Search NASA⌕ Search

SEARCH · Search NASA

Results for “Risk acceptability”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Risk Reduction for the System Design of an Enhanced MMRTG

Engineering of an enhanced Multi-Mission Radioisotope Thermoelectric Generator (eMMRTG) began 3 years ago with agreement between the U.S. National Aeronautics and Space Administration (NASA) and the U.S. Department of Energy (DOE). The Jet Propulsion Laboratory is leading the transfer of skutterudite thermoelectric couple technology to industry and leading the systems engineering of the proposed eMMRTG. Should NASA fund the flight development of an eMMRTG, the DOE would lead the flight system development. The analytical models and design of the MMRTG have been enhanced to use skutterudite couples developed at Jet Propulsion Laboratory over the last two decades. This required a thorough evaluation of the MMRTG design, and concurrent engineering of an enhanced MMRTG to shed light on potential design issues or risks. At the end of the U.S. fiscal year (FY) 2015, a complete catalog of risks was produced. Tests, hardware development, and analyses have now been put in place to mitigate those risks to acceptable levels. Few risks can ever be truly eliminated unless a design is modified to eliminate specific risks and not introduce more severe risks. The design imperative for the eMMRTG is to change only a few MMRTG features; therefore, risks can largely only be mitigated, not eliminated, through design changes. However, many risks can be effectively - though not totally - eliminated without design changes. This paper briefly describes some of the documented risks and mitigations or reduction approaches to be applied in the coming 3 years, on the way to completing the eMMRTG concept.

eMMRTG↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

Recovery of Space Shuttle Columbia and Return to Flight of Space Shuttle Discovery

NASA has come a long way in our journey to reduce the risks of operating the Spse Shuttle system. The External Tank bipod Thermal Protection System has been redesigned to eliminate the proximate cause of the Columbia accident. In all areas, we have applied the collective knowledge and capabilities of our Nation to comply with the Columbia Accident Investigation Board recommendations and to raise the bar beyond that. We have taken prudent technical action on potential threats to review and verify the material condition of all critical areas where failure could result in catastrophic loss of the crew and vehicle. We are satisfied that critical systems and elements should operate as intended-safely and reliably. While we will never eliminate all the risks from our human space flight programs, we have eliminated those we can and reduced, controlled, and/or mitigated others. The remaining identified risks will be evaluated for acceptance. Our risk reduction approach has its roots in the system safety engineering hierarchy for hazard abatement long employed in aerospace systems engineering. The components of the hierarchy are, in order of precedence, to: design/redesign; eliminate the hazard/risk; reduce the hazard/risk; and control the hazard/risk and/or mitigate the consequence of the remaining hazard/risk through warning devices, special procedures/capabilities, and/or training. This proven approach to risk reduction has been applied to potential hazards and risks in all critical areas of the Space Shuttle and has guided us through the technical challenges, failures, and successes present in return to flight endeavors. This approach provides the structured deliberation process required to verify and form the foundation for accepting any residual risk across the entire Space Shuttle Program by NASA leadership.

Rudolphi, Michael U.↗

Adaptive Mission Assurance (AMA) – A Conceptual Guide for NASA Missions

NASA is well acquainted with and skilled in conducting Risk Class A Safety and Mission Assurance (SMA). Class A missions are characterized as having highly specific performance with an ultra-low risk tolerance for risk and mission failure. But space is rapidly changing, and the space enterprise is challenged to pursue faster more agile mission developments with fewer resources and directed schedules. To meet this demand mission development teams face accepting more risk and trading performance within strict cost and schedule constraints. In responding to this challenge, The Aerospace Corporation has evolved the Adaptive Mission Assurance (AMA) approach. The benefit of an “adaptive” approach is most realized for smaller Research and Development (R&D), or Science and Technology (S&T) demonstration missions constrained by significantly smaller budgets and directed schedules. The challenge for these “risk tolerant, constraints-driven” missions is how to identify the most valuable mission assurance tasks that will fit within strict budgetary and schedule constraints for “gracefully” accepting risk that still achieves an agreeable expectation of mission success. AMA can respond to this challenge with little to no impact to team staffing or existing workload. This conceptual guide introduces AMA as a potential implementation for NASA Risk Class D and Sub-Class D missions.

Douglas A. Harris↗

Analysis of Launch Vehicle Liftoff Debris: Historical Perspective from Space Shuttle and Application to Artemis I

Human exploration-class launch vehicles are inherently prone to debris due to the extreme environments generated during pre-launch operations, liftoff, and flight. The use of cryogenic propellants often requires thermal protection system (TPS) coatings, typically foam, to maintain the propellant conditions in the tank and prevent an accumulation ice on the external surface of the vehicle. Some ice growth is to be expected at umbilical interfaces, vents, flanges, or brackets where it is difficult to apply TPS. This ice may come loose at any time due to wind on the launch pad, structural vibration and acoustics after rocket ignition, or aerodynamic forces during flight. This phenomena is especially apparent on vehicles with no TPS, such as the Saturn V rockets used in the Apollo Program, see Figure 1. During propellant tanking, the thermal contraction of the underlying substrate may generate cracks in the TPS (Figure 1). Chunks of TPS can release due to the expansion of ingested gas from cryopumping or from aerodynamic forces if the crack creates an offset surface. Most foams will also have a certain amount of “popcorning” where small pieces of foam will pop off during flight because of the differential between the static surface pressure and the pressure of the gas trapped in the foam cell structure. There are a number of other coating or closeout materials that may be shed from the vehicle and become debris. During pre-launch operations and liftoff, the vehicle may also be exposed to debris originating from the launch pad or ground support equipment. This debris is separate from foreign object debris, or FOD, which is not intended to be present and is strictly controlled through operations and maintenance procedures. In this case, debris is generated from hardware and materials that are necessary for launch and are subject to the intense vibration, acoustics, and direct plume impingement of the launch environment. Examples include ice from umbilicals, tape and tie wraps that protect cables, and rust or corrosion from the launch platform. While NASA has historically been aware of debris as a potential issue that could cause a failure resulting in loss of mission, loss of vehicle, or loss of crew, the likelihood and severity of that risk was not always well understood or given sufficient weight in program and flight decisions. After the Space Shuttle Columbia accident (STS-107), the investigation found that foam TPS debris shed from the external tank was the proximate cause of the damage to the orbiter wing. Six previous observations of debris released from the foam ramp that covered the bipod connecting the forward end of the orbiter to the external tank resulted in minor changes or were determined to be accepted flight risks. Two occurrences of bipod ramp foam loss were not identified until the STS-107 investigation. Despite the damage inflicted by these debris strikes, the Shuttle Program Requirements Control Board deemed the vehicle safe to fly. During the Return to Flight effort following the Columbia disaster, NASA Engineering developed a process for the assessment of debris transport, impact, and damage tolerance to support independent assessments of risk by NASA Safety and Mission Assurance (S&MA). Under this system, each element (vehicle or ground system) defines a catalog of all expected debris based on launch history, component testing, or analysis. Debris transport analysis (DTA) is conducted using the debris catalog characteristics and potential flow transport mechanisms (e.g., vehicle aerodynamics, gravity, wind, plume-driven). The predicted debris impact locations and velocities are provided to the hardware owners, who use available test data and analysis to determine whether each component can withstand the impacts. In cases where the element hardware may be severely damaged or fail, the options are to mitigate the debris source through some change in design or operation, or to work with S&MA to try to characterize the probability of the impact and damage for program risk acceptance. Because of the differences in debris characteristics and transport, the DTA has been divided between the Liftoff and Ascent regimes. The development and application of Liftoff DTA methodology from the Shuttle Program to the current Artemis Program is the subject of this paper. Liftoff DTA covers the time from the start of pre-launch operations at the launch pad, up until the vehicle clears the launch tower and there is no longer any interaction with ground systems. Debris transport during this period is broadly classified as either gravity, wind, and plume-entrained (GWPE) or plume driven (PD). GWPE debris is generally lower speed, travelling in a forward-to-aft direction. PD transport includes flow features from the rocket ignition transient, as well as plume impingement and recirculation that occur as the vehicle lifts off the launch platform. In these cases, the debris typically moves in an aft-to-forward direction at higher speeds. The applicable transport mechanisms must be considered for each piece of debris depending on the material, and release location and time. For example, rust or metallic debris from the tower could fall (GWPE) and impact the vehicle before landing on the launch platform deck where it could be also be transported by plume impingement (PD). However, falling ice (GWPE) from an umbilical is unlikely to survive impact with the vehicle or launch platform and be available for PD transport. Modeling of debris transport is accomplished using a set of DTA tools which simulate debris trajectories subject to a reference frame acceleration (i.e., gravity) and aerodynamic drag. Where the trajectory encounters a solid surface, the debris is allowed to rebound with a specified coefficient of restitution. The drag is calculated by interpolating the fluid state at each point in the debris trajectory from high-fidelity computational fluid dynamics (CFD) simulations of the launch vehicle and pad. The CFD data may either be static (steady state or time averaged), typically for GWPE transport, or dynamic (time-accurate) for PD flow features like the ignition transient. Examples of the CFD flow field solutions for the Space Launch System (SLS) rocket and launch pad are shown in Figure 2. Typical SLS debris trajectory predictions from DTA are illustrated in Figure 3. The final version of this paper will include a more detailed examination of the Liftoff DTA process developed during the Shuttle Program, and how it has been augmented and applied to the SLS rocket under the Artemis Program. Comparisons with debris observations from the Artemis I launch will demonstrate validation of the tools and methodology.

Debris↗

Risk Management in EVA

This viewgraph presentation reviews the use of risk management in Extravehicular Activities (EVA). The contents include: 1) EVA Office at NASA - JSC; 2) EVA Project Risk Management: Why and When; 3) EVA Office Risk Management: How; 4) Criteria for Closing a Risk; 5) Criteria for Accepting a Risk; 6) ISS IRMA Reference Card Data Entry Requirement s; 7) XA/ EVA Office Risk Activity Summary; 8) EVA Significant Change Summary; 9) Integrated Risk Management Application (XA) Matrix, March 31, 2004; 10) ISS Watch Item: 50XX Summary Report; and 11) EVA Project RM Usefulness

Hall, Jonathan↗

The Mars Project: Avoiding Decompression Sickness on a Distant Planet

A cost-effective approach for Mars exploration is to use available resources, such as water and atmospheric gases. Nitrogen (N2) and argon (Ar) are available and could form the inert gas component of a habitat atmosphere at 8.0, 9.0, or 10.0 pounds per square inch (psia). The habitat and space suit are designed as an integrated system: a comfortable living environment about 85% of the time and a safe working environment about 15% of the time. A goal is to provide a system that permits unrestricted exploration of Mars, but the risk of decompression sickness (DCS) during the extravehicular activity in a 3.75-psia suit, after exposure to any of the three habitat conditions, may limit unrestricted exploration. I evaluate here the risk of DCS since a significant proportion of a trinary breathing gas in the habitat might contain Ar. I draw on past experience and published information to extrapolate into untested, multivariable conditions to evaluate risk. A rigorous assessment of risk as a probability of DCS for each habitat condition is not yet possible. Based on many assumptions about Ar in hypobaric decompressions, I conclude that the presence of Ar significantly increases the risk of DCS. The risk is significant even with the best habitat option: 2.56 psia oxygen, 3.41 psia N2, and 2.20 psia Ar. Several hours of prebreathing 100% 02, a higher suit pressure, or a combination of other important variables such as limited exposure time on the surface or exercise during prebreathe would be necessary to reduce the risk of DCS to an acceptable level. The acceptable level for DCS risk on Mars has not yet been determined. Mars is a great distance from Earth and therefore from primary medical care. The acceptable risk would necessarily be defined by the capability to treat DCS in the Rover vehicle, in the habitat, or both.

Conkin, Johnny↗

Effectiveness of Loan Guarantees versus Tax Incentives for Space Launch Ventures

Over the course of the past few years, several new and innovative fully or partiailly reusable launch vehicle designs have been initiated with the objective of reducing the cost of space transportation. These new designs are in various stages hardware development for technology and system demonstrators. The larger vehicles include the Lockheed Martin X-33 technology demonstrator for VentureStar and the Space Access launcher. The smaller launcher ventures include Kelly Space and Technology and Rotary Rocket Company. A common denominator between the new large and small commercial launch systems is the ability to obtain project financing and at an affordable cost. Both are having or will have great difficulty in obtaining financing in the capital markets because of the dollar amounts and the risk involved. The large established companies are pursuing multi-billion dollar developments which are a major challenge to finance because of the size and risk of the projects. The smaller start-up companies require less capital for their smaller systems, however, their lack of corporate financial muscle and launch vehicle track record results in a major challenge to obtain financing also because of high risk. On Wall Street, new launch system financing is a question of market, technical, organizational, legal/regulatory and financial risk. The current limit of acceptable financial risk for Space businesses on Wall Street are the telecommunications and broadcast satellite projects, of which many in number are projected for the future. Tbc recent problems with Iridium market and financial performance are casting a long shadow over new satellite project financing, making it increasingly difficult for the new satellite projects to obtain needed financing.

Scottoline, S.↗

Assessing the Risk of Crew Injury Due to Dynamic Loads During Spaceflight

Spaceflight requires tremendous amounts of energy to achieve Earth orbit and to attain escape velocity for interplanetary missions. Although the majority of the energy is managed in such a way as to limit the accelerations on the crew, several mission phases may result in crew exposure to dynamic loads. In the automotive industry, risk of serious injury can be tolerated because the probability of a crash is remote each time a person enters a vehicle, resulting in a low total risk of injury. For spaceflight, the level of acceptable injury risk must be lower to achieve a low total risk of injury because the dynamic loads are expected on each flight. To mitigate the risk of injury due to dynamic loads, the NASA Human Research Program has developed a research plan to inform the knowledge gaps and develop relevant tools for assessing injury risk. The risk of injury due to dynamic loads can be further subdivided into extrinsic and intrinsic risk factors. Extrinsic risk factors include the vehicle dynamic profile, seat and restraint design, and spacesuit design. Human tolerance to loads varies considerably depending on the direction, amplitude, and rise-time of acceleration therefore the orientation of the body to the dynamic vector is critical to determining crew risk of injury. Although a particular vehicle dynamic profile may be safe for a particular design, the seat, restraint, and suit designs can affect the risk of injury due to localized effects. In addition, characteristics intrinsic to the crewmember may also contribute to the risk of injury, such as crewmember sex, age, anthropometry, and deconditioning due to spaceflight, and each astronaut may have a different risk profile because of these factors. The purpose of the research plan is to address any knowledge gaps in the risk factors to mitigate injury risk. Methods for assessing injury risk have been well documented in other analogous industries and include human volunteer testing, human exposure to dynamic environments, post-mortem human subject (PMHS) testing, animal testing, anthropomorphic test devices (ATD), dynamic models of the human, numerical models of ATDs, and numerical models of the human. Each has inherent strengths and limitations. For example, human volunteer testing is advantageous because a population can be selected that is similar to the astronaut corps; however, because of the inherent ethical limitations, only sub-injurious conditions can be tested. PMHSs can be tested in a variety of conditions including injurious levels, but the responses are not completely analogous to living human subjects. In addition, it is exceedingly difficult to select a PMHS population that is similar to the astronaut corps. ATDs are currently widely used in the automotive industry and military because they are highly repeatable and durable. Unfortunately, because they are mechanical models of the human body, the biofidelity of the responses are limited to dynamic conditions used to validate the ATD. Numerical models of the ATD, in addition to the strengths and limitations for ATDs, are easy to use for a variety of designs before a design is fabricated, but also have additional limitations for ATDs, are easy to use for a variety of designs before a design is fabricated, but also have additional uncertainty. Dynamic models are simple and easy to use, but do not account for localized effects of the seat and suit. Finally, numerical models of the human have the potential to have the most advantages; however, the current models are not validated for the conditions expected during spaceflight. To properly assess spaceflight conditions with numerical human models, human data would be needed to optimize the model responses for those conditions. Using the appropriate assessment method with the knowledge gained for each risk factor, an appropriate approach for mitigating the risk of injury due to dynamic loads can be developed ensuring crew safety in future NASA vehicles.

Somers, J. T.↗

DCS: A Case Study of Identification of Knowledge and Disposition Gaps Using Principles of Continuous Risk Management

The Human Research Program (HRP) is formulated around the program architecture of Evidence-Risk-Gap-Task-Deliverable. Review of accumulated evidence forms the basis for identification of high priority risks to human health and performance in space exploration. Gaps in knowledge or disposition are identified for each risk, and a portfolio of research tasks is developed to fill them. Deliverables from the tasks inform the evidence base with the ultimate goal of defining the level of risk and reducing it to an acceptable level. A comprehensive framework for gap identification, focus, and metrics has been developed based on principles of continuous risk management and clinical care. Research towards knowledge gaps improves understanding of the likelihood, consequence or timeframe of the risk. Disposition gaps include development of standards or requirements for risk acceptance, development of countermeasures or technology to mitigate the risk, and yearly technology assessment related to watching developments related to the risk. Standard concepts from clinical care: prevention, diagnosis, treatment, monitoring, rehabilitation, and surveillance, can be used to focus gaps dealing with risk mitigation. The research plan for the new HRP Risk of Decompression Sickness (DCS) used the framework to identify one disposition gap related to establishment of a DCS standard for acceptable risk, two knowledge gaps related to DCS phenomenon and mission attributes, and three mitigation gaps focused on prediction, prevention, and new technology watch. These gaps were organized in this manner primarily based on target for closure and ease of organizing interim metrics so that gap status could be quantified. Additional considerations for the knowledge gaps were that one was highly design reference mission specific and the other gap was focused on DCS phenomenon.

Norcross, Jason↗

Managing Risk to Ensure a Successful Cassini/Huygens Saturn Orbit Insertion (SOI)

I. Design: a) S/C designed to be largely single fault tolerant; b) Operate in flight demonstrated envelope, with margin; and c) Strict compliance with requirements & flight rules. II. Test: a) Baseline, fault & stress testing using flight system testbeds (H/W & S/W); b) In-flight checkout & demos to remove first time events. III. Failure Analysis: a) Critical event driven fault tree analysis; b) Risk mitigation & development of contingencies. IV) Residual Risks: a) Accepted pre-launch waivers to Single Point Failures; b) Unavoidable risks (e.g. natural disaster). V) Mission Assurance: a) Strict process for characterization of variances (ISAs, PFRs & Waivers; b) Full time Mission Assurance Manager reports to Program Manager: 1) Independent assessment of compliance with institutional standards; 2) Oversight & risk assessment of ISAs, PFRs & Waivers etc.; and 3) Risk Management Process facilitator.

risk managment↗

Characterization of Evidence for Human System Risk Assessment

Understanding the kinds of evidence available and using the best evidence to answer a question is critical to evidenced-based decision-making, and it requires synthesis of evidence from a variety of sources. Categorization of human system risks in spaceflight, in particular, focuses on how well the integration and interpretation of all available evidence informs the risk statement that describes the relationship between spaceflight hazards and an outcome of interest. A mature understanding and categorization of these risks requires: 1) sufficient characterization of risk, 2) sufficient knowledge to determine an acceptable level of risk (i.e., a standard), 3) development of mitigations to meet the acceptable level of risk, and 4) identification of factors affecting generalizability of the evidence to different design reference missions. In the medical research community, evidence is often ranked by increasing confidence in findings gleaned from observational and experimental research (e.g., "levels of evidence"). However, an approach based solely on aspects of experimental design is problematic in assessing human system risks for spaceflight. For spaceflight, the unique challenges and opportunities include: (1) The independent variables in most evidence are the hazards of spaceflight, such as space radiation or low gravity, which cannot be entirely duplicated in terrestrial (Earth-based) analogs, (2) Evidence is drawn from multiple sources including medical and mission operations, Lifetime Surveillance of Astronaut Health (LSAH), spaceflight research (LSDA), and relevant environmental & terrestrial databases, (3) Risk metrics based primarily on LSAH data are typically derived from available prevalence or incidence data, which may limit rigorous interpretation, (4) The timeframe for obtaining adequate spaceflight sample size (n) is very long, given the small population, (5) Randomized controlled trials are unattainable in spaceflight, (6) Collection of personal and environmental data on the astronaut population may create opportunities for advanced analytics and human-environment modeling that goes beyond that achieved in isolated experimental designs; and (7) Translation of relevant research to operations is a complex, transdisciplinary enterprise in which the approach must apply across the physical, biological, behavioral, and social sciences. The approach to synthesizing evidence must address both source and fidelity of data, and reflect the most general attributes of quality of evidence in science and engineering: reliability and validity. The authors are developing a two-factor approach which includes the various kinds of evidence required to understand risks and for the integrated interpretation of all evidence that is essential to develop standards and countermeasures. A unified framework for aggregating and assessing different kinds of evidence provides a consistent, traceable, evidence-based decision-making process to translate research to operations in an environment where engineers, scientists, physicians, and managers all engage in analyzing the trade space of vehicle design, standards, requirements and solutions for spaceflight.

Steinberg, S. L.↗

A Team Mental Model Perspective of Pre-Quantitative Risk

This study was conducted to better understand how teams conceptualize risk before it can be quantified, and the processes by which a team forms a shared mental model of this pre-quantitative risk. Using an extreme case, this study analyzes seven months of team meeting transcripts, covering the entire lifetime of the team. Through an analysis of team discussions, a rich and varied structural model of risk emerges that goes significantly beyond classical representations of risk as the product of a negative consequence and a probability. In addition to those two fundamental components, the team conceptualization includes the ability to influence outcomes and probabilities, networks of goals, interaction effects, and qualitative judgments about the acceptability of risk, all affected by associated uncertainties. In moving from individual to team mental models, team members employ a number of strategies to gain group recognition of risks and to resolve or accept differences.

Cooper, Lynne P.↗

Autonomous Congestion Control in Delay-Tolerant Networks

Congestion control is an important feature that directly affects network performance. Network congestion may cause loss of data or long delays. Although this problem has been studied extensively in the Internet, the solutions for Internet congestion control do not apply readily to challenged network environments such as Delay Tolerant Networks (DTN) where end-to-end connectivity may not exist continuously and latency can be high. In DTN, end-to-end rate control is not feasible. This calls for congestion control mechanisms where the decisions can be made autonomously with local information only. We use an economic pricing model and propose a rule-based congestion control mechanism where each router can autonomously decide on whether to accept a bundle (data) based on local information such as available storage and the value and risk of accepting the bundle (derived from historical statistics). Preliminary experimental results show that this congestion control mechanism can protect routers from resource depletion without loss of data.

delay-tolerant networking↗

Autonomous Congestion Control in Delay-Tolerant Networks

Congestion control is an important feature that directly affects network performance. Network congestion may cause loss of data or long delays. Although this problem has been studied extensively in the Internet, the solutions for Internet congestion control do not apply readily to challenged network environments such as Delay Tolerant Networks (DTN) where end-to-end connectivity may not exist continuously and latency can be high. In DTN, end-to-end rate control is not feasible. This calls for congestion control mechanisms where the decisions can be made autonomously with local information only. We use an economic pricing model and propose a rule-based congestion control mechanism where each router can autonomously decide on whether to accept a bundle (data) based on local information such as available storage and the value and risk of accepting the bundle (derived from historical statistics).

delay tolerant networking↗

Safer Liquid Natural Gas

After the disaster of Staten Island in 1973 where 40 people were killed repairing a liquid natural gas storage tank, the New York Fire Commissioner requested NASA's help in drawing up a comprehensive plan to cover the design, construction, and operation of liquid natural gas facilities. Two programs are underway. The first transfers comprehensive risk management techniques and procedures which take the form of an instruction document that includes determining liquid-gas risks through engineering analysis and tests, controlling these risks by setting up redundant fail safe techniques, and establishing criteria calling for decisions that eliminate or accept certain risks. The second program prepares a liquid gas safety manual (the first of its kind).

Source record↗

"Making Safety Happen" Through Probabilistic Risk Assessment at NASA

NASA is using Probabilistic Risk Assessment (PRA) as one of the tools in its Safety & Mission Assurance (S&MA) tool belt to identify and quantify risks associated with human spaceflight. This paper discusses some of the challenges and benefits associated with developing and using PRA for NASA human space programs. Some programs have entered operation prior to developing a PRA, while some have implemented PRA from the start of the program. It has been observed that the earlier a design change is made in the concept or design phase, the less impact it has on cost and schedule. Not finding risks until the operation phase yields much costlier design changes and major delays, which can result in discussions of just accepting the risk. Risk contributors identified by PRA are not just associated with hardware failures. They include but are not limited to crew fatality due to medical causes, the environment the vehicle and crew are exposed to, the software being used, and the reliability of the crew performing required actions. Some programs have entered operation prior to developing a PRA, and while PRA can still provide a benefit for operations and future design trades, the benefit of implementing PRA from the start of the program provides the added benefit of informing design and reducing risk early in program development. Currently, NASA’s International Space Station (ISS) program is in its 20th year of on-orbit operations around the Earth and has several new programs in the design phase preparing to enter the operation phase all of which have active (or living) PRAs. These programs incorporate PRA as part of their Risk-Informed, Decision-Making (RIDM) process. For new NASA human spaceflight programs discussion begins with mission concept, establishing requirements, forming the PRA team, and continues through the design cycles into the operational phase. Several examples of PRA related applications and observed lessons are included.

Applications↗

Risk Management for Human Support Technology Development

NASA requires continuous risk management for all programs and projects. The risk management process identifies risks, analyzes their impact, prioritizes them, develops and carries out plans to mitigate or accept them, tracks risks and mitigation plans, and communicates and documents risk information. Project risk management is driven by the project goal and is performed by the entire team. Risk management begins early in the formulation phase with initial risk identification and development of a risk management plan and continues throughout the project life cycle. This paper describes the risk management approach that is suggested for use in NASA's Human Support Technology Development. The first step in risk management is to identify the detailed technical and programmatic risks specific to a project. Each individual risk should be described in detail. The identified risks are summarized in a complete risk list. Risk analysis provides estimates of the likelihood and the qualitative impact of a risk. The likelihood and impact of the risk are used to define its priority location in the risk matrix. The approaches for responding to risk are either to mitigate it by eliminating or reducing the effect or likelihood of a risk, to accept it with a documented rationale and contingency plan, or to research or monitor the risk, The Human Support Technology Development program includes many projects with independently achievable goals. Each project must do independent risk management, considering all its risks together and trading them against performance, budget, and schedule. Since the program can succeed even if some projects fail, the program risk has a complex dependence on the individual project risks.

jones, Harry↗