Search NASASearch

SEARCH · Search NASA

Results for “Risk-Informed Decision Making”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

47 records · Page 3

What Has ExMC Systems Engineering Been Up To Since Last IWS?

Long duration Lunar and Martian missions will change the way NASA currently practices medicine. The missions will require more autonomous capability compared to current low Earth orbit operations. For the medical system, lack of consumable resupply, evacuation opportunities, and real-time ground support are key drivers toward greater autonomy. Recognition of the limited mission and vehicle resources available to carry out exploration missions motivates the Exploration Medical Capability (ExMC) Element’s approach to enabling the necessary autonomy. This element promotes human health and performance in space by advancing medical systems design and risk-informed decision-making for long-duration deep-space exploration missions (LDEMs). ExMC is using system engineering processes and Model-Based System Engineering (MBSE) tools to identify the user needs and requirements of LDEM medical systems. The MBSE approach to medical system design offers a paradigm shift toward greater integration between the vehicle and the medical system, and directly supports the transition of Earth-reliant International Space Station operations to the Earth-independent operations envisioned for LDEMs. This talk will provide a high-level overview of what the ExMC SE team has accomplished since the last IWS, an introduction to upcoming SE talks, and the ongoing systems engineering work.

K. McGuire

Exploration Atmosphere Demonstration of A Multi-Functional Integrated Medical Device (Tempus Pro)

INTRODUCTION The Exploration Medical Capability (ExMC) element within the Human Research Program and the Exploration Medical Integrated Product Team (XMIPT) within the Mars Campaign Office seek to advance medical system design and risk-informed decision-making for exploration missions. This includes assessment of candidate devices and their compatibility within a variety of increasingly Earth-independent medical scenarios. The Tempus Pro (Remote Diagnostic Technologies, Ltd., Philips Corp., Farnborough, UK) is a commercial-off-the-shelf (COTS), multi-functional integrated medical device capable of vital signs monitoring, with built-in procedure support (iAssist), patient record and telemedicine communication features, and medical imaging (e.g., camera, laryngoscope, ultrasound) that meets multiple exploration medical capability needs. One of several hypobaric atmospheres being considered for exploration vehicles is 8.2 psi with 34% oxygen. To assess the useability of the Tempus Pro in such environments by individuals without formal medical training, the unit was tested in May and June of 2023 at the Johnson Space Center 20-Foot Exploration Atmosphere Chamber in conjunction with the Exploration Atmospheres-2 (EA-2) study. TECHNOLOGY DEMONSTRATION Eight subjects in the EA-2 study were assigned roles as the caregiver or patient – or both in the case of a self-exam – and caregivers were asked to place sensors for 3-Lead ECG, non-invasive blood pressure (NIBP), pulse oximetry (SpO2), and temperature using Tempus Pro’s iAssist. Depending on the procedure, additional tasks included an oropharyngeal exam of the throat with the laryngoscope and capturing ultrasound images of a cardiac subxiphoid view or of the user’s choice from a pre-specified list. Scenarios ranged from remote-guided to fully autonomous operations and surveyed the effectiveness of support, amount of support desired, and importance of support by type (e.g., written crew procedures, iAssist and device guidance, remote console guidance, etc.). Feedback from the subjects and the support personnel was also gathered to inform future designs for training and support and to determine what operations are plausible given different levels of each. An unweighted NASA task load index (TLX) was used to profile the demands of using the device, however the sample size does not support statistics. The research was exploratory in nature and qualitative information was the main goal. Calibration checks on the Tempus Pro were conducted before and after chamber testing to ensure the device was in useable condition. RESULTS All subjects performed their tasks successfully and found the Tempus Pro easy to use with the support provided. The calibration checks outside the chamber showed that the Tempus Pro remained unchanged and measurements inside the chamber were within normal values. Caregivers taking the NASA TLX reported mean scores ≤ 41/100 showing the tasks to be undemanding and less demanding with repeated use (~20/100). Novice users were able to easily connect sensors and take vital signs with the guidance from Tempus Pro’s iAssist feature. For more complex tasks, such as the oropharyngeal exam and ultrasound image acquisition, guidance beyond iAssist was needed, primarily from a supporting physician. Feedback on the importance of support types varied by person and scenario but greater than 50% of the support used by each was non-native to the device. Overall opinions were positive, but the ultrasound users expressed a lack of confidence in their results and 3 out of 4 desired more time, training, or support. Subjects found the sensors to be comfortable and comparable to prior experiences with such devices, except for the blood pressure cuff, which squeezed too tightly for uncomfortably long periods. Many observations provoked discussion, especially regarding ultrasound, that will aide decisions about future demonstrations.

R. S. Miller

2009 Space Shuttle Probabilistic Risk Assessment Overview

Loss of a Space Shuttle during flight has severe consequences, including loss of a significant national asset; loss of national confidence and pride; and, most importantly, loss of human life. The Shuttle Probabilistic Risk Assessment (SPRA) is used to identify risk contributors and their significance; thus, assisting management in determining how to reduce risk. In 2006, an overview of the SPRA Iteration 2.1 was presented at PSAM 8 [1]. Like all successful PRAs, the SPRA is a living PRA and has undergone revisions since PSAM 8. The latest revision to the SPRA is Iteration 3. 1, and it will not be the last as the Shuttle program progresses and more is learned. This paper discusses the SPRA scope, overall methodology, and results, as well as provides risk insights. The scope, assumptions, uncertainties, and limitations of this assessment provide risk-informed perspective to aid management s decision-making process. In addition, this paper compares the Iteration 3.1 analysis and results to the Iteration 2.1 analysis and results presented at PSAM 8.

Hamlin, Teri L.

An Integrated Reliability and Physics-Based Risk Modeling Approach for Assessing Human Spaceflight Systems

This paper presents an integrated reliability and physics-based risk modeling approach for assessing human spaceflight systems. The approach is demonstrated using an example, end-to-end risk assessment of a generic-crewed space transportation system during a reference mission to the International Space Station. The behavior of the system is modeled using analysis techniques from multiple disciplines in order to properly capture the dynamic time- and state- dependent consequences of failures encountered in different mission phases. We discuss how to combine traditional reliability analyses with Monte Carlo simulation methods and physics-based engineering models to produce loss-of- mission and loss-of-crew risk estimates supporting risk-based decision-making and requirement verification. This approach facilitates risk-informed design by providing more realistic representation of system failures and interactions; identifying key risk-driving sensitivities, dependencies, and assumptions; and tracking multiple figures of merit within a single, responsive assessment framework that can readily incorporate evolving design information throughout system development.

Risk assessment

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon

An Altair Overview: Designing a Lunar Lander for 21st Century Human Space Exploration

Altair, the lunar lander element of NASA's Constellation program, was conducted in a different design environment than many other NASA projects of similar scope. Because of this relatively unique approach, there are a number of significant success stories that should be considered during the development of any future lunar landers or human spacecraft. This paper is divided into two separate themes; the first is the approach used during the conceptual design studies, including the systematic analysis cycles and the decision making process associated with each: and the second is a summary of the resulting lessons learned that were compiled after looking back at the lifetime of the Project. Altair was terminated before entering Phase B of its design, and was often criticized for being a very heavy and very large vehicle. While there was specific rationale for all of the decisions that led up to that configuration, future design cycles were specifically planned to re-address the mass challenge. Had the project continued, the deliberate, stepwise design process would have converged on an optimized lander design that balanced mass, risk, cost and capabilities. Some of the specific items that will be addressed in this paper include project development strategy, organizational approach and team dynamics, risk-informed design process, mission architecture constraints, mission key driving requirements, model-based systems engineering process, configuration studies, contingency considerations, subsystem overviews and key trade studies. The paper will conclude with a summary of the lessons identified during the Altair project and make suggestions for application to future studies.

Brown, Kendall K.

The Evolution of System Safety at NASA

The NASA system safety framework is in the process of change, motivated by the desire to promote an objectives-driven approach to system safety that explicitly focuses system safety efforts on system-level safety performance, and serves to unify, in a purposeful manner, safety-related activities that otherwise might be done in a way that results in gaps, redundancies, or unnecessary work. An objectives-driven approach to system safety affords more flexibility to determine, on a system-specific basis, the means by which adequate safety is achieved and verified. Such flexibility and efficiency is becoming increasingly important in the face of evolving engineering modalities and acquisition models, where, for example, NASA will increasingly rely on commercial providers for transportation services to low-earth orbit. A key element of this objectives-driven approach is the use of the risk-informed safety case (RISC): a structured argument, supported by a body of evidence, that provides a compelling, comprehensible and valid case that a system is or will be adequately safe for a given application in a given environment. The RISC addresses each of the objectives defined for the system, providing a rational basis for making informed risk acceptance decisions at relevant decision points in the system life cycle.

Dezfuli, Homayoon

Promoting a Culture of Tailoring for Systems Engineering Policy Expectations

NASA's Marshall Space Flight Center (MSFC) has developed an integrated systems engineering approach to promote a culture of tailoring for program and project policy requirements. MSFC's culture encourages and supports tailoring, with an emphasis on risk-based decision making, for enhanced affordability and efficiency. MSFC's policy structure integrates the various Agency requirements into a single, streamlined implementation approach which serves as a "one-stop-shop" for our programs and projects to follow. The engineers gain an enhanced understanding of policy and technical expectations, as well as lesson's learned from MSFC's history of spaceflight and science missions, to enable them to make appropriate, risk-based tailoring recommendations. The tailoring approach utilizes a standard methodology to classify projects into predefined levels using selected mission and programmatic scaling factors related to risk tolerance. Policy requirements are then selectively applied and tailored, with appropriate rationale, and approved by the governing authorities, to support risk-informed decisions to achieve the desired cost and schedule efficiencies. The policy is further augmented by implementation tools and lifecycle planning aids which help promote and support the cultural shift toward more tailoring. The MSFC Customization Tool is an integrated spreadsheet that ties together everything that projects need to understand, navigate, and tailor the policy. It helps them classify their project, understand the intent of the requirements, determine their tailoring approach, and document the necessary governance approvals. It also helps them plan for and conduct technical reviews throughout the lifecycle. Policy tailoring is thus established as a normal part of project execution, with the tools provided to facilitate and enable the tailoring process. MSFC's approach to changing the culture emphasizes risk-based tailoring of policy to achieve increased flexibility, efficiency, and effectiveness in project execution, while maintaining appropriate rigor to ensure mission success.

Blankenship, Van A.

TPSAS-NF1676L-17243-DND

This presentation captures ERA Project's effort in using integrated cost-schedule-risk analysis tool, identifying and capturing explicit relationships between program funds, schedule, and discrete risks. The project team merged a myriad of cost and schedule data for timely, objective, uncertainty analysis of the ITD's budget and schedule. The project team conducted detailed schedule uncertainty analysis showing schedule activities and how their interrelationships were impacted, representing an impressive advance beyond routine Gantt charts. Furthermore, the ERA Project collected discrete risk events including their impacts to costs and/or schedule and interwove these risks into cost and schedule logic networks, providing the foundation to conduct cost and schedule analyses. The team integrated this data into the analysis model, providing probabilistic results that were then used by the ERA Project's senior management for decision-making purposes. The ERA Project management team, through technical and pathfinder expertise in integrating cost, schedule, risk, and technical content, consistently provided risk-informed recommendations to Implementing Centers and ISRP senior management which ultimately ensured the successful ARMD Key Decision Point (KDP) review of the ERA Phase 2 ITD Portfolio and increased the likelihood of achieving technical objectives within cost and schedule constraints.

Gaudy M Bezos-O'Connor

Habitability Assessments And Lessons-learned From 3-day And 11-day Enriched Oxygen Hypobaric Chamber Tests At NASA Johnson Space Center

INTRODUCTION: Decompression sickness (DCS) is a risk to the health and performance of astronauts and high-altitude aircrew. Tolerance to flammability, hypoxia, prebreathe duration, and DCS risk varies across different organizations, vehicles, suits, and destinations, necessitating a variety of DCS risk mitigation approaches. Existing models of altitude DCS risk are often insufficient to enable accurate risk-informed decisions during hardware development, mission planning, and flight operations. METHODS: NASA completed outfitting of a dedicated facility at Johnson Space Center to support testing of up to eight human subjects for multiple days in hypobaric and enriched oxygen atmospheres. The primary purpose of the testing capability is validation of DCS risk mitigation protocols for Artemis missions to the Moon; however, it will also support development and validation of a generalizable altitude DCS risk estimation tool. A 3-day and an 11-day prebreathe validation test were completed in 2022, each with 8 human subjects living at 56.5 kPa (8.2 psia), 34% O2, 66% N2, with 5 simulated EVAs performed on masks at 29.6 kPa (4.3 psi), 85% O2, 15% N2. Facility and organizational lessons-learned and process improvements were recorded during and following the tests, and subjective habitability ratings were recorded daily during the 11-day test. Hypoxia and DCS-related physiological and cognitive outcome measures were recorded during both tests and are reported in companion presentations. RESULTS & DISCUSSION: All subjects completed each of the tests. Primary habitability issues related to mask discomfort during simulated EVAs and poor sleep quality due to thin mattresses. Polybenzimidazole (PBI) clothing was worn by all subjects due to the increased fire risk and may be required for Artemis missions; clothing was found to be acceptable overall with the worst ratings being due to poor fit and inelasticity. Chamber O2 and CO2 sensor inconsistency was observed that did not result in test termination but required post-test follow-up. Forward plans include additional hypobaric testing and integration of existing and future physiological outcome data into an open-source Aerospace Estimation Tool for Hypobaric Exposure Risk (AETHER). NASA is also working to make the testing capability available to commercial companies.

Andrew F J Abercromby

Habitability Assessments And Lessons-learned From 3-day And 11-day Enriched Oxygen Hypobaric Chamber Tests At NASA Johnson Space Center

INTRODUCTION: Decompression sickness (DCS) is a risk to the health and performance of astronauts and high-altitude aircrew. Tolerance to flammability, hypoxia, prebreathe duration, and DCS risk varies across different organizations, vehicles, suits, and destinations, necessitating a variety of DCS risk mitigation approaches. Existing models of altitude DCS risk are often insufficient to enable accurate risk-informed decisions during hardware development, mission planning, and flight operations. METHODS: NASA completed outfitting of a dedicated facility at Johnson Space Center to support testing of up to eight human subjects for multiple days in hypobaric and enriched oxygen atmospheres. The primary purpose of the testing capability is validation of DCS risk mitigation protocols for Artemis missions to the Moon; however, it will also support development and validation of a generalizable altitude DCS risk estimation tool. A 3-day and an 11-day prebreathe validation test were completed in 2022, each with 8 human subjects living at 56.5 kPa (8.2 psia), 34% O2, 66% N2, with 5 simulated EVAs performed on masks at 29.6 kPa (4.3 psi), 85% O2, 15% N2. Facility and organizational lessons-learned and process improvements were recorded during and following the tests, and subjective habitability ratings were recorded daily during the 11-day test. Hypoxia and DCS-related physiological and cognitive outcome measures were recorded during both tests and are reported in companion presentations. RESULTS & DISCUSSION: All subjects completed each of the tests. Primary habitability issues related to mask discomfort during simulated EVAs and poor sleep quality due to thin mattresses. Polybenzimidazole (PBI) clothing was worn by all subjects due to the increased fire risk and may be required for Artemis missions; clothing was found to be acceptable overall with the worst ratings being due to poor fit and inelasticity. Chamber O2 and CO2 sensor inconsistency was observed that did not result in test termination but required post-test follow-up. Forward plans include additional hypobaric testing and integration of existing and future physiological outcome data into an open-source Aerospace Estimation Tool for Hypobaric Exposure Risk (AETHER). NASA is also working to make the testing capability available to commercial companies.

Andrew Abercromby