Search NASA⌕ Search

SEARCH · Search NASA

Results for “Systems Engineering, Failure Prevention”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

100 records · Page 6

Preliminary Analysis of Aircraft Loss of Control Accidents: Worst Case Precursor Combinations and Temporal Sequencing

Aircraft loss of control (LOC) is a leading cause of fatal accidents across all transport airplane and operational classes, and can result from a wide spectrum of hazards, often occurring in combination. Technologies developed for LOC prevention and recovery must therefore be effective under a wide variety of conditions and uncertainties, including multiple hazards, and their validation must provide a means of assessing system effectiveness and coverage of these hazards. This requires the definition of a comprehensive set of LOC test scenarios based on accident and incident data as well as future risks. This paper defines a comprehensive set of accidents and incidents over a recent 15 year period, and presents preliminary analysis results to identify worst-case combinations of causal and contributing factors (i.e., accident precursors) and how they sequence in time. Such analyses can provide insight in developing effective solutions for LOC, and form the basis for developing test scenarios that can be used in evaluating them. Preliminary findings based on the results of this paper indicate that system failures or malfunctions, crew actions or inactions, vehicle impairment conditions, and vehicle upsets contributed the most to accidents and fatalities, followed by inclement weather or atmospheric disturbances and poor visibility. Follow-on research will include finalizing the analysis through a team consensus process, defining future risks, and developing a comprehensive set of test scenarios with correlation to the accidents, incidents, and future risks. Since enhanced engineering simulations are required for batch and piloted evaluations under realistic LOC precursor conditions, these test scenarios can also serve as a high-level requirement for defining the engineering simulation enhancements needed for generating them.

Belcastro, Christine M.↗

Micrometeoroid and Orbital Debris (MMOD) Testing, Ballistic Limit Definition and Risk Assessment of the Exploration Extravehicular Mobility Unit (xEMU)

A well-known hazard associated with exposure to the space environment is the risk of failure due to an impact from a micrometeoroid and orbital debris (MMOD) particle. As NASA prepares to return astronauts to the moon with the Artemis program, the next generation of spacesuit is in development to support future extravehicular activities (EVAs.) An MMOD impact to the spacesuit is of great concern as a large leak could prevent an astronaut from safely reaching an airlock in time resulting in a loss of life. The exploration extravehicular mobility unit (xEMU) must meet MMOD requirements for multiple environments including those in low earth orbit (LEO) as well as the meteoroid and secondary lunar regolith ejecta environments found on the lunar surface. The subject of this paper is an internal xEMU configuration design developed by NASA Johnson Space Center (JSC) personnel. The xEMU shares similarities with the legacy Extravehicular Mobility Unit (EMU) spacesuit that is currently used for ISS EVAs, however differences in the layup (e.g., materials, thicknesses, and layers) of the fabric environmental protection garment (EPG), portable life support system (xPLSS) and helmet required an extensive test program to determine ballistic performance. Over 100 hypervelocity impact (HVI) tests were performed by the NASA/JSC HVIT and White Sands Test Facility (WSTF) teams on the xEMU EPG, xPLSS and helmet to generate ballistic limit equations (BLEs) for MMOD impacts. Additionally, over 50 low speed tests (< 1km/s) were performed by the NASA/JSC HVIT and Southwest Research Institute (SwRI) teams on the xEMU EPG, xPLSS and helmet to generate BLEs for lunar ejecta impacts. Post testing, ballistic limit equations (BLEs) used to define the performance of the various regions on the xEMU spacesuit were developed from a generic set of BLEs. The HVI and low speed testing was performed to establish a physical basis for the equations with the coefficients and exponents of the generic BLEs adjusted to fit the test data. The xEMU BLEs were added to the NASA/JSC software application used for spacecraft MMOD risk assessments (BUMPER-3). A finite element model (FEM) of the xEMU spacesuit, which defines the size and shape of the spacesuit as well as the locations of the various shielding configurations, was created based on a solid model provided by the xEMU program office. Using the FEM file and added xEMU BLEs, BUMPER-3 assessments of the xEMU spacesuit for probability of no penetration (PNP) were performed. For the LEO assessment of a typical ISS EVA, the orbital debris and meteoroids environments were defined using the latest engineering models, ORDEM 3.2 and MEM-3 respectively. The lunar surface assessment again used the MEM-3 engineering model to define the meteoroid environment along with the current released lunar surface ejecta model, NASA SP-8013 (developed during the Apollo Program). The Space Team in the Natural Environments Branch at Marshall Space Flight Center (MSFC) will soon release the new Lunar Meteoroid Ejecta Engineering Model (LMEEM), at which time the xEMU lunar surface EVA will be reassessed. Assessment of the MMOD risk for an 8-hour, 2-person EVA in both LEO and on the lunar surface showed that the xEMU spacesuit meets the program technical requirement of 1 in 2500 failure odds. Similar to the legacy EMU spacesuit, the majority of the MMOD risk (96% of the LEO EVA risk and 99% of the lunar surface EVA risk) is concentrated in regions of xEMU that are comprised primarily of softgoods (arms, legs, and gloves) rather than the hardgoods (xPLSS, hard upper torso and helmet).

Micrometeoroid↗

Analysis of Launch Vehicle Liftoff Debris: Historical Perspective from Space Shuttle and Application to Artemis I

Human exploration-class launch vehicles are inherently prone to debris due to the extreme environments generated during pre-launch operations, liftoff, and flight. The use of cryogenic propellants often requires thermal protection system (TPS) coatings, typically foam, to maintain the propellant conditions in the tank and prevent an accumulation ice on the external surface of the vehicle. Some ice growth is to be expected at umbilical interfaces, vents, flanges, or brackets where it is difficult to apply TPS. This ice may come loose at any time due to wind on the launch pad, structural vibration and acoustics after rocket ignition, or aerodynamic forces during flight. This phenomena is especially apparent on vehicles with no TPS, such as the Saturn V rockets used in the Apollo Program, see Figure 1. During propellant tanking, the thermal contraction of the underlying substrate may generate cracks in the TPS (Figure 1). Chunks of TPS can release due to the expansion of ingested gas from cryopumping or from aerodynamic forces if the crack creates an offset surface. Most foams will also have a certain amount of “popcorning” where small pieces of foam will pop off during flight because of the differential between the static surface pressure and the pressure of the gas trapped in the foam cell structure. There are a number of other coating or closeout materials that may be shed from the vehicle and become debris. During pre-launch operations and liftoff, the vehicle may also be exposed to debris originating from the launch pad or ground support equipment. This debris is separate from foreign object debris, or FOD, which is not intended to be present and is strictly controlled through operations and maintenance procedures. In this case, debris is generated from hardware and materials that are necessary for launch and are subject to the intense vibration, acoustics, and direct plume impingement of the launch environment. Examples include ice from umbilicals, tape and tie wraps that protect cables, and rust or corrosion from the launch platform. While NASA has historically been aware of debris as a potential issue that could cause a failure resulting in loss of mission, loss of vehicle, or loss of crew, the likelihood and severity of that risk was not always well understood or given sufficient weight in program and flight decisions. After the Space Shuttle Columbia accident (STS-107), the investigation found that foam TPS debris shed from the external tank was the proximate cause of the damage to the orbiter wing. Six previous observations of debris released from the foam ramp that covered the bipod connecting the forward end of the orbiter to the external tank resulted in minor changes or were determined to be accepted flight risks. Two occurrences of bipod ramp foam loss were not identified until the STS-107 investigation. Despite the damage inflicted by these debris strikes, the Shuttle Program Requirements Control Board deemed the vehicle safe to fly. During the Return to Flight effort following the Columbia disaster, NASA Engineering developed a process for the assessment of debris transport, impact, and damage tolerance to support independent assessments of risk by NASA Safety and Mission Assurance (S&MA). Under this system, each element (vehicle or ground system) defines a catalog of all expected debris based on launch history, component testing, or analysis. Debris transport analysis (DTA) is conducted using the debris catalog characteristics and potential flow transport mechanisms (e.g., vehicle aerodynamics, gravity, wind, plume-driven). The predicted debris impact locations and velocities are provided to the hardware owners, who use available test data and analysis to determine whether each component can withstand the impacts. In cases where the element hardware may be severely damaged or fail, the options are to mitigate the debris source through some change in design or operation, or to work with S&MA to try to characterize the probability of the impact and damage for program risk acceptance. Because of the differences in debris characteristics and transport, the DTA has been divided between the Liftoff and Ascent regimes. The development and application of Liftoff DTA methodology from the Shuttle Program to the current Artemis Program is the subject of this paper. Liftoff DTA covers the time from the start of pre-launch operations at the launch pad, up until the vehicle clears the launch tower and there is no longer any interaction with ground systems. Debris transport during this period is broadly classified as either gravity, wind, and plume-entrained (GWPE) or plume driven (PD). GWPE debris is generally lower speed, travelling in a forward-to-aft direction. PD transport includes flow features from the rocket ignition transient, as well as plume impingement and recirculation that occur as the vehicle lifts off the launch platform. In these cases, the debris typically moves in an aft-to-forward direction at higher speeds. The applicable transport mechanisms must be considered for each piece of debris depending on the material, and release location and time. For example, rust or metallic debris from the tower could fall (GWPE) and impact the vehicle before landing on the launch platform deck where it could be also be transported by plume impingement (PD). However, falling ice (GWPE) from an umbilical is unlikely to survive impact with the vehicle or launch platform and be available for PD transport. Modeling of debris transport is accomplished using a set of DTA tools which simulate debris trajectories subject to a reference frame acceleration (i.e., gravity) and aerodynamic drag. Where the trajectory encounters a solid surface, the debris is allowed to rebound with a specified coefficient of restitution. The drag is calculated by interpolating the fluid state at each point in the debris trajectory from high-fidelity computational fluid dynamics (CFD) simulations of the launch vehicle and pad. The CFD data may either be static (steady state or time averaged), typically for GWPE transport, or dynamic (time-accurate) for PD flow features like the ignition transient. Examples of the CFD flow field solutions for the Space Launch System (SLS) rocket and launch pad are shown in Figure 2. Typical SLS debris trajectory predictions from DTA are illustrated in Figure 3. The final version of this paper will include a more detailed examination of the Liftoff DTA process developed during the Shuttle Program, and how it has been augmented and applied to the SLS rocket under the Artemis Program. Comparisons with debris observations from the Artemis I launch will demonstrate validation of the tools and methodology.

Debris↗

Micrometeoroid and Orbital Debris (MMOD) Testing, Ballistic Limit Equation Definition and Risk Assessment of the Exploration Extravehicular Mobility Unit (xEMU)

A well-known hazard associated with exposure to the space environment is the risk of failure due to an impact from a micrometeoroid and orbital debris (MMOD) particle. As NASA prepares to return astronauts to the moon with the Artemis program, the next generation of spacesuit is in development to support future extravehicular activities (EVAs.) An MMOD impact to the spacesuit is of great concern as a large leak could prevent an astronaut from safely reaching an airlock in time resulting in a loss of life. The exploration extravehicular mobility unit (xEMU) must meet MMOD requirements for multiple environments including those in low earth orbit (LEO) as well as the meteoroid and secondary lunar regolith ejecta environments found on the lunar surface. The subject of this paper is an internal xEMU configuration design developed by NASA Johnson Space Center (JSC) personnel. This paper will expand on the hypervelocity impact (HVI) testing and ballistic limit equation (BLE) definition work that was partially presented at the 2nd International Orbital De-bris (IOC-II) Conference held in Sugar Land, TX in December 2023. The xEMU shares similarities with the legacy Extravehicular Mobility Unit (EMU) spacesuit that is currently used for ISS EVAs, however differences in the layup (e.g., materials, thicknesses, and layers) of the fabric environmental protection garment (EPG), portable life support system (xPLSS) and helmet required an extensive test program to determine ballistic performance. Over 100 hypervelocity impact (HVI) tests were performed by the NASA/JSC HVIT and White Sands Test Facility (WSTF) teams on the xEMU EPG, xPLSS and helmet to generate ballistic limit equations (BLEs) for MMOD impacts. Additionally, over 50 low speed tests (< 1km/s) were performed by the NASA/JSC HVIT and Southwest Research Institute (SwRI) teams on the xEMU EPG, xPLSS and helmet to generate BLEs for lunar ejecta impacts. Post testing, ballistic limit equations used to define the performance of the various regions on the xEMU spacesuit were developed from a generic set of BLEs. The HVI and low speed testing was performed to establish a physical basis for the equations with the co-efficients and exponents of the generic BLEs adjusted to fit the test data. The xEMU BLEs were added to the NASA/JSC software application used for space-craft MMOD risk assessments (BUMPER-3). A finite element model (FEM) of the xEMU spacesuit, which defines the size and shape of the spacesuit as well as the locations of the various shielding configurations, was created based on a solid model provided by the xEMU program office. Using the FEM file and added xEMU BLEs, BUMPER-3 assessments of the xEMU spacesuit for probability of no penetration (PNP) were performed. For the LEO assessment of a typical ISS EVA, the orbital debris and meteoroids environments were defined using the latest engineering models, ORDEM 3.2 and MEM-3 respectively. The lunar sur-face assessment again used the MEM-3 engineering model to define the meteoroid environ-ment along with the current released lunar surface ejecta model, NASA SP-8013 (developed during the Apollo Program). The Space Team in the Natural Environments Branch at Mar-shall Space Flight Center (MSFC) will soon release the new Lunar Meteoroid Ejecta Engineering Model (LMEEM), at which time the xEMU lunar surface EVA will be reassessed. Assessment of the MMOD risk for an 8-hour, 2-person EVA in both LEO and on the lunar surface showed that the xEMU spacesuit meets the program technical requirement of 1 in 2500 failure odds. Similar to the legacy EMU spacesuit, the majority of the MMOD risk (96% of the LEO EVA risk and 99% of the lunar surface EVA risk) is concentrated in regions of xEMU that are comprised primarily of softgoods (arms, legs, and gloves) rather than the hardgoods (xPLSS, hard upper torso and helmet).

Micrometeoroid↗

Accelerometer method and apparatus for integral display and control functions

Vibration analysis has been used for years to provide a determination of the proper functioning of different types of machinery, including rotating machinery and rocket engines. A determination of a malfunction, if detected at a relatively early stage in its development, will allow changes in operating mode or a sequenced shutdown of the machinery prior to a total failure. Such preventative measures result in less extensive and/or less expensive repairs, and can also prevent a sometimes catastrophic failure of equipment. Standard vibration analyzers are generally rather complex, expensive, and of limited portability. They also usually result in displays and controls being located remotely from the machinery being monitored. Consequently, a need exists for improvements in accelerometer electronic display and control functions which are more suitable for operation directly on machines and which are not so expensive and complex. The invention includes methods and apparatus for detecting mechanical vibrations and outputting a signal in response thereto. The apparatus includes an accelerometer package having integral display and control functions. The accelerometer package is suitable for mounting upon the machinery to be monitored. Display circuitry provides signals to a bar graph display which may be used to monitor machine condition over a period of time. Control switches may be set which correspond to elements in the bar graph to provide an alert if vibration signals increase over the selected trip point. The circuitry is shock mounted within the accelerometer housing. The method provides for outputting a broadband analog accelerometer signal, integrating this signal to produce a velocity signal, integrating and calibrating the velocity signal before application to a display driver, and selecting a trip point at which a digitally compatible output signal is generated. The benefits of a vibration recording and monitoring system with controls and displays readily mountable on the machinery being monitored and having capabilities described will be appreciated by those working in the art.

Bozeman, Richard J., Jr.↗

NASA-DoD Lead-Free Electronics Project. DRAFT Joint Test Report

The use of conventional tin-lead (SnPb) in circuit board manufacturing is under ever-increasing political scrutiny due to increasing regulations concerning lead. The "Restriction of Hazardous Substances" (RoHS) directive enacted by the European Union (EU) and a pact between the United States National Electronics Manufacturing Initiative (NEMI), Europe's Soldertec at Tin Technology Ltd. and the Japan Electronics and Information Technology Industries Association (JEITA) are just two examples where worldwide legislative actions and partnerships/agreements are affecting the electronics industry. As a result, many global commercial-grade electronic component suppliers are initiating efforts to transition to lead-free (Pb-free) in order to retain their worldwide market. Pb-free components are likely to find their way into the inventory of aerospace or military assembly processes under current government acquisition reform initiatives. Inventories "contaminated" by Pb-free will result in increased risks associated with the manufacturing, product reliability, and subsequent repair of aerospace and military electronic systems. Although electronics for military and aerospace applications are not included in the RoHS legislation, engineers are beginning to find that the commercial industry's move towards RoHS compliance has affected their supply chain and changed their parts. Most parts suppliers plan to phase out their non-compliant, leaded production and many have already done so. As a result, the ability to find leaded components is getting harder and harder. Some buyers are now attempting to acquire the remaining SnPb inventory, if it's not already obsolete. Original Equipment Manufacturers (OEMs), depots, and support contractors have to be prepared to deal with an electronics supply chain that increasingly provides more and more parts with Pb-free finishes-some labeled no differently than their Pb counterparts-while at the same time providing the traditional Pb parts. The longer the transition period, the greater the likelihood of Pb-free parts inadvertently being mixed with Pb parts and ending up on what are supposed to be Pb systems. As a result, OEMs, depots, and support contractors need to take action now to either abate the influx of Pb-free parts, or accept it and deal with the likely interim consequences of reduced reliability due to a wide variety of matters, such as Pb contamination, high temperature incompatibility, and tin whiskering. Allowance of Pb-free components produces one of the greatest risks to the reliability of a weapon system. This is due to new and poorly understood failure mechanisms, as well as unknown long-term reliability. If the decision is made to consciously allow Pb-free solder and component finishes into SnPb electronics, additional effort (and cost) will be required to make the significant number of changes to drawings and task order procedures. This project is a follow-on effort to the Joint Council on Aging Aircraft/Joint Group on Pollution Prevention (JCAA/JG-PP) Pb-free Solder Project which was the first group to test the reliability of Pb-free solder joints against the requirements of the aerospace and military community.

Kessel, Kurt↗

Importance of Contrast-to-Noise Ratio Sensitivity Function in Nondestructive Evaluation

A reliable nondestructive evaluation (NDE) technique provides minimum 90% probability of detection (POD) with 95% confidence for detection of cracklike flaws of a specific size. This requirement comes from fracture control. Fracture control is a risk assessment and control approach for preventing structural failure of fracture critical hardware during its service life. One of the approaches of fracture control is damage tolerance safe life analysis, which assumes that NDE reliably detectable size flaw may exist in the hardware post nondestructive evaluation. Analysis and/or testing are performed to verify that the hardware will not fail during its service life despite existence of such a flaw. NDE methods are conventionally qualified by probability of detection (POD) demonstration testing to ensure reliable flaw detection. Here, a novel and alternative to POD flaw detection reliability approach that uses contrast-to-noise ratio (CNR) is given. The approach uses CNR sensitivity function (SF) and CNR. CNR SF is the minimum CNR needed for reliable flaw detection as a function of certain flaw indication characteristics. Primary difference between POD approaches and CNR flaw detection reliability approach is resolution of flaw detection system. POD approach does not account for the resolution of the system, while CNR approach accounts for the flaw detection resolution. Resolution is determined from the modulation transfer function (MTF) of the flaw detection system. CNR flaw detection reliability approach emphasizes quantitative assessment of “how well each flaw indication is detected”. Therefore, CNR approach is helpful in reducing number of flaws in the sample used in NDE procedure qualification, resulting in cost and time savings. CNR approach is also a case of multi-hit flaw detection analysis which has better flaw detectability size than conventional single-hit flaw detectability. Thus, CNR approach, where applicable, may be superior to conventional POD approach. The paper is an overview of development of CNR modeling, CNR SF modeling and measurement by the author. The paper gives key references to currently used NDE procedure POD qualification approaches including those specific to CNR and CNR SF development in multi-hit flaw detection in NDE. The paper covers core topics in nondestructive evaluation engineering.

Contrast-to-noise ratio↗

Computational Analyses in Support of Sub-scale Diffuser Testing for the A-3 Facility: Unsteady Analyses and Risk Assessment - Part 2

Simulation technology can play an important role in rocket engine test facility design and development by assessing risks, providing analysis of dynamic pressure and thermal loads, identifying failure modes and predicting anomalous behavior of critical systems. This is especially true for facilities such as the proposed A-3 facility at NASA SSC because of a challenging operating envelope linked to variable throttle conditions at relatively low chamber pressures. Design Support of the feasibility of operating conditions and procedures is critical in such cases due to the possibility of startup/shutdown transients, moving shock structures, unsteady shock-boundary layer interactions and engine and diffuser unstart modes that can result in catastrophic failure. Analyses of such systems is difficult due to resolution requirements needed to accurately capture moving shock structures, shock-boundary layer interactions, two-phase flow regimes and engine unstart modes. In a companion paper, we will demonstrate with the use of CFD, steady analyses advanced capability to evaluate supersonic diffuser and steam ejector performance in the sub-scale A-3 facility. In this paper we will address transient issues with the operation of the facility especially at startup and shutdown, and assess risks related to afterburning due to the interaction of a fuel rich plume with oxygen that is a by-product of the steam ejectors. The primary areas that will be addressed in this paper are: (1) analyses of unstart modes due to flow transients especially during startup/ignition, (2) engine safety during the shutdown process (3) interaction of steam ejectors with the primary plume i.e. flow transients as well as probability of afterburning. In this abstract we discuss unsteady analyses of the engine shutdown process. However, the final paper will include analyses of a staged startup, drawdown of the engine test cell pressure, and risk assessment of potential afterburning in the facility. Unsteady simulations have been carried out to study the engine shutdown process in the facility and understand the physics behind the interactions between the steam ejectors, the test cell and the supersonic diffuser. As a first approximation, to understand the dominant unsteady mechanisms in the engine test cell and the supersonic diffuser, the turning duct in the facility was removed. As the engine loses power a rarefaction wave travels downstream that disrupts the shock cell structure in the supersonic diffuser. Flow from the test cell is seen to expand into the supersonic diffuser section and re-pressurizes the area around the nozzle along with a upstream traveling compression wave that emanates from near the first stage ejectors. Flow from the first stage ejector expands to the center of the duct and a new shock train is formed between the first and second stage ejectors. Both stage ejectors keep the facility pressurized and prevent any large amplitude pressure fluctuations from affecting the engine nozzle. The resultant pressure loads the nozzle experiences in the shutdown process are small.

Ahuja, Vineet↗

Topology-Aware Reinforcement Learning for Voltage Control: Centralized and Decentralized Strategies

Volt-VAR control (VVC) methods based on deep reinforcement learning (DRL) can effectively control distribution grid voltage and minimize power loss by implementing corrective and preventive control measures on the reactive power output of inverter-based distributed energy resources (DERs). However, model-free DRL-based VVC approaches usually cannot capture the important topological feature of the power system since they use a fully-connected network (FCN) to deliver the action. Therefore, this paper proposes a graph convolutional network (GCN)-based DRL approach that can employ the topological information of the network to take better control action for regulating the voltage. Our implementation allows for both centralized and decentralized configurations, utilizing a single agent and multiple agents respectively. Although the centralized GCN-based DRL approach has its advantages of minimizing voltage fluctuation and power loss, it is not suitable for large scale power systems due to its challenges in terms of scalability, computation speed and potential single points of failure. Therefore, these problems can be resolved using the decentralized GCN-based DRL approach. Moreover, to ensure the safe operation of the model, our proposed approach incorporates an exponential barrier function while formulating the reward function for each agent. To validate performance of the proposed approaches, the proposed model is tested on modified IEEE test systems and the performances are measured in terms on voltage fluctuation reduction, minimization of power loss and computational speed. Finally, the results show that the proposed topology-aware approach outperforms the FCN-based DRL approach in terms of reducing voltage fluctuation and minimizing power loss of the network. Moreover, it is shown that the decentralized GCN-based DRL has faster computational speed than other approaches.

42 ENGINEERING↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗