Search NASA⌕ Search

SEARCH · Search NASA

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Marine Energy Technology Development Risk Management Framework

Over the past decades, the global marine energy industry has suffered a number of serious technological and commercial setbacks. To help reduce the risks of industry failures and advance the development of new technologies, the U.S. Department of Energy (DOE) and the National Renewable Energy Laboratory (NREL) developed a Marine Energy Risk Management Framework in 2015, with this revision published in 2024. This risk management framework shall be utilized on all DOE Water Power Technologies Office (WPTO) projects that require system testing in the open water. By addressing uncertainties, the Marine Energy Risk Management Framework increases the likelihood of successful development of marine energy converter technology. It covers projects of any technology readiness level technology performance level (TPL) and all risk types (e.g. technological risk, regulatory risk, commercial risk) over the development cycle. This risk framework is not a substitute for other risk management procedures that may be required for marine operations, such as installations at sea, hoisting and rigging, safe diver operations, and other safety requirements. This risk framework is intended to meet DOE's risk management expectations for marine energy technology research and development efforts from WPTO. It also provides an overview of other relevant risk management tools and documentation.

16 TIDAL AND WAVE POWER↗

Distributed Energy Resources Cybersecurity Framework & Risk Manager

Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic assessment for evaluating the cybersecurity posture of DER systems - filling an important gap that expands upon existing cybersecurity frameworks for more modern energy systems. The DER-CF is available as a written framework and an interactive Web tool. Distributed Energy Resource Risk Manager (DER-RM) process adheres closely to NIST's seven risk management steps: prepare, categorize, select, implement, assess, monitor, and authorize. This added feature is independent of the DER-CF's existing self-assessment and allows managers to focus on the RMF process.

cybersecurity↗

Guide to the Distributed Energy Resource Risk Management Framework

The emergence of distributed energy resources (DERs) has transformed the electric power sector and will likely have even more profound impacts on the future evolution of the United States energy sector as it modernizes and becomes more reliant upon complex informatics programming and systems to ensure that our power grid remains safe from malicious interference. To mitigate risks associated with the increased and diversified use of DERs, the Distributed Energy Resource Cybersecurity Framework (DER-CF) was developed in 2019. The National Renewable Energy Laboratory extended the scope of the DER-CF to include the RMF. To address the challenges faced by federal energy managers and energy system stakeholders in applying the RMF to DER systems, the Distributed Energy Resource Risk Manager (DER-RM) is a six-step process to proactively manage cybersecurity risk in a methodical manner. The DER-RM is independent of the DER-CF's existing assessment, allowing users to focus specifically on the RMF steps. The tools are targeted to different processes - DER-CF enables organizations to perform self-assessments to improve their cybersecurity posture, while DER-RM assists organizations in achieving compliance with specific requirements. This document provides an overview of the DER-RM. The RMF process outlined in this report serves as a guide to diagnose information and operational system threats, gather required materials to comply with industry standards, and document plans for achieving Authority to Operate. Using the DER-RM, federal agencies and other organizations can easily and intuitively follow the RMF process, manage the risks to their grid-edge infrastructure through the integration of their on-site DERs, and comply with appropriate requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

FEMP Cybersecurity Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. The tools are meant to help federal owners and operators to evaluate their overall cybersecurity posture. These tools are developed based on the NIST Cybersecurity framework, risk management framework, and DOE C2M2 architectures. Version 3 provides significant updates and features in ten areas

Ashley, Travis [Pacific Northwest National Laborat↗

An Integrated Paradigm for the Management of Delivery Risk in Electricity Markets: From Batteries to Insurance and Beyond

If power systems transition to integrate higher amounts of variable renewable energy sources, storage technologies, and distributed energy resources (DERs), new risk management frameworks are necessary to ensure cost-effective and reliable power system operations. Projects funded by the Advanced Research Projects Agency-Energy (ARPA-E) Performance-based Energy Resource Feedback, Optimization, and Risk Management (PERFORM) program aim to contribute new risk management frameworks by developing methods to quantify and manage risk at grid asset and system levels. The National Renewable Energy Laboratory (NREL) led a PERFORM project in collaboration with the Johns Hopkins University, the Electric Power Research Institute (EPRI), kWh Analytics, Packetized Energy, and Imperial Consultants (ICON). The project addressed two challenges related to risk management in electricity markets: managing net load imbalances and flexibility from DERs. This final technical report presents a list of project accomplishments, activities, and outputs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Artificial Intelligence in Nuclear Safeguards; Evaluating Safeguards and Security Risks and Benefits for Advanced and Small Modular Reactor Deployments

Rapidly growing interest in advanced and small modular reactor (A/SMR) technologies presents challenges as well as opportunities for implementing international safeguards and security. A/SMR deployments are expected to be more numerous, more geographically dispersed, and more varied in their designs, placing new demands on the data systems and analytical tools used to support oversight (Alberti et al., 2023; Canadian Nuclear Safety Commission et al., 2024). Because of this variability, the importance and reliance on data systems for A/SMR deployments is expected to be higher than for previous reactor generations. Artificial Intelligence and Machine Learning (AI/ML) offer potential capabilities to address the high variability inherent in A/SMR technology. The beneficiaries of AI-assisted tools include facility operators, government regulators, IAEA inspectors, and A/SMR vendors. This report analyzes how AI/ML-assisted technologies can strengthen the implementation of IAEA safeguards and security measures. It also identifies AI-assisted tools to strengthen operator, facility, and regulator knowledge management practices and examines the potential risks AI/ML-based tools may introduce to IAEA safeguards and security efforts. It concludes with a set of hypothetical, standards-style requirements for AI/ML systems used in safeguards contexts, grounded in an inspector-centric view of system verification. Despite the potential benefits of AI/ML systems, understanding potential intentional and unintentional failure modes is critical for ensuring adequate protection of nuclear materials and facilities. Unique features of A/SMRs including sealed cores, remote and novel paradigms of operation, off-site reactor fabrication, novel fuel forms, and varied refueling requirements, introduce challenges for traditional safeguards technological approaches (Pensado et al., 2024; Federation of American Scientists, 2025). AI/ML systems deployed to address these challenges may introduce new risks requiring systematic evaluation rooted in both AI-specific risk frameworks, such as the NIST AI Risk Management Framework (NIST AI RMF), and established cyber risk management standards such as NIST SP 800-30 (National Institute of Standards and Technology [NIST], 2023; NIST, 2012).

97 MATHEMATICS AND COMPUTING↗

Accelerated Materials Deployment in Advanced Nuclear Power Plants

The purpose of this report is to begin the development of a maximally efficient process for licensing and deploying new materials in Advanced Non-Light-Water Reactors (ANLWRs). Some new materials that are to be used in some new plants are seen as possibly introducing risks, because our understanding of those new materials’ behavior in the conditions generated by some novel plant designs is less complete than our understanding of the behavior of materials with long use histories in existing designs. In these cases, an approved code/standard or a code case to support the use of these materials in the novel design’s safety case may not exist for the regulator to utilize as part of the licensing determination. This circumstance creates the potential for an extremely long licensing process for new designs using new materials. The present strategy is to show how to manage these risks proactively, in such a way as to permit licensing decisions to be made in a timely manner, based on this risk management process. The present report outlines the gaps in the current codes to support deployment and use of novel materials and begins the development of the necessary risk management framework that is focused on the subject materials issues; it is based on risk-informed in-service surveillance practices, carried out in such a way as to compensate for current limitations in our state of knowledge. This development will enable licensing and deployment of the subject materials, conditional on the proactive surveillance process to be established. While this report is occasioned by limitations in our knowledge of certain materials issues that may arise in advanced designs, in-service surveillance is always done in order to compensate for a lack of knowledge: if we knew that components were not already failed and not trending toward failure, we would not perform surveillance, even in current-generation plants (except that prescriptive requirements would force us to do so). What is different about the surveillance program discussed here is that the issues are newer and the relevant experience base is less complete, so the surveillance presently contemplated may need to measure new things and/or measure them more often than has been traditional for surveillance coupons. The present report is devoted to the risk management framework and applies American Society of Mechanical Engineers Boiler and Pressure Vessel Code Section XI, Division [1] to establish the structure of a protocol for carrying out the necessary surveillance. These documents are generic: they do not tell us how often to surveille, or what to surveille, or what to measure, but rather how to determine those things, given certain technical inputs. The Regulatory Development R&D Program [2] is currently developing the companion supporting technical basis for the materials surveillance technology that, when completed and validated, can be used by owner/operator and NRC to implement a materials degradation management program for ANLWRs. This report also outlines salient points of discussion, positive potential outcomes, and potential concerns from industry and the USNRC. These aspects of the report intend to inform future work to develop a proposed technical process for adoption by the industry and endorsement by the USNRC to allow developers to propose a risk informed and conservative approach for the use of materials where operating experience/data and codes and standards may not exist for use of a novel material in an operating reactor environment. Additionally, such a technology could be leveraged to potentially reduce part of the upfront materials data requirements from ongoing long-term materials testing so that early action on license application could be undertaken by NRC, in parallel with the continuation of long-term data collection. This could accelerate the schedule for a first-of-a-kind ANLWR deployment or a nth-of-a-kind new materials insertion for established ANLWR designs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

An Integrated Paradigm for the Management of Delivery Risk in Electricity Markets: From Batteries to Insurance and Beyond [Slides]

In wholesale electricity markets today, flexibility from a limited number of distributed energy resources (DERs) is offered daily, and the value of flexibility is not yet recognized for economic hedging of delivery risk. Under a three-year project funded by the ARPA-E PERFORM program, a collaborative team is working towards developing an integrated risk management framework that will leverage flexibility from distributed and bulk resources to cost-effectively and reliably manage delivery risk of intermittent resources. Two concepts are at the core of the proposed integrated risk management framework: (A) flexibility options, which are a novel type of options and enable wholesale electricity market participants to hedge uncertainty by buying flexibility. (B) DER flexibility scores, which provide a way for utilities or aggregators to classify assets in groups with different likelihood of delivering contracted flexibility. This report presentation will focus on the proposed ISO-product "flexibility options," which is complementary to ramp and other products being introduced by ISOs/RTOs to manage net load uncertainties. Participating resources with imbalance risk can buy flexibility options to hedge their production, whereas grid-connected resources that can provide physical flexibility can offer flexibility options. We will present basics of the formulation for a day-ahead ISO market that matches buyers and sellers of this hedge in coordination with existing capabilities to schedule energy and ancillary services, and outline how their settlements mitigate the impact of imbalance risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Managing Marine Energy Risks for Project Success

This presentation reviews recommended practices for marine energy risk management based on NLR's recent risk management framework publication (https://www.nrel.gov/docs/fy24osti/90212.pdf). This presentation will include a demonstration of risk management processes and techniques that everyone in the marine energy industry can use to successfully meet their project objectives. This presentation will include a description of methods to identify and manage risks that are specific to marine energy, while demonstrating this through tools such as risk registers, failure modes effects and criticality analysis (FMECA), and more tools that are currently being developed. The goal of this presentation is for the participants to have knowledge and access to tools to help them manage the risks specific to their marine energy projects.

13 HYDRO ENERGY↗

Integrated Issues and Risk Management: A Theoretical Framework Overview

The contractor requirements document for DOE O 226.1B, Implementation of Department of Energy Oversight Policy, requires DOE/NNSA contractors to establish an assurance system that includes, among other things, “Rigorous, risk-informed, and credible self-assessment and feedback and improvement activities. Assessment programs must be risk-informed, formally described and documented, and appropriately cover potentially high consequence activities” and “Contains an issues management process that is capable of categorizing the significance of findings based on risk and priority and other appropriate factors….” However, the term “risk-informed” is not defined in this or any other DOE order, and no formal guidance on how to integrate the two concepts currently exists. The Risk Management Guide for Defense Programs released by NA-18, Office of Systems Engineering and Integration (SE&I), states it is “a framework and general guidance to program office personnel on the effective management of program risks and issues”, however it then defines issues as “events with 100% likelihood of affecting program objectives” and states “unless specified otherwise, the term “risk” will also serve to represent issues for the remainder of this plan,” severally limiting its ability to provide adequate guidance on this topic. Outside of DOE scope, the U.S. Nuclear Regulatory Commission (U.S. NRC) imposes similar requirements. ASME NQA-1-2015 Requirement 16 states “Conditions adverse to quality shall be identified promptly and corrected as soon as practicable. In the case of a significant condition adverse to quality, the cause of the condition shall be determined, and corrective action taken to preclude recurrence. The identification, cause, and corrective action for significant conditions adverse to quality shall be documented and reported to appropriate levels of management. Completion of corrective actions shall be verified”. The purpose of this document is to provide a best-in-class framework for an integrated risk and issues management process. This process would provide a robust feedback loop between risk management and issues management to: Enhance risk identification and characterization, use risk handling principles to improve corrective action planning, and ensure regulatory compliance.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Cybersecurity Assessment Tools for Distributed Energy Resources

This growing number of smart devices that support DERs can increase the number of access points outside a utility’s administrative domain, which can increase the potential for cyberattack. With the integration of DERs at federal sites, the cybersecurity vulnerabilities of DER systems must be understood and addressed. This presentation covers two NREL tools available. The Distributed Energy Resource Cybersecurity Framework (DER-CF) is a web-based holistic tool for evaluating cybersecurity posture including governance, physical security and technical management. The Distributed Energy Resource Risk Manager (DER-RM) extends the DER-CF by applying it to the NIST risk management framework process. It will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Cybersecurity for Distributed Wind: MIRACL Advisory Board Meeting 2022

This presentation for the MIRACL Industry Advisory Board summarizes the cybersecurity research for distributed wind that was performed during the project. Highlights include an overview of the distributed wind reference architecture, descriptions of the unique needs and challenges for securing distributed wind, the cyber risk management framework that was developed for this project, and key takeaways for various stakeholders.

17 WIND ENERGY↗

Risk Management for Ocean-Based Technologies [Slides]

This presentation discusses risk management for ocean-based technologies by stepping through elements of the National Laboratory of the Rockies' 2024 Marine Energy Technology Development Risk Management Framework.

16 TIDAL AND WAVE POWER↗

Risk Management for Distributed Energy Resources

The National Institute of Standards and Technology will be hosting on Tuesday, February 2 and Wednesday, February 3, 2021, the second workshop in a new series focusing on the Open Security Controls Assessment Language. NREL extended the scope of the DERCF to include the NIST Risk Management Framework (RMF), addressing the challenges faced by federal energy managers when complying with the NIST RMF for DER systems. The NIST RMF is a cyclical process designed to incorporate principles of security and risk management into an organization’s system policies and procedures. The DER-RM will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

cybersecurity↗

Comparison of Deterministic and Statistical Models for Water Quality Compliance Forecasting in the San Joaquin River Basin, California

Model selection for water quality forecasting depends on many factors including analyst expertise and cost, stakeholder involvement and expected performance. Water quality forecasting in arid river basins is especially challenging given the importance of protecting beneficial uses in these environments and the livelihood of agricultural communities. In the agriculture-dominated San Joaquin River Basin of California, real-time salinity management (RTSM) is a state-sanctioned program that helps to maximize allowable salt export while protecting existing basin beneficial uses of water supply. The RTSM strategy supplants the federal total maximum daily load (TMDL) approach that could impose fines associated with exceedances of monthly and annual salt load allocations of up to $1 million per year based on average year hydrology and salt load export limits. The essential components of the current program include the establishment of telemetered sensor networks, a web-based information system for sharing data, a basin-scale salt load assimilative capacity forecasting model and institutional entities tasked with performing weekly forecasts of river salt assimilative capacity and scheduling west-side drainage export of salt loads. Web-based information portals have been developed to share model input data and salt assimilative capacity forecasts together with increasing stakeholder awareness and involvement in water quality resource management activities in the river basin. Two modeling approaches have been developed simultaneously. The first relies on a statistical analysis of the relationship between flow and salt concentration at three compliance monitoring sites and the use of these regression relationships for forecasting. The second salt load forecasting approach is a customized application of the Watershed Analysis Risk Management Framework (WARMF), a watershed water quality simulation model that has been configured to estimate daily river salt assimilative capacity and to provide decision support for real-time salinity management at the watershed level. Analysis of the results from both model-based forecasting approaches over a period of five years shows that the regression-based forecasting model, run daily Monday to Friday each week, provided marginally better performance. However, the regression-based forecasting model assumes the same general relationship between flow and salinity which breaks down during extreme weather events such as droughts when water allocation cutbacks among stakeholders are not evenly distributed across the basin. A recent test case shows the utility of both models in dealing with an exceedance event at one compliance monitoring site recently introduced in 2020.

54 ENVIRONMENTAL SCIENCES↗

Developing a Decision Support System for Regional Agricultural Nonpoint Salinity Pollution Management: Application to the San Joaquin River, California

Environmental problems and production losses associated with irrigated agriculture, such as salinity, degradation of receiving waters, such as rivers, and deep percolation of saline water to aquifers, highlight water-quality concerns that require a paradigm shift in resource-management policy. New tools are needed to assist environmental managers in developing sustainable solutions to these problems, given the nonpoint source nature of salt loads to surface water and groundwater from irrigated agriculture. Equity issues arise in distributing responsibility and costs to the generators of this source of pollution. This paper describes an alternative approach to salt regulation and control using the concept of “Real-Time Water Quality management”. The approach relies on a continually updateable WARMF (Watershed Analysis Risk Management Framework) forecasting model to provide daily estimates of salt load assimilative capacity in the San Joaquin River and assessments of compliance with salinity concentration objectives at key monitoring sites on the river. The results of the study showed that the policy combination of well-crafted river salinity objectives by the regulator and the application of an easy-to use and maintain decision support tool by stakeholders have succeeded in minimizing water quality (salinity) exceedances over a 20-year study period.

real-time management economics↗

Automation for Distributed Energy Resources Risk Manager Using OSCAL

The risk management framework (RMF) provides a well-organized and thorough approach to diagnose information technology (IT) system threats, to gather required materials to comply with industry standards, and to document a plan for achieving authority to operate (ATO). ATO is given by the operating authority with the awareness of vulnerabilities that arise when operating the IT system. The primary goal of the National Renewable Energy Laboratory’s (NREL’s) distributed energy resource (DER) RM application is to provide a user-friendly interface and in-depth guidance for generating the authorization package for the authorizing official to review. In other words, the application satisfies steps 1 through 7 of the RMF process with a focus on DERs.

cybersecurity↗