Search NASASearch

SEARCH · Search NASA

Results for “risk matrix”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Development of Risk Assessment Matrix for NASA Engineering and Safety Center

This paper describes a study, which had as its principal goal the development of a sufficiently detailed 5 x 5 Risk Matrix Scorecard. The purpose of this scorecard is to outline the criteria by which technical issues can be qualitatively and initially prioritized. The tool using this score card has been proposed to be one of the information resources the NASA Engineering and Safety Center (NESC) takes into consideration when making decisions with respect to incoming information on safety concerns across the entire NASA agency. The contents of this paper discuss in detail each element of the risk matrix scorecard, definitions for those elements and the rationale behind the development of those definitions. This scorecard development was performed in parallel with the tailoring of the existing Futron Corporation Integrated Risk Management Application (IRMA) software tool. IRMA was tailored to fit NESC needs for evaluating incoming safety concerns and was renamed NESC Assessment Risk Management Application (NAFMA) which is still in developmental phase.

Malone, Roy W., Jr.

Peru Health and Air Quality II: Leveraging Earth Observations and Health Data to Map Outbreak Risk and Inform Public Health Interventions for Zoonotic Disease Prevention

Peru's Madre de Dios region is a hotspot for dengue fever and leishmaniasis due to its tropical Amazonian climate. Though treatable, these zoonotic diseases are debilitating for under-resourced communities whose already close proximity to mosquito and sandfly vectors continues to increase via rapid urbanization and deforestation. Peru’s Ministries of Health (MINSA) and Environment (MINAM) are working to better understand the environmental factors amplifying the risk of dengue fever and leishmaniasis transmission. The first term of this project classified the land use and land cover of Madre de Dios’ 11 districts for 2010, 2015, and 2020 and identified a correlation between both diseases and urbanization. Our team expanded this analysis by creating urban-forest edge maps and incorporating climatic and topographic variables with data from Landsat 7 Enhanced Thematic Mapper Plus (ETM+), Landsat 8 Operational Land Imager (OLI), the Global Precipitation Measurement (GPM) Integrated Multi-satellitE Retrievals for GPM (IMERG), and the Shuttle Radar Topography Mission (SRTM). We determined these variables’ impacts on disease incidence by assessing existing literature and running regression models. Dengue fever correlated with urban-forest edge, urban area, slope, temperature, and precipitation. Leishmaniasis primarily correlated with forest-edge area and elevation, but lacking additional statistical significance prevented further work, a decision supported by the literature. Thus, the risk matrix and risk map which we scripted in R to visualize the risk of disease posed to districts alongside health post locations addresses only dengue fever. The results and products will inform MINSA and MINAM in public health interventions, resource distribution, and policy initiatives.

Jennifer Rogers

Recognizing and Assigning Risks and Responsibilities Using the Risk, Responsibility, and Performance (RRP) Matrix

The Risk, Responsibility, and Performance Matrix (RRP Matrix) is the energy savings performance contract (ESPC) document that focuses on 16 areas of risks and responsibilities in an ESPC project. The RRP Matrix summarizes and documents the contractor (energy service company, i.e., ESCO) and ordering agency’s agreements about allocating risks and responsibilities – to the ESCO, to the ordering agency, or shared. Ordering agencies and ESCOs should be mindful, however, that the ESCO remains responsible for achieving energy savings guaranteed under the ESPC, notwithstanding the allocations of risks, responsibilities, and performance.

Walker, Christine

Risk Management for Human Support Technology Development

NASA requires continuous risk management for all programs and projects. The risk management process identifies risks, analyzes their impact, prioritizes them, develops and carries out plans to mitigate or accept them, tracks risks and mitigation plans, and communicates and documents risk information. Project risk management is driven by the project goal and is performed by the entire team. Risk management begins early in the formulation phase with initial risk identification and development of a risk management plan and continues throughout the project life cycle. This paper describes the risk management approach that is suggested for use in NASA's Human Support Technology Development. The first step in risk management is to identify the detailed technical and programmatic risks specific to a project. Each individual risk should be described in detail. The identified risks are summarized in a complete risk list. Risk analysis provides estimates of the likelihood and the qualitative impact of a risk. The likelihood and impact of the risk are used to define its priority location in the risk matrix. The approaches for responding to risk are either to mitigate it by eliminating or reducing the effect or likelihood of a risk, to accept it with a documented rationale and contingency plan, or to research or monitor the risk, The Human Support Technology Development program includes many projects with independently achievable goals. Each project must do independent risk management, considering all its risks together and trading them against performance, budget, and schedule. Since the program can succeed even if some projects fail, the program risk has a complex dependence on the individual project risks.

jones, Harry

Machine Learning Enabled Quantitative Risk Assessment of Aerial Wildfire Response

Aerial wildfire operations are high risk and account for a large number of firefighter deaths. Increasing intensity of wildfires is driving a surge in aerial operations, while simultaneously there is growing interest in improving system safety and performance. In this work, wildfire aviation mishaps documented using the SAFECOM system are analyzed using a previously developed framework for hazard extraction and analysis of trends (HEAT). Hazards and specific failure modes are extracted from the narrative data in SAFECOM forms using natural language processing techniques. Metrics for each hazard are calculated, including frequency, rate, and severity. We examine whether these metrics change over time, and whether they are related to metadata, such as region and aircraft type. The results of the hazard analysis are presented in a risk matrix, identifying the highest and lowest risk hazards based on rate of occurrence and average severity. Results identify jumper operations hazards as high-risk, in addition to bucket drop failures, cargo let down failures, and severe weather as medium risk.

machine learning

Machine Learning Enabled Quantitative Risk Assessment of Aerial Wildfire Response

Aerial wildfire operations are high risk and account for a large number of firefighter deaths. Increasing intensity of wildfires is driving a surge in aerial operations, while simultaneously there is growing interest in improving system safety and performance. In this work, wildfire aviation mishaps documented using the SAFECOM system are analyzed using a previously developed framework for hazard extraction and analysis of trends (HEAT). Hazards and specific failure modes are extracted from the narrative data in SAFECOM forms using natural language processing techniques. Metrics for each hazard are calculated, including frequency, rate, and severity. We examine whether these metrics change over time, and whether they are related to metadata, such as region and aircraft type. The results of the hazard analysis are presented in a risk matrix, identifying the highest and lowest risk hazards based on rate of occurrence and average severity. Results identify jumper operations hazards as high-risk, in addition to bucket drop failures, cargo let down failures, and severe weather as medium risk.

machine learning

Quantifying Cybersecurity Risk for NASA Missions

An end-to-end cyber risk assessment process is presented that is based on the combination of guidelines from the National Institute of Standards & Technology (NIST), the standard 5x5 risk matrix, and quantitative methods for generating loss exceedance curves. The NIST guidelines provide a framework for cyber risk assessment, and the standard 5x5 matrix is widely used across the industry for the representation of risk across multiple disciplines. Loss exceedance curves are a means of quantitatively assessing the loss that occurs due to a given risk profile. Combining these different techniques enables us to follow the guidelines, adhere to standard 5x5 risk management practices and develop quantitative metrics simultaneously. Our quantification process is based on the consideration of the NASA and JPL Cost Risk assessment modeling techniques as we define the cost associated with the cybersecurity risk profile of a mission as a function of the mission cost.

Miller, Robert L.

Summary of Pilot Project State Technical Assistance on Multi-Sector Analysis for Electric and Petroleum Fuels

The Oregon Energy Security Plan, (ODOE 2024) published in September 2024, builds a strong case for the state to give acute attention to the fuel supply chain. In December 2024, Pacific Northwest National Laboratory (PNNL) in partnership with Oregon Department of Energy (ODOE), announced a pilot project to conduct an analysis that synthesizes current and projected transportation fuel dynamics, supply chain risks, and risk comparators with relevant sectors, such as transportation electrification, sponsored by the Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER). The study, is intended to leverage existing modeling and frameworks from a recent 2024 sector coupling analysis supported by the DOEs Office of Electricity (OE) (B. Mitra, S. Pal, et al., Coupling of the Electricity and Transportation Sectors - Part I: Sector Overviews 2024) (B. Mitra, S. Pal and J. Reeve, et al. 2024). While the PNNL team set out to conduct a quantitative risk analysis driven by detailed data that synthesizes current and projected transportation fuel dynamics, supply chain risks, and risk comparators with relevant sectors. The intention was to provide an approach that could be extendable to other parts of the country. They encountered data limitations and adjusted their approach accordingly. This report summarizes PNNL's original plan for executing the study, including limitations for obtaining data requirements for fuel flows and interim products, as well as a risk matrix that can be used to identify supply chain risks.

02 PETROLEUM

Understanding Pre-Quantitative Risk in Projects

Standard approaches to risk management in projects depend on the ability of teams to identify risks and quantify the probabilities and consequences of these risks (e.g., the 5 x 5 risk matrix). However, long before quantification does - or even can - occur, and long after, teams make decisions based on their pre-quantitative understanding of risk. These decisions can have long-lasting impacts on the project. While significant research has looked at the process of how to quantify risk, our understanding of how teams conceive of and manage pre-quantitative risk is lacking. This paper introduces the concept of pre-quantitative risk and discusses the implications of addressing pre-quantitative risk in projects.

risk levels.

Machine Learning Framework for Hazard Extraction and Analysis of Trends (HEAT) in Wildfire Response

This research proposes a natural language processing enabled risk analysis framework, named Hazard Extraction andAnalysis of Trends (HEAT), and applies the framework to the ICS-209-PLUS data set of wildfire incident responseforms. The HEAT framework produces safety- and risk- relevant analyses, consisting of: (1) a set of hazards extractedfrom text data, (2) a primary analysis using hazard-relevant metrics, such as rate and severity, to form an FMEA-styletable and risk matrix, (3) a time series analysis of metric trends, and (4) a secondary analysis examining potentialpredictors for hazards. Results from HEAT provide quantitative risk-relevant information for high-level hazards doc-umented in existing-state operations. Because of the generalizability of the steps and limited data requirements, HEATcan be applied to any dataset containing narrative text, thus providing a framework for data-driven machine learning-enabled quantitative risk analysis across a variety of domains. To demonstrate HEAT in a case study, we apply theframework to the ICS-209-PLUS dataset of wildland fire incident response forms. Hazards identified in wildfire re-sponse arise from environmental conditions, the mission, and the wildland urban interface. The resulting risk matrixidentifies evacuations as high-risk hazards, while all other identified hazards are medium or serious risk.

natural language processing

Method for Tracking and Communicating Aggregate Risk Through the Use of Model-Based Systems Engineering (MBSE) Tools

Large, complex projects can identify a significant number and variety of risks, throughout the project life cycle. These risks are analyzed, mitigated, closed or accepted as independent uncertainties. Once closed or accepted, it is easy for projects to lose awareness of their impact. In reality, each of these risks contributes some amount to the overall risk posture of the project. The ability to track and effectively communicate this aggregate risk has represented a challenge to project management. There have been previous attempts to create a schema to communicate the aggregate effect of risks, without notable success. Most of these attempts have centered on some additive metric derived from the scoring of likelihood and consequence values. This, in and of itself, is a logical approach, but all too often the scores were then aggregated to a level where all context was lost. One weakness has been a lack of attempt to create linkages or logical groups of the risks upon which useful aggregation could then occur. The overall move to model-based (systems) engineering (MBSE) has opened up a vast frontier of opportunities to better integrate all project data. MBSE provides an underlying layer that links data items to each other. Objectives link to requirements, which then link to functions, functions to physical architecture items, and so on, as far down as projects want to model. While it started with a focus on modeling requirements based on things like use cases, efforts are now underway to integrate safety and mission assurance (S&MA) information and analyses, such as risks. This effort, called Model Based Mission Assurance (MBMA), is yielding models that are more useful and are a more accurate representations of the systems. MBSE models, with this ability to link related items, provide a new means of tracking and communicating aggregate risks. In the proposed method, risks are added into the models as distinct items, having attributes that communicate a scoring derived from the likelihood and consequence values as charted on the standard NASA 5x5 risk matrix. Like earlier efforts, each box in the 5x5 has an associated scoring, which may include both a current score and potential post-mitigation/control score. The risk items are then linked to elements of the model, such as system objectives/goals, requirements, functions, or physical architecture items, with "Risk to" relationships. These risks will then be communicated by use of reports generated from the model, detailing all risks and/or hazards linked to model elements. These reports can include aggregate impacts, including a current scoring and potential future state scoring based on the planned mitigations and/or controls. These reports will show all risks, open, accepted, and closed, linked to project objectives or requirements. When run as part of an upcoming risk acceptance discussion, these reports will serve to remind the team of all previous risks that relate to the effected portion of the system. When included as part of periodic program or project reviews, risk reviews, and safety reviews, this method can improve the overall understanding of the system's true risk posture. This proposed method takes full advantage of the advances that modern modeling techniques provide, with a minimal investment of additional time. Utilizing the model environment also enables a near constant access to current state of aggregate risks.

model based mission assurance

Qualitative Risk Assessment of Legacy Wells within the Estimated Prairie State Generating Company Area of Review

This report details the digitization of a legacy wellbore database, including data processing assumptions, parameter estimation, and risk assessment methodology. The database, comprising 6,454 documents, was provided by ISGS. It includes valuable data from the Prairie State Generating Company (PSGC) and One Earth Energy (OEE) sites of the CarbonSAFE Phase III – Illinois Storage Corridor project. The report focuses on wells within a 15-mile radius from the Lively Grove #1 (LG#1) well at PSGC site, evaluating subsurface conditions and potential risks. A total of 4,386 wellbores within 15 miles of the LG#1 well were filtered based on depth and formation codes. LG#1 is the stratigraphic well at the PSGC site drilled in 2021. Ninety-four (94) wells penetrating the Maquoketa Shale Group (the primary confining unit) within the estimated area-of-review (AoR) for the PSGC site were evaluated using a qualitative risk assessment (QRA) methodology. The QRA developed by Arbad et al. 2022 focuses on legacy wells within the AoR and categorizes them based on well construction details. The QRA identifies wells that need immediate attention by categorizing them based on penetration depth and protection. Wells within the AoR were categorized into nine groups based on penetrations and protections. These categories range from Type 1 wells, with no documentation, to Type 9 wells, which do not penetrate the primary confining unit or storage reservoir (unit). Well accessibility within the AoR varies based on well status, including Dry & Abandoned (DA), Plugged & Abandoned (PA), Injection (INJ), Oil/Gas Producing (PROD), and Observation (Obs) wells. Accessibility levels were determined by well construction, with DA wells being the least accessible and Observation wells the most accessible, impacting gas leakage detection possibilities. Remedial action priority of wells decreases from Type 1 to Type 9 wells. Type 1 to Type 6 wells with status DA and PA require immediate attention, while Type 7 and Type 8 wells are low priority. A risk matrix used to prioritize corrective actions for legacy wells is proposed to categorize wells within an AoR based on penetrations, protections, and accessibility. The methodology involves data acquisition, well categorization into nine types, and determining CO 2 leakage pathways using well schematics and geospatial mapping. This approach is particularly useful for managing the integrity of legacy wells throughout the lifecycle of a Carbon Capture and Storage (CCS) project. A qualitative risk assessment of 94 wells within the AoR of the PSGC site identified 54 wells with high priority for corrective action due to penetration of the primary containment seal. The assessment utilizes color-coded maps to categorize well types and prioritize corrective actions, providing a comprehensive analysis. Schematics of wells penetrating the primary confining unit were drawn, and leakage pathways were identified. Details of all wells penetrating the confining zone are provided in the appendix, including information on well types, plugging, and casing status.

01 COAL, LIGNITE, AND PEAT

The Future of X-ray Irradiation: Addressing Supply Chain Risks and Opportunities (UUR Edition)

This study supports the Office of Radiological Security’s (ORS) mission of eliminating cesium irradiators by analyzing the supply chain for self-shielded X-ray irradiators (SSXIs), identifying potential risks, and proposing mitigation measures. The research focuses on the primary components of SSXIs, including X-ray tubes, controllers, generators, and coolers or chillers, and evaluates their vulnerabilities using a comprehensive risk matrix framework. The methodology includes subject matter expert (SME) interviews with relevant manufacturers and major stakeholders, a deep literature review, and a meta-analysis of maintenance reports provided by SSXI end users. Results show that while the SSXI market is small, it’s growing, and the highly global nature of the supply chain may create vulnerabilities for critical SSXI components (X-ray tubes are the most vulnerable, followed by generators and controllers). This research communicates necessary information to address concerns of current and future end users, especially those interested in transitioning away from radioactive sources, and informs future policy aimed at supporting the irradiation industry.

07 ISOTOPE AND RADIATION SOURCES

Silent Aircraft Initiative Concept Risk Assessment

A risk assessment of the Silent Aircraft Initiative's SAX-40 concept design for extremely low noise has been performed. A NASA team developed a list of 27 risk items, and evaluated the level of risk for each item in terms of the likelihood that the risk would occur and the consequences of the occurrence. The following risk items were identified as high risk, meaning that the combination of likelihood and consequence put them into the top one-fourth of the risk matrix: structures and weight prediction; boundary-layer ingestion (BLI) and inlet design; variable-area exhaust and thrust vectoring; displaced-threshold and continuous descent approach (CDA) operational concepts; cost; human factors; and overall noise performance. Several advanced-technology baseline concepts were created to serve as a basis for comparison to the SAX-40 concept. These comparisons indicate that the SAX-40 would have significantly greater research, development, test, and engineering (RDT&E) and production costs than a conventional aircraft with similar technology levels. Therefore, the cost of obtaining the extremely low noise capability that has been estimated for the SAX-40 is significant. The SAX-40 concept design proved successful in focusing attention toward low noise technologies and in raising public awareness of the issue.

Nickol, Craig L.

Natural Language Processing Techniques for Intelligent Knowledge Management of Safety Reports

Safety, failure, and incident reports are common artifacts across various domains, including aviation and wildfire response. These reports are often mandatory to submit, resulting in the culmination of large repositories of text-based documents. Simultaneously, these reports and corresponding repositories are often only manually analyzed and queried by users via out-of-date search engines. As a consequence, we have been developing the Manager for Intelligent Knowledge Access (MIKA) toolkit, which uses natural language processing to improve information access and reuse. In this presentation, we discuss natural language processing techniques for knowledge discovery and apply these methods to a repository of aerial wildfire mishap reports. Two methods are used for knowledge discovery: topic modeling and named-entity recognition. We use topic modeling to identify hazards and perform a trend analysis to produce a data-driven risk matrix. A custom named-entity recognition model, build from fine tuning a pre-trained language model, is used to identify failure modes, failure causes, failure effects, control processes, and recommendations to aid in failure modes and effects analysis (FMEA). Throughout the presentation, we discuss and apply natural language processing techniques to better leverage the vast amount of information contained in report repositories.

Machine learning

Multiple Changes to Reusable Solid Rocket Motors, Identifying Hidden Risks

The Space Shuttle Reusable Solid Rocket Motor (RSRM) baseline is subject to various changes. Changes are necessary due to safety and quality improvements, environmental considerations, vendor changes, obsolescence issues, etc. The RSRM program has a goal to test changes on full-scale static test motors prior to flight due to the unique RSRM operating environment. Each static test motor incorporates several significant changes and numerous minor changes. Flight motors often implement multiple changes simultaneously. While each change is individually verified and assessed, the potential for changes to interact constitutes additional hidden risk. Mitigating this risk depends upon identification of potential interactions. Therefore, the ATK Thiokol Propulsion System Safety organization initiated the use of a risk interaction matrix to identify potential interactions that compound risk. Identifying risk interactions supports flight and test motor decisions. Uncovering hidden risks of a full-scale static test motor gives a broader perspective of the changes being tested. This broader perspective compels the program to focus on solutions for implementing RSRM changes with minimal/mitigated risk. This paper discusses use of a change risk interaction matrix to identify test challenges and uncover hidden risks to the RSRM program.

Greenhalgh, Phillip O.