Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Integrated formal methods”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

A Performance Analysis of Folding Conformal Propeller Blade Designs

NASA’s X-57 Maxwell flight demonstrator has a high-lift system that includes 12 fixed- pitch high-lift propellers located upstream of the wing leading edge for lift augmentation at low speeds. These high-lift propellers are only required at low speeds, and to reduce drag, the propeller blades are folded conformally along the nacelles at other operating conditions. The method of designing the high-lift blades permits several variations of blade cross-section placement along the nacelle surface and a comparative performance analysis was needed to determine if any particular design showed significant benefits. We analyzed the performance of three conformal high-lift propeller designs and compared them to that of a non-conformal baseline propeller to establish both the benefit of stowable blades and the value of each variation. In this study, we first performed a drag analysis of each design in the stowed configuration at the X-57 cruise speed and altitude to determine the drag benefits of each conforming method. Then, among blade designs we compared the thrust, power, and lift for a given input shaft speed to establish any performance losses from the baseline. This analysis shows that the conformal blade designs do not have any appreciable performance losses compared to the baseline blades. Moreover, although the drag in the cruise condition is significantly less than for the non-folding baseline, the drag benefits of each conforming blade approach are similar and the value of each approach largely depends on the ease of integration into the nacelle. This paper presents the results of these studies and discusses the benefits and drawbacks of implementing the conformal blade designs. Specifically, we demonstrate that folding, conformal propeller blades contribute significantly less to cruise drag when compared to windmilling, with an increase relative to a. We also show a less than 1% difference in performance formal, folding propellers and the non-conforming baseline propeller.

Litherland, Brandon L.↗

Integrated topology and shape optimization in structural design

Structural optimization procedures usually start from a given design topology and vary its proportions or boundary shapes to achieve optimality under various constraints. Two different categories of structural optimization are distinguished in the literature, namely sizing and shape optimization. A major restriction in both cases is that the design topology is considered fixed and given. Questions concerning the general layout of a design (such as whether a truss or a solid structure should be used) as well as more detailed topology features (e.g., the number and connectivities of bars in a truss or the number of holes in a solid) have to be resolved by design experience before formulating the structural optimization model. Design quality of an optimized structure still depends strongly on engineering intuition. This article presents a novel approach for initiating formal structural optimization at an earlier stage, where the design topology is rigorously generated in addition to selecting shape and size dimensions. A three-phase design process is discussed: an optimal initial topology is created by a homogenization method as a gray level image, which is then transformed to a realizable design using computer vision techniques; this design is then parameterized and treated in detail by sizing and shape optimization. A fully automated process is described for trusses. Optimization of two dimensional solid structures is also discussed. Several application-oriented examples illustrate the usefulness of the proposed methodology.

Bremicker, M.↗

Probabilistic Study of Fluid Structure Interaction

Probabilistic CFD design is needed because we are asked to do more with less. To cost effectively accomplish the design task, we need to formally quantify the effect of uncertainties (variables) in the design. Probabilistic design is one effective method to formally quantify the effect of uncertainties. Our objective is to establish a revolutionary new early design process, by developing non-deterministic physics-based probabilistic design tools, which will include all the life cycle processes. Breakthroughs will be sought in speed, accuracy, intelligence, and usability of the system. This paper is concerned with the usefulness of parametric optimization method coupled with a Navier-Stokes analysis code for the aero-thermodynamic design of turbomachinery combustor liner. The interconnection between the CFD code and NESSUS codes facilitated the coupling between the thermal profiles and structural design. We have developed new concepts for reducing the computational cost of unsteady, three-dimensional, compressible aerodynamic analyses for multistage turbomachinery flows. The flow was modeled by the three-dimensional Favre-Reynolds-averaged Navier-Stokes equations using the k-epsilon turbulence closure, which was integrated using an implicit third-order upwind solver. The methodology developed in this paper is expected to lead to the design optimization of turbomachinery blades.

Gorla, Rama S. R.↗

Data-Flow Based Model Analysis

The concept of (meta) modeling combines an intuitive way of formalizing the structure of an application domain with a high expressiveness that makes it suitable for a wide variety of use cases and has therefore become an integral part of many areas in computer science. While the definition of modeling languages through the use of meta models, e.g. in Unified Modeling Language (UML), is a well-understood process, their validation and the extraction of behavioral information is still a challenge. In this paper we present a novel approach for dynamic model analysis along with several fields of application. Examining the propagation of information along the edges and nodes of the model graph allows to extend and simplify the definition of semantic constraints in comparison to the capabilities offered by e.g. the Object Constraint Language. Performing a flow-based analysis also enables the simulation of dynamic behavior, thus providing an "abstract interpretation"-like analysis method for the modeling domain.

Saad, Christian↗

A Verification Framework for Runtime Assurance of Autonomous UAS

Runtime Assurance (RTA) is a design-time architecture for safety-critical systems where an internal monitor acts upon detecting a violation of a property. The simplex architecture is an instance of RTA, where the action taken is to hand control of the overall system to a trusted controller when an untrusted one violates a safety property. Simplex RTA is emerging as a method for allowing AI/ML and other unverified software to be integrated into safety-critical applications like aircraft. To this end, the American Society for Testing and Materials (ASTM) and NASA have each published guidelines on the use of RTA in such systems. In the simplex RTA framework, a system has an advanced controller (AC) and a reversionary controller (RC). The system is allowed to operate with the AC until a runtime monitor detects that some property has been violated and then the RC takes over. Assuming that the sample rate of the monitor will detect improper functioning with enough time for the RC to correct the impending problem, and that the RC is trusted, the system will operate as intended. This use of the simplex RTA framework can allow for the integration of untrusted, but possibly more performant, controllers in a safe way. This paper presents a formalization of a simplex RTA framework in the Prototype Verification System (PVS) theorem prover using an embedding of differential dynamic logic (DDL) called Plaidypvs. A novel feature of this framework is that it can be instantiated at different levels of abstraction. This feature allows for the formal verification of a system with an untrusted black box component, such as an AI/ML controller. This paper does not address the many difficulties in deploying RTA in an industrial-level system. Instead, the focus is on the formal verification of the simplex RTA framework in the language of hybrid programs. Hybrid programs are programs that include both discrete and continuous dynamics and can be used to model complex cyber-physical systems. Plaidypvs is a tool that enables formalization of hybrid programs in the PVS theorem prover. Plaidypvs enables the verification of the general simplex RTA framework and then, by specializing some components of the hybrid program, verifying instances of the framework while treating the untrusted component as a black box. A selection of Unmanned Aircraft Systems (UAS) operations are shown as instances of the general RTA framework in PVS. This offers the benefit of design time verification of relevant safety properties to the system, and it also gives requirements on the sample rate of sensors that determine the time interval in which the ‘switch’ property of the RTA framework is checked.

PVS↗

3D mesh regularization within an ALE code using a weighted line sweeping method

The Lagrangian formalism is widely used to simulate hydrodynamic responses in complex engineering applications, particularly those involving strong shock waves. However, as the mesh moves with the fluid, it can become highly distorted, requiring a regularization step. This involves constructing a new grid and remapping conservative quantities onto it to restore mesh quality. This work introduces a regularization method for block-structured meshes within a 3D ALE (Arbitrary Lagrangian-Eulerian) code. The proposed approach prevents mesh tangling while preserving the anisotropic features of the initial Lagrangian mesh. This regularization technique incorporates aspect ratio-based weights to control mesh smoothing. Unlike uniform rezoning techniques, this weighted approach maintains proximity to the Lagrangian mesh while improving mesh quality. Here, the method effectively handles concave geometries by mitigating the grid attraction phenomenon, which typically leads to mesh concentration along concave edges. Numerical experiments demonstrate its efficiency in regularizing severely deformed meshes, and its integration within the ALE framework is validated on challenging hydrodynamic test cases, including the triple point problem.

42 ENGINEERING↗

Bridging the Gap between Earth Science and Students: An Integrated Approach using NASA Earth Science Climate Data

Under the auspices of the Department of Education's No Child Left Behind (NCLB) Act, beginning in 2007 students will be tested in the science area. There are many techniques that educators can employ to teach students science. The use of authentic materials or in this case authentic data can be an engaging alternative to more traditional methods. An Earth science classroom is a great place for the integration of authentic data and science concepts. The National Aeronautics and Space Administration (NASA) has a wealth of high quality Earth science data available to the general public. For instance, the Atmospheric Science Data Center (ASDC) at NASA s Langley Research Center houses over 800 Earth science data sets related to Earth's radiation budget, clouds, aerosols and tropospheric chemistry. These data sets were produced to increase academic understanding of the natural and anthropogenic factors that influence global climate; however, a major hurdle in using authentic data is the size of the data and data documentation. To facilitate the use of these data sets for educational purposes, the Mentoring and inquirY using NASA Data on Atmospheric and Earth science for Teachers and Amateurs (MY NASA DATA) project has been established to systematically support educational activities at all levels of formal and informal education. The MY NASA DATA project accomplishes this by reducing these large data holdings to microsets that are easily accessible and explored by K-12 educators and students though the project's Web page. MY NASA DATA seeks to ease the difficulty in understanding the jargon-heavy language of Earth science. This manuscript will show how MY NASA DATA provides resources for NCLB implementation in the science area through an overview of the Web site, the different microsets available, the lesson plans and computer tools, and an overview of educational support mechanisms.

Alston, Erica J.↗

Structure-aware Initialization via Numerical Continuation and Informed Priors

Scientific machine learning (SciML) often operates in ill-conditioned, weakly identifiable regimes due to limited data or indirect observations. In such settings, optimization and inference are highly sensitive to the starting point, making initialization--often under-reported--a consequential degree of freedom. Random initialization is not a neutral default as it induces an implicit prior over candidate solutions and can systematically bias the result, producing large run-to-run variability. Here, we formalize this view by treating initialization as a hidden confounder in SciML and develop a unifying theory for structure-aware initialization via numerical continuation, constructing warm starts from related problem instances. Across representative tasks, including physics-informed neural networks, maximum likelihood estimation, and variational inference, warm starts have been shown to consistently reduce optimization effort and improve reliability.

Data integrity↗

Challenges and Demands on Automated Software Revision

In the past three decades, automated program verification has undoubtedly been one of the most successful contributions of formal methods to software development. However, when verification of a program against a logical specification discovers bugs in the program, manual manipulation of the program is needed in order to repair it. Thus, in the face of existence of numerous unverified and un- certified legacy software in virtually any organization, tools that enable engineers to automatically verify and subsequently fix existing programs are highly desirable. In addition, since requirements of software systems often evolve during the software life cycle, the issue of incomplete specification has become a customary fact in many design and development teams. Thus, automated techniques that revise existing programs according to new specifications are of great assistance to designers, developers, and maintenance engineers. As a result, incorporating program synthesis techniques where an algorithm generates a program, that is correct-by-construction, seems to be a necessity. The notion of manual program repair described above turns out to be even more complex when programs are integrated with large collections of sensors and actuators in hostile physical environments in the so-called cyber-physical systems. When such systems are safety/mission- critical (e.g., in avionics systems), it is essential that the system reacts to physical events such as faults, delays, signals, attacks, etc, so that the system specification is not violated. In fact, since it is impossible to anticipate all possible such physical events at design time, it is highly desirable to have automated techniques that revise programs with respect to newly identified physical events according to the system specification.

Bonakdarpour, Borzoo↗

Numerical Techniques for Scattering from Submerged Objects

To represent the final results in terms of matrices, one expands all appropriate physical quantities in terms of partial wave basis states. This includes expansions for the incident and scattered fields and the surface quantities. The method then utilizes the Huygen-Poincare integral representation for both the exterior and interior solutions, leading to the required matrix equations. One thus deals with matrix equations, the complexity of which depends on the nature of the problem. It is shown that in general a transition matrix T can be obtained relating the incident field A with the scattered field f having the form T = PQ(-1), where f = TA. The structure of Q can be quite complicated and can itself be composed of other matrix inversions such as arise from layered objects. Recent improvements in this method appropriate for a variety of physical problems are focused on, and on their implementation. Results are outlined from scattering simulations for very elongated submerged objects and resonance scattering from elastic solids and shells. The final improvement concerns eigenfunction expansions of surface terms, arising from solution of the interior problem, obtained via a preconditioning technique. This effectively reduces the problem to that of obtaining eigenvalues of a Hermitian operator. This formalism is reviewed for scattering from targets that are rigid, sound-soft, acoustic, elastic solids, elastic shells, and elastic layered objects. Two sets of the more interesting results are presented. The first concerns scattering from elongated objects, and the second to thin elastic spheroids.

Werby, M. F.↗

Fault tolerant system performance modeling

With the proliferation of complex digital systems on aircraft, the need to accurately predict system performance early in the system design cycle becomes imperative. In the past, system designers have relied on ad hoc methods for evaluating performance issues. This has produced systems that have not always worked as originally intended. To alleviate these design deficiencies, formal methods, with supporting tools, must be adhered to during the system design process. The use of performance modeling tools is becoming widely accepted as a way to address timing considerations of system design. An additional incentive for the use of these tools is that they allow the system architect to analyze system component interactions (i.e., bus contention, contention of functions for a processing site, and system repair activity on application performance). This inherent flexibility can result in an explicit specification of the system architecture. This paper addresses a method that supports performance modeling of fault tolerant systems using a discrete event simulation tool. An additional focus is on lessons learned from analyzing these classes of problems. The methodology and supporting work provide system architects with the capability to specify candidate architectures and accurately predict their performance in the early stages of design, where changes to system design is most cost effective. The work has been supported under NASA contract NAS1-18099. Integrated Airframe Propulsion Control System Architecture (IAPSA II). This contract addresses methodology, analysis, and detailed design of integrated control system architectures suitable for high-performance aircraft of the 1990's.

Discrete event simulation↗

Automatic Generation of Algorithms for the Statistical Analysis of Planetary Nebulae Images

Analyzing data sets collected in experiments or by observations is a Core scientific activity. Typically, experimentd and observational data are &aught with uncertainty, and the analysis is based on a statistical model of the conjectured underlying processes, The large data volumes collected by modern instruments make computer support indispensible for this. Consequently, scientists spend significant amounts of their time with the development and refinement of the data analysis programs. AutoBayes [GF+02, FS03] is a fully automatic synthesis system for generating statistical data analysis programs. Externally, it looks like a compiler: it takes an abstract problem specification and translates it into executable code. Its input is a concise description of a data analysis problem in the form of a statistical model as shown in Figure 1; its output is optimized and fully documented C/C++ code which can be linked dynamically into the Matlab and Octave environments. Internally, however, it is quite different: AutoBayes derives a customized algorithm implementing the given model using a schema-based process, and then further refines and optimizes the algorithm into code. A schema is a parameterized code template with associated semantic constraints which define and restrict the template s applicability. The schema parameters are instantiated in a problem-specific way during synthesis as AutoBayes checks the constraints against the original model or, recursively, against emerging sub-problems. AutoBayes schema library contains problem decomposition operators (which are justified by theorems in a formal logic in the domain of Bayesian networks) as well as machine learning algorithms (e.g., EM, k-Means) and nu- meric optimization methods (e.g., Nelder-Mead simplex, conjugate gradient). AutoBayes augments this schema-based approach by symbolic computation to derive closed-form solutions whenever possible. This is a major advantage over other statistical data analysis systems which use numerical approximations even in cases where closed-form solutions exist. AutoBayes is implemented in Prolog and comprises approximately 75.000 lines of code. In this paper, we take one typical scientific data analysis problem-analyzing planetary nebulae images taken by the Hubble Space Telescope-and show how AutoBayes can be used to automate the implementation of the necessary anal- ysis programs. We initially follow the analysis described by Knuth and Hajian [KHO2] and use AutoBayes to derive code for the published models. We show the details of the code derivation process, including the symbolic computations and automatic integration of library procedures, and compare the results of the automatically generated and manually implemented code. We then go beyond the original analysis and use AutoBayes to derive code for a simple image segmentation procedure based on a mixture model which can be used to automate a manual preproceesing step. Finally, we combine the original approach with the simple segmentation which yields a more detailed analysis. This also demonstrates that AutoBayes makes it easy to combine different aspects of data analysis.

Fischer, Bernd↗

The Role of Formal Experiment Design in Hypersonic Flight System Technology Development

Hypersonic airbreathing engine (scramjet) powered vehicles are being considered to replace conventional rocket-powered launch systems. Effective utilization of scramjet engines requires careful integration with the air vehicle. This integration synergistically combines aerodynamic forces with propulsive cycle functions of the engine. Due to the highly integrated nature of the hypersonic vehicle design problem, the large flight envelope, and the large number of design variables, the use of a statistical design approach in design is effective. Modern Design-of-Experiments (MDOE) has been used throughout the Hyper-X program, for both systems analysis and experimental testing. Application of MDOE fall into four categories: (1) experimental testing; (2) studies of unit phenomena; (3) refining engine design; and (4) full vehicle system optimization. The MDOE process also provides analytical models, which are also used to document lessons learned, supplement low-level design tools, and accelerate future studies. This paper will discuss the design considerations for scramjet-powered vehicles, specifics of MDOE utilized for Hyper-X, and present highlights from the use of these MDOE methods within the Hyper-X Program.

McClinton, Charles R.↗

Control Architecture for Robotic Agent Command and Sensing

Control Architecture for Robotic Agent Command and Sensing (CARACaS) is a recent product of a continuing effort to develop architectures for controlling either a single autonomous robotic vehicle or multiple cooperating but otherwise autonomous robotic vehicles. CARACaS is potentially applicable to diverse robotic systems that could include aircraft, spacecraft, ground vehicles, surface water vessels, and/or underwater vessels. CARACaS incudes an integral combination of three coupled agents: a dynamic planning engine, a behavior engine, and a perception engine. The perception and dynamic planning en - gines are also coupled with a memory in the form of a world model. CARACaS is intended to satisfy the need for two major capabilities essential for proper functioning of an autonomous robotic system: a capability for deterministic reaction to unanticipated occurrences and a capability for re-planning in the face of changing goals, conditions, or resources. The behavior engine incorporates the multi-agent control architecture, called CAMPOUT, described in An Architecture for Controlling Multiple Robots (NPO-30345), NASA Tech Briefs, Vol. 28, No. 11 (November 2004), page 65. CAMPOUT is used to develop behavior-composition and -coordination mechanisms. Real-time process algebra operators are used to compose a behavior network for any given mission scenario. These operators afford a capability for producing a formally correct kernel of behaviors that guarantee predictable performance. By use of a method based on multi-objective decision theory (MODT), recommendations from multiple behaviors are combined to form a set of control actions that represents their consensus. In this approach, all behaviors contribute simultaneously to the control of the robotic system in a cooperative rather than a competitive manner. This approach guarantees a solution that is good enough with respect to resolution of complex, possibly conflicting goals within the constraints of the mission to be accomplished by the vehicle(s).

Huntsberger, Terrance↗

"Built-In" Action/Issues Tracking and Post-Ops Analysis Tool for Realtime Console Operations

Marshall Space Flight Center's (MSFC) Payload Operations Integration Center (POIC) for the International Space Station (ISS) uses a number of formal databases to manage and track flight plan changes, onboard and ground equipment anomalies, and other events. However, individual console positions encounter many action items and/or occurrences that don't fit neatly into the databases, and while console logs are comprehensive, manual or automated searches do not always yield consistent results. The Payload Communications Manager (PAYCOM) team, whose members speak directly with the ISS onboard crew with respect to NASA payload operations, has found a creative way to reformat a mandatory Daily Report to organize action items, standing reminders, significant events, and other comments. While the report keeps others appraised of PAYCOMs activities and issues of the moment, the format makes it easy to capture very brief summaries of the items in a "Roll Off Matrix", including start and stop dates, resolution, and possible applicability to future ops. The matrix provides accountability for all action items, gives direct insight into the issues surrounding various payloads and methods of dealing with them, yields indirect information on PAYCOM priorities and processes, and provides a roadmap that makes it easier to get back to extensive details if needed. This paper describes how the ISS PAYCOM Daily Report and Roll Off Matrix are organized, used, and inter-related to each other and the PAYCOM operations log. While the application is for a manned vehicle, the concepts could apply in a wide spectrum of operational settings.

Scott, David W.↗

Using software security analysis to verify the secure socket layer (SSL) protocol

nal Aeronautics and Space Administration (NASA) have tens of thousands of networked computer systems and applications. Software Security vulnerabilities present risks such as lost or corrupted data, information the3, and unavailability of critical systems. These risks represent potentially enormous costs to NASA. The NASA Code Q research initiative 'Reducing Software Security Risk (RSSR) Trough an Integrated Approach '' offers, among its capabilities, formal verification of software security properties, through the use of model based verification (MBV) to address software security risks. [1,2,3,4,5,6] MBV is a formal approach to software assurance that combines analysis of software, via abstract models, with technology, such as model checkers, that provide automation of the mechanical portions of the analysis process. This paper will discuss: The need for formal analysis to assure software systems with respect to software and why testing alone cannot provide it. The means by which MBV with a Flexible Modeling Framework (FMF) accomplishes the necessary analysis task. An example of FMF style MBV in the verification of properties over the Secure Socket Layer (SSL) communication protocol as a demonstration.

software↗

An Open Computing Infrastructure that Facilitates Integrated Product and Process Development from a Decision-Based Perspective

Computer applications for design have evolved rapidly over the past several decades, and significant payoffs are being achieved by organizations through reductions in design cycle times. These applications are overwhelmed by the requirements imposed during complex, open engineering systems design. Organizations are faced with a number of different methodologies, numerous legacy disciplinary tools, and a very large amount of data. Yet they are also faced with few interdisciplinary tools for design collaboration or methods for achieving the revolutionary product designs required to maintain a competitive advantage in the future. These organizations are looking for a software infrastructure that integrates current corporate design practices with newer simulation and solution techniques. Such an infrastructure must be robust to changes in both corporate needs and enabling technologies. In addition, this infrastructure must be user-friendly, modular and scalable. This need is the motivation for the research described in this dissertation. The research is focused on the development of an open computing infrastructure that facilitates product and process design. In addition, this research explicitly deals with human interactions during design through a model that focuses on the role of a designer as that of decision-maker. The research perspective here is taken from that of design as a discipline with a focus on Decision-Based Design, Theory of Languages, Information Science, and Integration Technology. Given this background, a Model of IPPD is developed and implemented along the lines of a traditional experimental procedure: with the steps of establishing context, formalizing a theory, building an apparatus, conducting an experiment, reviewing results, and providing recommendations. Based on this Model, Design Processes and Specification can be explored in a structured and implementable architecture. An architecture for exploring design called DREAMS (Developing Robust Engineering Analysis Models and Specifications) has been developed which supports the activities of both meta-design and actual design execution. This is accomplished through a systematic process which is comprised of the stages of Formulation, Translation, and Evaluation. During this process, elements from a Design Specification are integrated into Design Processes. In addition, a software infrastructure was developed and is called IMAGE (Intelligent Multidisciplinary Aircraft Generation Environment). This represents a virtual apparatus in the Design Experiment conducted in this research. IMAGE is an innovative architecture because it explicitly supports design-related activities. This is accomplished through a GUI driven and Agent-based implementation of DREAMS. A HSCT design has been adopted from the Framework for Interdisciplinary Design Optimization (FIDO) and is implemented in IMAGE. This problem shows how Design Processes and Specification interact in a design system. In addition, the problem utilizes two different solution models concurrently: optimal and satisfying. The satisfying model allows for more design flexibility and allows a designer to maintain design freedom. As a result of following this experimental procedure, this infrastructure is an open system that it is robust to changes in both corporate needs and computer technologies. The development of this infrastructure leads to a number of significant intellectual contributions: 1) A new approach to implementing IPPD with the aid of a computer; 2) A formal Design Experiment; 3) A combined Process and Specification architecture that is language-based; 4) An infrastructure for exploring design; 5) An integration strategy for implementing computer resources; and 6) A seamless modeling language. The need for these contributions is emphasized by the demand by industry and government agencies for the development of these technologies.

Hale, Mark A.↗

Integrated risk management

The purpose of this report is to first present a basis or foundation for the building of an integrated risk management plan and them to present the plan. The integration referred to is across both the temporal and the hierarchical dimensions. Complexity, consequence, and credibility seem to be driving the need for the consideration of risk. Reduction of personal bias and reproducibility of the decision making process seem to be driving the consideration of a formal risk plan. While risk can be used as either a selection tool or a control tool, this paper concentrates on the selection usage. Risk relies on stated purpose. The tightness of the definition of purpose and success is directly reflected in the definition and control of risk. Much of a risk management plan could be designed by the answers to the questions of why, what, who, when, and where. However, any plan must provide the following information about a threat or risk: likelihood, consequence, predictability, reliability, and reproducibility. While the environment at NASA is seen as warm, but not hot, for the introduction of a risk program, some encouragement is seen if the following problems are addressed: no champion, no commitment of resource, confused definitions, lack of direction and focus, a hard sell, NASA culture, many choices of assessment methods, and cost. The plan is designed to follow the normal method of doing work and is structured to follow either the work break down structure or a functional structure very well. The parts of the plan include: defining purpose and success, initial threat assessment, initial risk assessment, reconciling threats and parameters, putting part of the information down and factoring the information back into the decision process as it comes back up, and developing inferences. Two major suggestions are presented. One is to build an office of risk management to be used as a resource by managers in doing the risk process. Another is to form a pilot program to try out the details in the plan and modify the method where needed.

Hunsucker, J. L.↗