permeability multipliers are the dominant risk drivers, reflecting reduced reservoir connectivity and limited pressure dissipation. Altogether, these results provide a novel framework for risk-informed site prescreening and monitoring design that explicitly considers rare but high-impact geological scenarios in GCS projects.

25 ENERGY STORAGE↗

Defensive Cybersecurity Architecture Design Using Force-on-Force Cyber-Physical Modeling

Currently, nuclear power plant physical security systems are highly dependent on air-gaps as a protective measure against cyber-threats. Cyber-physical threats become more likely as advanced cyber-threat capabilities to jump air-gaps transition into common use. Defending against the emerging threat of cyber-enabled physical intrusions is poorly understood. The consequence of these cyber-physical attacks has no quantitative analysis method to inform risk-informed, performance-based cybersecurity approaches. By modifying the physical security simulation tool Dante, cyber-physical threat consequence was able to be analyzed on a notional facility. The results of this analysis are used to design a Defensive Cybersecurity Architecture (DCSA) for the physical security system to produce example resilience measures for this notional facility. A DCSA defines security levels to provide a graded approach for defending plant functions, and security zones for trusted communication between systems. This approach can be applied to real world systems to produce physical protection systems and response measures that are resilient to cyber-physical threats.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

Templates for Risk Informed Assurance with Curvature Embeddings (TRACE)

We investigate recovery of geometric structure from networks embedded in manifolds with spatially varying curvature, extending the constant-curvature framework of Lubold et al. (2023). Our work supports cascade risk assessment in critical infrastructure through the Templates for Risk-informed Assurance with Curvature Embeddings (TRACE) framework. Simulations on a bi-modal Gaussian surface show that constant-curvature methods yield weighted averages shaped by clique patterns, while hierarchical clustering identifies distinct regimes. Localized estimation, however, reveals boundary contamination in transitional regions. To address heterogeneity, we develop distance metrics for graphs with edge and node features, proving their metric validity, and validate them via deterministic graph generation from canonical tilings. We further propose a diffusion-based anomaly detection approach that treats networks as glued manifolds, using curvature discontinuities to detect structural anomalies. Employing the carré-du-champ operator and scalar curvature, we achieve robust anomaly discrimination, demonstrated on the Singapore Water Treatment (SWaT) dataset with joint network-traffic and sensor features. Integration with TRACE reveals how curvature shapes cascade dynamics: positive curvature impedes, while negative curvature accelerates propagation. This geometric perspective provides interpretable risk metrics and visualization tools for critical infrastructure managers. While full validation remains ongoing, our contributions establish a rigorous foundation for geometric analysis of network resilience and cascade vulnerability.

97 MATHEMATICS AND COMPUTING↗

ARCADE Analysis Methods & Validation Pathway

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) provides an automated analysis system which supports risk-informed performance based (RIPB) evaluations of nuclear control systems. Every possible cyber threat which could lead to consequence is identified by simulating the unsafe control action sequences which transform digital harm into physical harm. Eliminating the simulation of complex digital cyber attack chains cuts out unnecessary computational overhead and focuses directly on the physics of cyber-physical attacks. This focus enables designers to make informed decisions which can entirely eliminate categories of cyber threats against advanced reactors through the physical nature of the plant design. This narrowing of cyber threat against nuclear power plants through the physics of the system is intended to make any remaining threat management and cost efficient. This is the goal of the Tiered Cyber Analysis (TCA) outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors. ARCADE has been custom developed to meet the demands of the rigorous analysis required in Tier 1 of the TCA, which forms the foundation of the TCA process. Currently, ARCADE is still under development, but has made significant leaps in capability. A pilot analysis on the opensource Asherah simulator was performed which demonstrated key functionality goals. The next stage of ARCADE development involves improvements to the applications which support the analysis system, and enabling the analysis system to utilize the full suite of unsafe control action simulations. Since the analysis method’s core functions are complete, validation of the analysis method will be started concurrent to the next development stages. The automated analysis ARCADE will provide can radically change the cybersecurity design process for advanced reactors, reducing the cost of security implementation while enhancing cyber resilience. The pathway for ARCADE’s development to this goal has become much clearer. The majority of technical hurdles have been cleared, and the remaining development needs have been solidified. ARCADE is now capable of assisting the advanced reactor design process and directly support advanced reactor industry RIPB practices.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Diversion Path Analysis: A Proposed Methodology to Develop an MC&A Approach for Liquid-Fueled Molten Salt Reactors

Nuclear material control and accounting (MC&A) is a critical element of both the US Nuclear Regulatory Commission (NRC) and US Department of Energy (DOE)’s domestic safeguards and security requirements. NRC licensees are required, under Title 10 of the Code of Federal Regulations (10 CFR) Part 74 to establish and maintain an MC&A program that captures and records the quantities and locations of special nuclear material (SNM) at the facility. Along with physical protection, MC&A is a key element of domestic nuclear material safeguards that enables the NRC to ensure that SNM is controlled and accounted for. SNM, per 10 CFR Part 74, refers to plutonium, 233 U, and uranium enriched in the isotope 233 U or 235 U, but does not include source material. Periodic physical inventories, coupled with material balance evaluations, are effective and demonstrated tools to account for and detect theft or diversion of SNM in facilities containing SNM in bulk material form (i.e., not in discrete, countable items). Historically in the United States, these types of facilities have included fuel fabrication, conversion, and enrichment facilities. In comparison, reactors have relied on item counting of assemblies and control of SNM while in containment (e.g., a sealed reactor pressure vessel) because, to date, reactor fuel has been in item form. In liquid-fueled molten salt reactors (MSRs), unlike traditional light water reactors (LWRs) or bulk facilities, bulk SNM quantities can change significantly during operation as a result of depletion and transmutation. This introduces challenges to the use of traditional periodic physical inventories and material balance evaluations to detect theft or diversion of SNM in reactors that use SNM in bulk material form. Liquid-fueled (i.e., salt-fueled) MSR facilities are MSRs that use SNM within a salt eutectic as the fuel. The SNM is in a bulk material form any time it is outside of fresh or spent fuel storage containers. Some examples of when SNM will be in bulk form in the facility are during addition of fuel to the reactor system, while fuel is circulating in operation, and while fuel is in a drain tank. Periodic physical inventories and material balance evaluations can likely be effectively applied to many portions of an MSR facility, including all areas where depletion and transmutation are not significantly changing the quantities of SNM within the control area. Within an MSR facility, this would include fresh fuel receipt and loading, waste streams that may contain SNM, irradiated fuel storage outside of the reactor core, and any irradiated fuel processing that may happen after SNM has been removed from the reactor. All of these process steps could rely on measurements of SNM quantities compared with documented inventories. Any discrepancies from predicted (i.e., book) inventories and measured inventories could be quantified as inventory differences, consistent with traditional MC&A guidance from the NRC (e.g., in NUREG-1065 Revision 2, NUREG-2159 Revision 1, and RG 5.29 Revision 2). Within the reactor system, additions and removals to the book inventory include depletion of the SNM (e.g., fission of 235 U), which complicates the use of physical inventories. SNM control, however, can also likely be effectively applied to detect theft of SNM throughout a liquid-fueled MSR facility. To complement these approaches, prior technical reports have identified that a diversion path analysis may be a useful, risk-informed, and performance-based tool to determine suitable elements of an MC&A approach for the reactor system within a liquid-fueled MSR facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer Based Hydrogen Production Facility

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at NREL's Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Radiological Releases from Novel Fuel Forms in Advanced Reactors During Severe Accidents for Consequence Analyses

Various advanced reactor developers are exploring the potential for reductions in the size of physical security forces and emergency planning zones. These reductions are based on robust fuel forms and inherently safe reactor designs. However, such reductions in physical protection measures could increase the risk of sabotage. To assess the possibility of reducing these measures, sabotage-induced radiological consequence analyses were carried out. These analyses considered accident scenarios that were beyond design basis accidents and overly conservative (Shah, 2025a; Shah, 2025b; Shah and Hartanto, 2026), yielding very large release fractions. These fractions, which can be used to evaluate physical protection and emergency planning requirements, have been crudely determined and applied as demonstrations for a sodium-cooled fast reactor (SFR) (Shah and Hartanto, 2025a), a high-temperature gas-cooled reactor (HTGR) (Shah and Hartanto, 2025b), a heat pipe–cooled reactor (HPR) (Shah and Hartanto, 2025c), and a molten salt–cooled reactor (MSR) (Shah et al., 2026). A Sandia National Laboratories (SNL) team used MELCOR—a fully integrated severe accident analysis code—to demonstrate the code’s capability to analyze advanced (i.e., not light water–cooled) reactors (including a fluoride salt–cooled high-temperature reactor [FHR]) and calculate radiological releases to the environment during severe accidents (Wagner et al., 2022a, 2022b, 2022c, 2023a, and 2023b). Although the analyses were carried out to demonstrate MELCOR’s growing capability, the release source terms were estimated for advanced reactors, providing valuable insights into the accident progression and radiological releases. These findings from prior SNL studies, including estimated source terms and related sensitivity studies, were leveraged to derive source terms for postulated sabotage-induced accidents. Insights from these sensitivity studies informed the scaling of SNL’s estimated source terms for the defined accident scenarios. The derived release fractions for the severe accident scenarios for the respective reactor designs can be used to perform more nuanced dose consequence analyses to evaluate the reactors’ physical protection and emergency planning zone requirements. These analyses are in accordance with the risk-informed, performance-based approach proposed under 10 CFR Part 53. This study builds on the prior source term analyses and associated sensitivity studies by SNL to derive time-dependent and design-informed release fractions. Section 2 describes the diverse advanced reactor designs analyzed by the SNL team. Section 3 discusses the severe accident analyses, the release fractions calculated, and the limitations and assumptions of the demonstration project. Section 4 presents the release percentages derived for the hypothetical sabotage-induced severe accidents at the advanced reactors. Section 5 summarizes the study’s findings and conclusions.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Security Licensing Basis Framework Development

This report summarizes a technology-inclusive and performance-based method to determine the physical security licensing basis for a commercial nuclear reactor under the proposed 10 CFR 73.100 for Part 53 licensees. The method focuses on the identification of security functions, the contributing security systems and programs to meet those functions, the identification of security events that will provide the foundation for the security licensing basis and includes a risk-informed performance-based defense in depth adequacy method. The method can also be employed to justify performance-based alternative measures to traditional security requirements found in 10 CFR 73.55.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Reassessing Double-Ended Guillotine Break Requirements: Evidence-Based Analysis of Regulatory Assumptions After Five Decades of Nuclear Operation

After five decades of nuclear power operation encompassing more than 20,000 reactor-years across 35 countries and 647 reactors, zero double-ended guillotine breaks (DEGBs) have been documented in commercial reactor coolant systems—despite DEGB being the fundamental design-basis assumption driving Emergency Core Cooling System (ECCS) sizing, structural protection requirements, and containment design specifications. This report examines the basis for DEGB requirements in nuclear power plant design. The DEGB postulate assumes the instantaneous, complete circumferential severance of the largest diameter pipes in reactor coolant systems, driving major design requirements under 10 Code of Federal Regulations 50.46, General Design Criterion 4 and containment design specifications. The United States (4,880 reactor-years) and France (2,505 reactor-years) contribute the largest operational datasets. Probabilistic assessments estimate direct DEGB occurrence probabilities with extremely low event frequencies, far below the 10-5/reactor-year thresholds typically used to define non-credible events in nuclear-safety analyses; i.e., events with probability this low fall into beyond-design-basis events. Current material-science knowledge demonstrates that the ductile steel materials used in nuclear piping systems exhibit stable crack-growth behavior fundamentally incompatible with instantaneous severance. International regulatory experience, particularly Germany’s comprehensive break-preclusion implementation, and successful leak-before-break (LBB) applications in almost all of U.S. pressurized water reactor units validate that alternatives can maintain safety performance while reducing economic burden. Current DEGB protection systems impose estimated lifetime costs of hundreds of millions of dollars per unit, over the life of a plant across the nuclear industry (including ongoing costs), representing substantial resource allocation toward scenarios with extremely low probability. Although this report acknowledges uncertainties regarding long-term aging effects, potential synergistic degradation mechanisms, and site-specific seismic considerations that warrant continued evaluation as regulatory policy evolves, there remains no documented evidence that a DEGB has occurred as a consequence of the conditions or mechanisms described in this report. This report acknowledges the Nuclear Regulatory Commission’s (NRC’s) recent efforts—outlined in the draft Interim Staff Guidance (ISG) NRC-DSS-ISG-2025-XX (“Treatment of Certain Loss-of-Coolant Accident Locations as Beyond-Design-Basis Accidents Draft Interim Staff Guidance”)—to reduce overly conservative requirements for large-break loss of coolant accidents through technical justifications and exemptions. However, extensive operating experience and validated methodologies—such as LBB and in-service inspection programs—demonstrate that the probability of a DEGB in reactor coolant-loop piping is extremely low, even under seismic conditions. The authors and reviewers of this report recommend that DEGB be removed as a design-basis event through formal rulemaking, rather than case-by-case exemptions, to better reflect credible failure modes, align with current data, and align with modern, risk-informed safety analysis.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Operating Experience Data Analysis for Digital Instrumentation and Control System Reliability and Risk Assessment in Nuclear Power Plants

The implementation of advanced digital instrumentation and control (DI&C) systems in U.S. nuclear power plants (NPPs) can bring significant advancements in reliability, monitoring, and control capabilities. However, these systems also introduce new challenges, particularly in assessing risks such as common-cause failures (CCFs) and establishing robust reliability estimates for DI&C components. Addressing these challenges is critical for ensuring the safe and efficient operation of NPPs. Recently, Idaho National Laboratory was tasked by the U.S. Nuclear Regulatory Commission (NRC) to conduct a DI&C reliability study using operating experience data from the nuclear industry. The two operating experience data sources for the study are the Institute of Nuclear Power Operations’ Industry Reporting and Information System (IRIS) and the NRC’s Licensee Event Report database which is hosted at Idaho National Laboratory at https://lersearch.inl.gov/LERSearchCriteria.aspx. This report provides a comprehensive examination of DI&C systems, including their architecture, operational advantages, and associated challenges. It reviews existing industry DI&C studies and failure mode taxonomies, along with reliability data from various industries. Through a detailed analysis of these databases, the study provides insights into DI&C system performance. Considerations should be given to incorporate DI&C failure data into the NRC's Integrated Data Collection and Coding System and updating the Reliability and Availability Data System to support ongoing DI&C reliability studies. Recommendations are also provided for modeling DI&C reliability and CCF in probabilistic risk assessment, thereby supporting risk-informed decision-making and enhancing the reliability and safety of NPPs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Hazard Analysis to Support Fusion Systems Safety Assessments

Reliability, safety, and performance are vital aspects of any nuclear operation. Fusion technology continues to grow in public, private, and research interest, and coupled with rapidly growing energy needs, fusion technology research is poised for fast progress. The development of a Fusion Nuclear Science Facility (FNSF) is seen as stepping stone for demonstrating long-cycle fusion. Naturally, such operation requires systems that are available, reliable, and safe. This work provides a novel demonstration of systems theory coupled with traditional hazard analysis to provide insights into the risk priority of components and systems found within the FNSF. The results of this work are a set of identified hazards that should be considered for the risk-informed design and development of the FNSF.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer-Based Hydrogen Production Facility: Preprint

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at the National Renewable Energy Laboratory (NREL)'s Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

An Approach to Automate tools for the Risk Assessment of Digital Instrumentation and Control Systems

Reliable digital instrumentation and control systems (DI&C) are integral for sustaining the continued operation of nuclear power plants. These systems ensure that nuclear reactors operate safely, efficiently, and within regulatory requirements. Yet, the cost of designing and licensing new nuclear DI&C can be prohibitively expensive. Under the U.S. Department of Energy Light Water Reactor Sustainability Program, Idaho National Laboratory has developed a framework for supporting the risk-informed design of DI&C systems by offering methods to support the identification, quantification, and evaluation of risks for various DI&C design architectures. The framework indicates potential software failure modes and provides pathways for quantifying the potential for these software failures, including common cause failures. Using the framework’s systematic approach, challenges for assessing risks within new and existing nuclear DI&C systems can be reduced. Nevertheless, the current framework can be further improved using the convenience of automation. This paper introduces the development of Software for the Hazard Identification and Evaluation of Digital Systems (SHIELDS). SHIELDS is an engineering software package that enables the identification, elimination, and mitigation of potential risks and reduces the burden of deploying reliable DI&C systems. This work introduces plans and techniques to digitize and improve the manual risk assessment modules of the framework. These improvements will save time and increase the repeatability and usability of the framework, making it more accessible to a wider range of users. Ultimately, this introduces SHIELDS and how its modules support efficient development of safe and reliable DI&C systems.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN↗

Hungary 908 Event - Risk Based Graded Approach to ITM

This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.

99 - GENERAL AND MISCELLANEOUS↗