Search NASA⌕ Search

SEARCH · Search NASA

Results for “Enterprise Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Exploration Systems Development (ESD) Approach to Enterprise Risk Management

The National Aeronautics and Space Administration (NASA) Exploration Systems Development (ESD) Division has implemented an innovative approach to Enterprise Risk Management under a unique governance structure and streamlined integration model. ESD's mission is to design and build the capability to extend human existence to deep space. The Enterprise consists of three Programs: Space Launch System (SLS), Orion, and Ground Systems Development and Operations (GSDO). The SLS is a rocket and launch system that will be capable of powering humans, habitats, and support systems to deep space. Orion will be the first spacecraft in history capable of taking humans to multiple destinations within deep space. GSDO is modernizing Kennedy's spaceport to launch spacecraft built and designed by both NASA and private industry. ESD's approach to Enterprise Risk Management is commensurate with affordability and a streamlined management philosophy. ESD Enterprise Risk Management leverages off of the primary mechanisms for integration within the Enterprise. The Enterprise integration approach emphasizes delegation of authority to manage and execute the majority of cross-program activities and products to the individual Programs, while maintaining the overall responsibility for all cross-program activities at the Division. The intent of the ESD Enterprise Risk Management approach is to improve risk communication, to avoid replication and/or contradictory strategies, and to minimize overhead process burden. This is accomplished by the facilitation and integration of risk information within ESD. The ESD Division risks, Orion risks, SLS risks, and GSDO risks are owned and managed by the applicable Program. When the Programs have shared risks with multiple consequences, they are jointly owned and managed. When a risk is associated with the integrated system that involves more than one Program in condition, consequence, or mitigation plan, it is considered an Exploration Systems Integration (ESI) Risk. An ESI risk may require visibility and risk handling by multiple organizations. The Integrated Risk Working Group (IRWG) is a small team of Risk experts that are responsible for collaborating and communicating best practices. In addition, the forum facilitates proper integration of risks across the Enterprise. The IRWG uses a Continuous Risk Management approach for facilitating the identification, analysis, planning, tracking, and controlling of ESI Risks. The ESD Division, Programs, and Integrated Task Teams identify ESI Risks. The IRWG maintains a set of metrics for understanding Enterprise Risk process and the overall Risk Posture. The team is also actively involved in the modeling of risk for Enterprise Performance Management. With the Enterprise being constrained in Schedule and Budget, and with significant technical complexity, the appropriate use of Risk Management techniques is crucial to the success of the Enterprise. The IRWG achieves this through the modified approach, providing a forum for collaboration on risks that cross boundaries between the separate entities.

Bauder, Stephen P.↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

System-Level Integration of Modular Language Models for Real-Time Risk Assessment in Third-Party Risk Management Systems

Large enterprises typically rely on dedicated teams to govern and implement security measures throughout their supply chains, ensuring compliance with enterprise security procedures. There is a significant reliance on Third-Party Risk Management (TPRM) platforms, which often require complete, highly structured information from potential vendors. The review and compliance assurance processes are time- and labor intensive, often requiring several rounds of review between the supply chain security risk management teams, business users, and potential vendors, leading to delays in the supply chain processing and consumer experience. Significant challenges in the risk management paradigm include handling unstructured data in various formats and providing real-time feedback to users to reduce the required review time. This paper presents a novel solution to these challenges. A modular multi-step system architecture is proposed using advances in language processing, specifically for unstructured responses and provides real-time feedback (i.e., 3 seconds) so that users can improve their responses before the TPSRM team review. This novel system architecture will increase information accuracy and significantly reduce time and labor during the review process.

99 - GENERAL AND MISCELLANEOUS↗

Calysto: Risk Management for Commercial Manned Spaceflight

The Calysto: Risk Management for Commercial Manned Spaceflight study analyzes risk management in large enterprises and how to effectively communicate risks across organizations. The Calysto Risk Management tool developed by NASA's Kennedy Space Center's SharePoint team is used and referenced throughout the study. Calysto is a web-base tool built on Microsoft's SharePoint platform. The risk management process at NASA is examined and incorporated in the study. Using risk management standards from industry and specific organizations at the Kennedy Space Center, three methods of communicating and elevating risk are examined. Each method describes details of the effectiveness and plausibility of using the method in the Calysto Risk Management Tool. At the end of the study suggestions are made for future renditions of Calysto.

Dillaman, Gary↗

Supply Chain Research and Analysis for Space Systems

The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supply Chain Research and Analysis capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 105 reports since its start-up in early 2015.This presentation addresses the approach, methodology and performance of the Supply Chain Research and Analysiscapability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability.

supply chain risk management↗

Supplier Research & Analysis Approach

"The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supplier Research and Analysis (SRA) capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 95 reports since its start-up in early 2015. This presentation addresses the approach, methodology and performance of the Supplier Research and Analysis (SRA) capability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability."

supplier research and analysis↗

Improving Our Odds: Success through Continuous Risk Management

Launching a rocket, running a business, driving to work and even day-to-day living all involve some degree of risk. Risk is ever present yet not always recognized, adequately assessed and appropriately mitigated. Identification, assessment and mitigation of risk are elements of the risk management component of the "continuous improvement" way of life that has become a hallmark of successful and progressive enterprises. While the application of risk management techniques to provide continuous improvement may be detailed and extensive, the philosophy, ideals and tools can be beneficially applied to all situations. Experiences with the use of risk identification, assessment and mitigation techniques for complex systems and processes are described. System safety efforts and tools used to examine potential risks of the Ares I First Stage of NASA s new Constellation Crew Launch Vehicle (CLV) presently being designed are noted as examples. Recommendations from lessons learned are provided for the application of risk management during the development of new systems as well as for the improvement of existing systems. Lessons learned and suggestions given are also examined for applicability to simple systems, uncomplicated processes and routine personal daily tasks. This paper informs the reader of varied uses of risk management efforts and techniques to identify, assess and mitigate risk for improvement of products, success of business, protection of people and enhancement of personal life.

Greenhalgh, Phillip O.↗

Human Factors Throughout the Life Cycle: Lessons Learned from the Shuttle Program

With the ending of the Space Shuttle Program, it is critical that we not forget the Human Factors lessons we have learned over the years. At every phase of the life cycle, from manufacturing, processing and integrating vehicle and payload, to launch, flight operations, mission control and landing, hundreds of teams have worked together to achieve mission success in one of the most complex, high-risk socio-technical enterprises ever designed. Just as there was great diversity in the types of operations performed at every stage, there was a myriad of human factors that could further complicate these human systems. A single mishap or close call could point to issues at the individual level (perceptual or workload limitations, training, fatigue, human error susceptibilities), the task level (design of tools, procedures and aspects of the workplace), as well as the organizational level (appropriate resources, safety policies, information access and communication channels). While we have often had to learn through human mistakes and technological failures, we have also begun to understand how to design human systems in which individuals can excel, where tasks and procedures are not only safe but efficient, and how organizations can foster a proactive approach to managing risk and supporting human enterprises. Panelists will talk about their experiences as they relate human factors to a particular phase of the shuttle life cycle. They will conclude with a framework for tying together human factors lessons-learned into system-level risk management strategies.

human factors↗

Space Toxicology Challenges and Ethical Considerations

Before delineating specific ways that nanotechnology enterprises might contribute to better management of toxicological risks during spaceflight, I will show how ethical considerations and several theories of justice can be applied to nanotechnology strategic plans. The principles that guide an ethical technical enterprise include autonomy, beneficence, non-maleficence, veracity and justice. Veracity (truth) is the underpinning principle; however, beyond this, proponents of nanotechnology must think carefully about balancing conflicting principles. For example, autonomy must yield to beneficence when fearful individuals simply lack knowledge to appreciate nanotechnology's beneficial advances. Justice is a complex topic upon which I will place six models: utilitarian, distributive, free-exchange/choice, individual dignity (social participation), equity vs. greed, and liberation of the poor. After briefly summarizing each model, I will present what I call an iterative-hybrid model of justice to show specifically how our thinking can be applied to nanotechnology enterprises. Within that broad landscape, I will discuss a single feature: how our early effort to understand health risks of carbon nanotubes fits into the iterative model. Finally, I will suggest ways that nanotechnology might advance our management of toxicological risks during spaceflight, but always with an eye toward how such advances might result in a more just world.

James, John T.↗

NASA Risk Management Handbook: Version 2.0, Part 1

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0. NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Uncertainty↗

NASA Risk Management Handbook: Version 2.0, Part 2

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0 (January 2020). NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Risk Leadership↗

Lay and Expert Perceptions of Planetary Protection

As space scientists and engineers plan new missions to Mars and other planets in our solar system, they will face critical questions about the potential for biological contamination of planetary surfaces. In a society that places ever-increasing importance on the role of public involvement in science and technology policy, questions about risks of biological contamination will be examined and debated in the media, and will lead to the formation of public perceptions of planetary-contamination risks. These perceptions will, over time, form an important input to the development of space policy. Previous research in public and expert perceptions of technological risks and hazards has shown that many of the problems faced by risk-management organizations are the result of differing perceptions of risk (and risk management) between the general public and scientific and technical experts. These differences manifest themselves both as disagreements about the definition (and level) of risk associated with a scientific, technological or industrial enterprise, and as distrust about the ability of risk-management organizations (both public and private) to adequately protect people's health and safety. This report presents the results of a set of survey studies designed to reveal perceptions of planetary exploration and protection from a wide range of respondents, including both members of the general public and experts in the life sciences. The potential value of this research lies in what it reveals about perceptions of risk and benefit that could improve risk-management policies and practices. For example, efforts to communicate with the public about Mars sample return missions could benefit from an understanding of the specific concerns that nonscientists have about such a mission by suggesting areas of potential improvement in public education and information. Assessment of both public and expert perceptions of risk can also be used to provide an advanced signal of aspects of planetary exploration and protection that may be particularly sensitive or controversial and that could prove problematic from a risk-management standpoint, perhaps warranting a more stringent risk-management approach than would otherwise be the case based on technical considerations alone. The design of the study compares perceptions and attitudes about space exploration relevant to a Mars sample return mission between three respondent groups: (1) members of The Planetary Society, a group representing individuals with a strong interest in space-related issues, (2) a group of university-aged students, representing a population relatively sensitive to environmental hazards, and (3) a group of life scientists outside of the space research community. Members of The Planetary Society received the survey as part of a special issue of The Planetary Report on planetary protection, which contained a number of background articles on planetary protection and related topics. A synopsis of the issue was prepared as an introduction to the survey for the other two groups.

Race, Margaret S.↗

Managing information technology security risk

Information Technology (IT) Security Risk Management is a critical task for the organization to protect against the loss of confidentiality, integrity and availability of IT resources. As systems bgecome more complex and diverse and and attacks from intrusions and malicious content increase, it is becoming increasingly difficult to manage IT security risk. This paper describes a two-pronged approach in addressing IT security risk and risk management in the organization: 1) an institutional enterprise appraoch, and 2) a project life cycle approach.

security toolset↗

Managing Space Radiation Risk in the New Era of Space Exploration

Space exploration is a risky enterprise. Rockets launch astronauts at enormous speeds into a harsh, unforgiving environment. Spacecraft must withstand the bitter cold of space and the blistering heat of reentry. Their skin must be strong enough to keep the inside comfortably pressurized and tough enough to resist damage from micrometeoroids. Spacecraft meant for lunar or planetary landings must survive the jar of landing, tolerate dust, and be able to take off again. For astronauts, however, there is one danger in space that does not end when they step out of their spacecraft. The radiation that permeates space -- unattenuated by Earth s atmosphere and magnetosphere -- may damage or kill cells within astronauts bodies, resulting in cancer or other health consequences years after a mission ends. The National Aeronautics and Space Administration (NASA) has recently embarked on Project Constellation to implement the Vision for Space Exploration -- a program announced by President George W. Bush in 2004 with the goal of returning humans to the Moon and eventually transporting them to Mars. To adequately prepare for the safety of these future space explorers, NASA s Exploration Systems Mission Directorate requested that the Aeronautics and Space Engineering Board of the National Research Council establish a committee to evaluate the radiation shielding requirements for lunar missions and to recommend a strategic plan for developing the radiation mitigation capabilities needed to enable the planned lunar mission architecture

Source record↗

From Stewardship to Transformation: Toward a Nuclear Enterprise for the 21st Century

The erosion of the global security environment over the last two decades has been rapid and dramatic. It appears also to be accelerating. There are deep and widening concerns in the United States and among its allies and partners that deterrence too has eroded at both the conventional and nuclear levels. The Strategic Posture Commission captured the essence of the problem in its October 2023 report—the United States seeks to meet the challenges of complex multipolar nuclear rivalry in the 21 st century with a slimmed down version of a nuclear deterrent designed in the middle of the 20 th century. With great urgency, the Commission recommended that something more and/or different is needed than simply the replacement of legacy systems with modern variants. But the U.S. nuclear security enterprise was reshaped after the Cold War to support the stockpile stewardship mission—not renewed designed, engineering, and production at scale. It has long fallen short of the agility, flexibility, and adaptiveness periodically asked of it by national leaders. In recent years, however, the message of urgency has been clearly received in the enterprise. Its culture has begun to shift. It has also been received by those in Washington D.C. responsible for funding and guiding the enterprise. The result is an enterprise in transition. Stockpile stewardship has given way to stockpile transformation. Risk aversion is giving way to risk management. Innovation and adaptation have been embraced. Experience to date has yielded some important lessons about what works and what doesn’t in terms of accelerating and delivering the needed innovation and adaptation. It has revealed the enduring character of some challenges. But it has also revealed that a much more agile and effective enterprise is within the national reach—something that will pay important dividends for deterrence, assurance, strategic stability, and peace.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Business Intelligence Modeling in Launch Operations

This technology project is to advance an integrated Planning and Management Simulation Model for evaluation of risks, costs, and reliability of launch systems from Earth to Orbit for Space Exploration. The approach builds on research done in the NASA ARC/KSC developed Virtual Test Bed (VTB) to integrate architectural, operations process, and mission simulations for the purpose of evaluating enterprise level strategies to reduce cost, improve systems operability, and reduce mission risks. The objectives are to understand the interdependency of architecture and process on recurring launch cost of operations, provide management a tool for assessing systems safety and dependability versus cost, and leverage lessons learned and empirical models from Shuttle and International Space Station to validate models applied to Exploration. The systems-of-systems concept is built to balance the conflicting objectives of safety, reliability, and process strategy in order to achieve long term sustainability. A planning and analysis test bed is needed for evaluation of enterprise level options and strategies for transit and launch systems as well as surface and orbital systems. This environment can also support agency simulation .based acquisition process objectives. The technology development approach is based on the collaborative effort set forth in the VTB's integrating operations. process models, systems and environment models, and cost models as a comprehensive disciplined enterprise analysis environment. Significant emphasis is being placed on adapting root cause from existing Shuttle operations to exploration. Technical challenges include cost model validation, integration of parametric models with discrete event process and systems simulations. and large-scale simulation integration. The enterprise architecture is required for coherent integration of systems models. It will also require a plan for evolution over the life of the program. The proposed technology will produce long-term benefits in support of the NASA objectives for simulation based acquisition, will improve the ability to assess architectural options verses safety/risk for future exploration systems, and will facilitate incorporation of operability as a systems design consideration, reducing overall life cycle cost for future systems. The future of business intelligence of space exploration will focus on the intelligent system-of-systems real-time enterprise. In present business intelligence, a number of technologies that are most relevant to space exploration are experiencing the greatest change. Emerging patterns of set of processes rather than organizational units leading to end-to-end automation is becoming a major objective of enterprise information technology. The cost element is a leading factor of future exploration systems.

Bardina, Jorge E.↗

Management of Guidance, Navigation, and Control Technologies for Spacecraft Formations Under the NASA Cross Enterprise Technology Development Program (CETDP)

Breakthrough technology development is critical to securing the future of our space industry. The National Aeronautics and Space Administration (NASA) Cross-Enterprise Technology Development Program (CETDP) is developing critical space technologies that enable innovative and less costly missions, and spawn new mission opportunities through revolutionary, long-term, high-risk, high-payoff technology advances. The CETDP is a NASA-wide activity managed by the Advanced Technology and Mission Studies Division (AT&MS) at Headquarters Office of Space Science. Program management for CETDP is distributed across the multiple NASA Centers and draws on expertise throughout the Agency. The technology research activities are organized along Project-level divisions called thrust areas that are directly linked to the Agency's goals and objectives of the Enterprises: Earth Science, Space Science, Human Exploration and Development of Space; and the Office of the Chief Technologist's (OCT) strategic technology areas. Cross-Enterprise technology is defined as long-range strategic technologies that have broad potential to span the needs of more than one Enterprise. Technology needs are identified and prioritized by each of the primary customers. The thrust area manager (TAM) for each division is responsible for the ultimate success of technologies within their area, and can draw from industry, academia, other government agencies, other CETDP thrust areas, and other NASA Centers to accomplish the goals of the thrust area. An overview of the CETDP and description of the future directions of the thrust area called Distributed Spacecraft are presented in this paper. Revolutionary technologies developed within this thrust area will enable the implementation of a spatially distributed network of individual vehicles, or assets, collaborating as a single collective unit, and exhibiting a common system-wide capability to accomplish a shared objective. With such a capability, new Earth and space science measurement concepts become a reality.

Hartman, Kathy↗