Search NASASearch

SEARCH · Search NASA

Results for “risk analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Risk Analysis for Remote Operation of Microreactors

Microreactors are a subset of advanced nuclear reactors that can be factory fabricated, transportable, and self-regulating. They have the potential to be used in microgrids, rural and remote areas, or emergency response applications, replacing fossil fuel sources like diesel generators and enabling sustainable energy generation. In order to make microreactor operation cost-effective, it is likely that remote communications will be needed to reduce the number of personnel required to be on site. While remote operation of energy generation and other industrial control systems is common in other industries, it is not yet adopted in the nuclear community and has many perceived and actual risks. In this paper, the severity of the risks introduced by remote operations for microreactors are explored. The primary changes in the operations involve the addition of a remote communications network and a certification system for data and controls. These changes lend themselves to considerations of cyber risks, whether unintentional or adversarial, but the assessment considers not just cyber risks introduced, but also how physical and human factors-based risks will impact the remote operations system and change the overall risk profile. This initial assessment indicates that there are standard cyber and mitigation measures that can be put in place so the risk of doing remote operations does not dramatically increase compared to local operations. This evaluation is a critical step in the process of evaluating if remote operations of microreactors is a suitable solution to meet future sustainable grid needs

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND

Peak Pc Prediction in Conjunction Analysis: Conjunction Assessment Risk Analysis

Satellite conjunction risk typically evaluated through the probability of collision (Pc). Considers both conjunction geometry and uncertainties in both state estimates. Conjunction events initially discovered through Joint Space Operations Center (JSpOC) screenings, usually seven days before Time of Closest Approach (TCA). However, JSpOC continues to track objects and issue conjunction updates. Changes in state estimate and reduced propagation time cause Pc to change as event develops. These changes a combination of potentially predictable development and unpredictable changes in state estimate covariance. Operationally useful datum: the peak Pc. If it can reasonably be inferred that the peak Pc value has passed, then risk assessment can be conducted against this peak value. If this value is below remediation level, then event intensity can be relaxed. Can the peak Pc location be reasonably predicted?

Operations

Dynamic Positioning System (DPS) Risk Analysis Using Probabilistic Risk Assessment (PRA)

The National Aeronautics and Space Administration (NASA) Safety & Mission Assurance (S&MA) directorate at the Johnson Space Center (JSC) has applied its knowledge and experience with Probabilistic Risk Assessment (PRA) to projects in industries ranging from spacecraft to nuclear power plants. PRA is a comprehensive and structured process for analyzing risk in complex engineered systems and/or processes. The PRA process enables the user to identify potential risk contributors such as, hardware and software failure, human error, and external events. Recent developments in the oil and gas industry have presented opportunities for NASA to lend their PRA expertise to both ongoing and developmental projects within the industry. This paper provides an overview of the PRA process and demonstrates how this process was applied in estimating the probability that a Mobile Offshore Drilling Unit (MODU) operating in the Gulf of Mexico and equipped with a generically configured Dynamic Positioning System (DPS) loses location and needs to initiate an emergency disconnect. The PRA described in this paper is intended to be generic such that the vessel meets the general requirements of an International Maritime Organization (IMO) Maritime Safety Committee (MSC)/Circ. 645 Class 3 dynamically positioned vessel. The results of this analysis are not intended to be applied to any specific drilling vessel, although provisions were made to allow the analysis to be configured to a specific vessel if required.

Thigpen, Eric B.

Dynamic Positioning System (DPS) Risk Analysis Using Probabilistic Risk Assessment (PRA)

The National Aeronautics and Space Administration (NASA) Safety & Mission Assurance (S&MA) directorate at the Johnson Space Center (JSC) has applied its knowledge and experience with Probabilistic Risk Assessment (PRA) to projects in industries ranging from spacecraft to nuclear power plants. PRA is a comprehensive and structured process for analyzing risk in complex engineered systems and/or processes. The PRA process enables the user to identify potential risk contributors such as, hardware and software failure, human error, and external events. Recent developments in the oil and gas industry have presented opportunities for NASA to lend their PRA expertise to both ongoing and developmental projects within the industry. This paper provides an overview of the PRA process and demonstrates how this process was applied in estimating the probability that a Mobile Offshore Drilling Unit (MODU) operating in the Gulf of Mexico and equipped with a generically configured Dynamic Positioning System (DPS) loses location and needs to initiate an emergency disconnect. The PRA described in this paper is intended to be generic such that the vessel meets the general requirements of an International Maritime Organization (IMO) Maritime Safety Committee (MSC)/Circ. 645 Class 3 dynamically positioned vessel. The results of this analysis are not intended to be applied to any specific drilling vessel, although provisions were made to allow the analysis to be configured to a specific vessel if required.

Thigpen, Eric B.

The Challenger tragedy was caused by an Apollo mistake, terminating risk analysis

NASA’s view of risk changed between early Apollo and the Space Shuttle. Risk was a known serious problem at the beginning of Apollo and the risk estimates were disturbingly high. To avoid public concern, risk analysis was discontinued. Risk analysis was avoided in Shuttle, leading to an unnecessarily risky design. The immediate cause of the Challenger tragedy was the mistaken decision to launch in cold weather. The fundamental cause was the high risk of the Shuttle design. Before Challenger, management thought and testified that the probability of an accident was 1 in 100,000. After Challenger, Probabilistic Risk Analysis (PRA) found a roughly 1 in 100 chance of a Shuttle failure. The recent Orion design uses the safer Apollo approach, with a hardened capsule, launch abort escape, and the crew placed above the rocket tanks and engines. During Apollo it was estimated that, “assuming all elements from propulsion to rendezvous and life support were done as well or better than ever before, that 30 astronauts would be lost before 3 were returned safely to the Earth.” The chance of astronaut survival was only 10%. After the Apollo 1 tragedy, the awareness of risk led to an intense focus on achieving safety. “The only possible explanation for the astonishing success – no losses in space and on time – was that every participant at every level in every area far exceeded the norm of human capabilities.” During Apollo, a NASA PRA found that the chance of success was “less than 5 percent.” The NASA Administrator felt that “the numbers could do irreparable harm,” and discontinued numerical risk assessment. This led to decreasing understanding of risk. The head of Apollo reliability and safety decided, “Statistics don’t count for anything,” and that risk is reduced by “attention taken in design.” The great and initially unexpected success of Apollo appeared to validate the neglect of PRA. Continuing to neglect the mathematical estimation of risk led Shuttle into a high risk design that produced tragic results. The initial design of the Shuttle emphasized increasing capability and reducing cost without analysis or even mention of risk. A retired NASA official stated, “some NASA people began to confuse desire with reality. … One result was to assess risk in terms of what was thought acceptable without regard for verifying the assessment. … Note that under such circumstances real risk management is shut out.” Not computing risk led to removing launch abort, removing crew escape, selecting less reliable Solid Rocket Boosters, placing the crew compartment next to the rocket boosters, and accepting more stressed shielding tile designs. Accepting these specific risks directly caused the shuttle disasters. The Challenger tragedy is frequently taught as a case of management failure. The focus is on the Challenger launch decision hours before, which is a dramatic example of bad management. However, the true cause of the Challenger disaster occurred decades earlier in the Apollo era. When the easily predictable failures occurred, failure investigations focused on how they might have been avoided. The Shuttle was cancelled after the space station was completed because of its high risk. The ultimate cause of the Shuttle tragedies was the choice by the Apollo-era NASA administrator to avoid a negative public reaction to realistic risk analysis.

Harry W. Jones

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING

The Challenger Tradgedy was Caused by an Apollo Mistake, Terminating Risk Analysis

NASA’s attitude toward risk changed drastically between the Apollo and Space Shuttle design. [1]Apollo engineers were seriously alarmed about riskbecause of the fatal Apollo 1 fire and the fact that the estimated probability of another fatal accident was extremely high. The predictions were so appalling thatmanagement terminated risk analysis to avoid public apprehension. Because risk analysis was not done, the Space Shuttle design accepted excessively high andunknown risk. The immediate cause of the Challengertragedy was the mistaken decision to launch in coldweather that impaired the O-ring seals, but the fundamental cause was the high risk of the shuttle design. Before Challenger, management asserted that the probability of a fatal accident was 1 in 100,000.Probabilistic Risk Analysis (PRA) found a roughly 1 in 100 chance of a shuttle failure.

Harry W Jones

Consideration of Collision "Consequence" in Satellite Conjunction Assessment and Risk Analysis

Classic risk management theory requires the assessment of both likelihood and consequence of deleterious events. Satellite conjunction risk assessment has produced a highly-developed theory for assessing collision likelihood but holds a completely static solution for collision consequence, treating all potential collisions as essentially equally worrisome. This may be true for the survival of the protected asset, but the amount of debris produced by the potential collision, and therefore the degree to which the orbital corridor may be compromised, can vary greatly among satellite conjunctions. This study leverages present work on satellite collision modeling to develop a method by which it can be estimated, to a particular confidence level, whether a particular collision is likely to produce a relatively large or relatively small amount of resultant debris and how this datum might alter conjunction remediation decisions. The more general question of orbital corridor protection is also addressed, and a preliminary framework presented by which both collision likelihood and consequence can be jointly considered in the risk assessment process.

Hejduk, M.

Program risk analysis handbook

NASA regulations specify that formal risk analysis be performed on a program at each of several milestones. Program risk analysis is discussed as a systems analysis approach, an iterative process (identification, assessment, management), and a collection of techniques. These techniques, which range from extremely simple to complex network-based simulation, are described in this handbook in order to provide both analyst and manager with a guide for selection of the most appropriate technique. All program risk assessment techniques are shown to be based on elicitation and encoding of subjective probability estimates from the various area experts on a program. Techniques to encode the five most common distribution types are given. Then, a total of twelve distinct approaches to risk assessment are given. Steps involved, good and bad points, time involved, and degree of computer support needed are listed. Why risk analysis should be used by all NASA program managers is discussed. Tools available at NASA-MSFC are identified, along with commercially available software. Bibliography (150 entries) and a program risk analysis check-list are provided.

Batson, R. G.

A Risk Analysis Tool for Estimating the Risk of Electrical Failures Due to Human Induced Defects

Aerospace electrical systems are required to withstand and adequately operate in extremely harsh environments that include, for example, high radiation exposure, temperature extremes, intense vibrational stress and drastic temperature cycling. The nature of aerospace electronics also demands high reliability since, with very few exceptions, there is no chance for hardware servicing or repairs. Common risk mitigation techniques for this type of situation are to perform a Reliability Analysis of the system throughout the development cycle, and to use electrical components that are regarded as “high reliability” because of additional controls and requirements applied in their design, manufacturing and testing. Unfortunately, studies have shown that even though these techniques are used, many systems fail to meet mission requirements well before the predicted lifetimes. This paper presents the analysis of failures of electrical parts, experienced during various stages of system development, at NASA Goddard Space Flight Center, Greenbelt MD, between the years 2001 and 2013. These components were subjected to qualification, screening and testing in which the goal was to ensure that the components would survive the stresses of the mission. The analysis categorizes failures by part type and failure mechanisms. One of the results of the analysis was the realization that a surprising proportion of failures experienced during system integration and testing were caused by human error (i.e. human induced defect). Further analysis included the determination of root failure mechanisms and any influencing factors contributing to these failures. The major causes of these defects were attributed to electrostatic damage (ESD), electrical overstress (EOS), mechanical overstress (MOS), and thermal overstress (TOS). Finally, the study proposes a risk analysis tool which incorporates these major causes for the failures, termed error-producing conditions (EPCs), and a proportionality factor representing the number of each type of failure that has occurred at the facility under study. These factors are quantified and used to communicate the risk of human induced defects for the assembly, integration and testing of space hardware based on the system’s electrical parts list. The new risk identification can trigger risk-mitigating actions more effectively, based on the presence of component categories or other hazardous conditions that have a history of failure due to human error.

Majewicz, Peter J.

Risk analysis methodology survey

NASA regulations require that formal risk analysis be performed on a program at each of several milestones as it moves toward full-scale development. Program risk analysis is discussed as a systems analysis approach, an iterative process (identification, assessment, management), and a collection of techniques. These techniques, which range from simple to complex network-based simulation were surveyed. A Program Risk Analysis Handbook was prepared in order to provide both analyst and manager with a guide for selection of the most appropriate technique.

Batson, Robert G.

American Airlines Propeller STOL Transport Economic Risk Analysis

A Monte Carlo risk analysis on the economics of STOL transports in air passenger traffic established the probability of making the expected internal rate of financial return, or better, in a hypothetical regular Washington/New York intercity operation.

Ransone, B.

Accounting for Point Estimate Uncertainty in Space Systems Reliability and Risk Analysis

Understanding and accounting for uncertainty in risk analysis is a critical step in the management and communication of risk in engineered systems. The component and system-level analysis to determine the probability of a negative outcome and its consequence is often quantified by a point estimate. Many Program and Enterprise decisions involving technical concerns and issues rely on reliability engineering activities to produce quantified risk analysis to inform the decision making process. At NASA, it is common to use a Probabilistic Risk Analysis (PRA) to inform the overall risk to Loss of Mission or Loss of Crew that involves integration across all spacecraft subsystem fault trees to produce an overall probability of mission failure. The point estimate is an estimate of this overall probability and is an immediate result of a fault tree model. It is the result of a model where the probability of each event is taken to be equal to its mean. The value provides an approximation of the overall mean without running any uncertainty calculations (e.g., no sampling). Using only the point estimate can lead to a false sense of precision and the point estimate may not match the resulting mean when uncertainty is taken into consideration. This paper will explore five conditions that can cause the PRA model mean to diverge from the point estimate and will provide engineers and managers insight into the importance of understanding uncertainty in the elements of PRA models.

Paul J Collier

Nasa Conjunction Assessment Risk Analysis Updated Requirements Architecture

The NASA Conjunction Assessment Risk Analysis (CARA) program has been performing routine on-orbit satellite conjunction risk analysis for unmanned NASA spacecraft since 2005, and has developed a robust operations procedure and set of recommended best practices for operational conjunction assessment. However, a number of recent developments in Space Situational Awareness and commercial space operations conduct, such as the immanent deployment of much more sensitive space sensing systems and the launching of much larger satellite constellations, have begun to challenge these standard collision risk parameters and calculations. In response CARA has pursued a multi-year evaluation initiative to re-examine risk assessment algorithms and techniques, to develop needed improvements, and to assemble analysis-based operational requirements. This paper gives an overview of the principal parts of the Conjunction Assessment (CA) risk assessment process used at CARA, outlines the technical challenges that each part presents, surveys the possible solutions, and then indicates which particular solution is being recommended for NASA.

Newman, Lauri K.

Carbon/graphite fiber risk analysis and assessment study: An assessment of the risk to Douglas commercial transport aircraft

The potential hazard to electrical and electronic devices should there be a release of free carbon fibers due to an aircraft crash and fire was assessed. Exposure and equipment sensitivity data were compiled for a risk analysis. Results are presented in the following areas: DC-9/DC-10 electrical/electronic component characterization; DC-9 and DC-10 fiber transfer functions; potential for transport aircraft equipment exposure to carbon fibers; and equipment vulnerability assessment. Results reflect only a negligible increase in risk for the DC-9 and DC-10 fleets either now or projected to 1993.

Schjelderup, H. C.

NASA Conjunction Assessment Risk Analysis (CARA) Updated Requirements Architecture

The NASA Conjunction Assessment Risk Analysis (CARA) program has been performing routine on-orbit satellite conjunction risk analysis for unmanned NASA spacecraft since 2005, and has developed a robust operations procedure and set of recommended best practices for operational conjunction assessment. However, a number of recent developments in Space Situational Awareness and commercial space operations conduct, such as the immanent deployment of much more sensitive space sensing systems and the launching of much larger satellite constellations, have begun to challenge these standard collision risk parameters and calculations. In response CARA has pursued a multi-year evaluation initiative to re-examine risk assessment algorithms and techniques, to develop needed improvements, and to assemble analysis-based operational requirements. This paper gives an overview of the principal parts of the Conjunction Assessment (CA) risk assessment process used at CARA, outlines the technical challenges that each part presents, surveys the possible solutions, and then indicates which particular solution is being recommended for NASA.

Newman, L. K.

Trade Studies of Space Launch Architectures using Modular Probabilistic Risk Analysis

A top-down risk assessment in the early phases of space exploration architecture development can provide understanding and intuition of the potential risks associated with new designs and technologies. In this approach, risk analysts draw from their past experience and the heritage of similar existing systems as a source for reliability data. This top-down approach captures the complex interactions of the risk driving parts of the integrated system without requiring detailed knowledge of the parts themselves, which is often unavailable in the early design stages. Traditional probabilistic risk analysis (PRA) technologies, however, suffer several drawbacks that limit their timely application to complex technology development programs. The most restrictive of these is a dependence on static planning scenarios, expressed through fault and event trees. Fault trees incorporating comprehensive mission scenarios are routinely constructed for complex space systems, and several commercial software products are available for evaluating fault statistics. These static representations cannot capture the dynamic behavior of system failures without substantial modification of the initial tree. Consequently, the development of dynamic models using fault tree analysis has been an active area of research in recent years. This paper discusses the implementation and demonstration of dynamic, modular scenario modeling for integration of subsystem fault evaluation modules using the Space Architecture Failure Evaluation (SAFE) tool. SAFE is a C++ code that was originally developed to support NASA s Space Launch Initiative. It provides a flexible framework for system architecture definition and trade studies. SAFE supports extensible modeling of dynamic, time-dependent risk drivers of the system and functions at the level of fidelity for which design and failure data exists. The approach is scalable, allowing inclusion of additional information as detailed data becomes available. The tool performs a Monte Carlo analysis to provide statistical estimates. Example results of an architecture system reliability study are summarized for an exploration system concept using heritage data from liquid-fueled expendable Saturn V/Apollo launch vehicles.

Mathias, Donovan L.

Command Process Modeling & Risk Analysis

Commanding Errors may be caused by a variety of root causes. It's important to understand the relative significance of each of these causes for making institutional investment decisions. One of these causes is the lack of standardized processes and procedures for command and control. We mitigate this problem by building periodic tables and models corresponding to key functions within it. These models include simulation analysis and probabilistic risk assessment models.

functional analysis