Cost-benefit based assurance planning
We have extended an existing risk management framework with a refined cost-benefit model. Benefits are measured in terms of reduction of risk.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
We have extended an existing risk management framework with a refined cost-benefit model. Benefits are measured in terms of reduction of risk.
This presentation for the MIRACL Industry Advisory Board summarizes the cybersecurity research for distributed wind that was performed during the project. Highlights include an overview of the distributed wind reference architecture, descriptions of the unique needs and challenges for securing distributed wind, the cyber risk management framework that was developed for this project, and key takeaways for various stakeholders.
The objective is to use cost-benefit analyses to identify, for a given project, optimal sets of software assurance activities. Towards this end we have incorporated cost-benefit calculations into a risk management framework.
This presentation discusses risk management for ocean-based technologies by stepping through elements of the National Laboratory of the Rockies' 2024 Marine Energy Technology Development Risk Management Framework.
After several decades of human spaceflight, the community of space-faring nations has accumulated a diverse and sometimes harrowing history of toxicological events that have plagued human space endeavors almost from the very beginning. Lessons have been learned in ground-based test beds and others were discovered the hard way - when human lives were at stake in space. From such lessons one can build a risk-management framework for toxicological events to minimize the probability of a harmful exposure, while recognizing that we cannot foresee all events. Space toxicologists have learned that relatively harmless compounds can be converted by air revitalization systems into compounds that cause serious harm to the crew. Our toxic risk management strategy now includes an assessment of the fate of any compound that might be released into the atmosphere. Propellants are highly toxic compounds, yet we have not always been able to thoroughly isolate the crew from exposure to these toxicants. Leakage of fluids from systems has resulted in hazardous conditions at times, and the behavior of such compounds inside a spacecraft has taught us how to manage potentially harmful escapes should they occur. Potential combustion events are an ever-present threat to the wellbeing of the crew. Such events have been sufficiently common that we have learned that one cannot judge the health threat of a given fire by the magnitude of the event. Management of such risks demands monitoring of combustion products. In the category of unpredictable toxic events, if one assumes that fires are predictable, we can place experience with toxic microbial metabolites, upsets during repair operations, and discharges from filters that have accumulated a substantial load of pollutants in their absorption beds. Management of such events requires a broad-spectrum, real-time analytical capability to discern the identity and concentrations of pollutants if they enter the atmosphere. Adverse events are an integral part of any human activity, and the spacefaring community must learn as much as possible from mistakes and near misses.
As the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multiorganizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other's, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission's leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA's requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.
Environmental problems and production losses associated with irrigated agriculture, such as salinity, degradation of receiving waters, such as rivers, and deep percolation of saline water to aquifers, highlight water-quality concerns that require a paradigm shift in resource-management policy. New tools are needed to assist environmental managers in developing sustainable solutions to these problems, given the nonpoint source nature of salt loads to surface water and groundwater from irrigated agriculture. Equity issues arise in distributing responsibility and costs to the generators of this source of pollution. This paper describes an alternative approach to salt regulation and control using the concept of “Real-Time Water Quality management”. The approach relies on a continually updateable WARMF (Watershed Analysis Risk Management Framework) forecasting model to provide daily estimates of salt load assimilative capacity in the San Joaquin River and assessments of compliance with salinity concentration objectives at key monitoring sites on the river. The results of the study showed that the policy combination of well-crafted river salinity objectives by the regulator and the application of an easy-to use and maintain decision support tool by stakeholders have succeeded in minimizing water quality (salinity) exceedances over a 20-year study period.
This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.
This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the ARC-100, a sodium-cooled fast reactor (SFR) being developed by ARC Clean Technology, Inc (ARC). The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, used fuel assembly wash station, cesium trap, sodium cold trap, noble gas decay tanks, used fuel dry storage facility, damaged fuel storage facility, and radioactive waste building. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.
As the electricity generated by variable resources grows, system operators and variable resources have to manage challenging imbalances between forward and real-time markets. The Flexibility Auction is a novel approach for managing imbalances as it will allow resources with imbalance risk to hedge their production by buying flexibility options. The flexibility options are offered by grid-connected resources that can provide physical flexibility. This presentation will focus on the design of the Flexibility Auction, its properties, and how it can complement system-level services such as CAISO's proposed imbalance reserves. The presentation will include simple examples to illustrate the impact of the Flexibility Auction on the market participants and the system's imbalance risk.
The National Aeronautics and Space Administration (NASA) defines risk management as an integrated framework, combining risk-informed decision making and continuous risk management to foster forward-thinking and decision making from an integrated risk perspective. Therefore, decision makers must have access to risks outside of their own project to gain the knowledge that provides the integrated risk perspective. Through the Goddard Space Flight Center (GSFC) Flight Projects Directorate (FPD) Business Change Initiative (BCI), risks were integrated into one repository to facilitate access to risk data between projects. With the centralized repository, communications between the FPD, project managers, and risk managers improved and GSFC created the cross-cutting risk framework (CCRF) team. The creation of the consolidated risk repository, in parallel with the initiation of monthly FPD risk managers and risk governance board meetings, are now providing a complete risk management picture spanning the entire directorate. This paper will describe the challenges, methodologies, tools, and techniques used to develop the CCRF, and the lessons learned as the team collectively worked to identify risks that FPD programs projects had in common, both past and present.
Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.
Energy management information systems (EMIS) are a broad and rapidly evolving family of tools that monitor, analyze, and control building energy use and system performance. Critical systems are often integrated with or operate on the same networks as EMIS scope systems, necessitating stable, continuous, and secure communication. When connecting EMIS to building automation and utility control systems, there are also many physical assets that could cause harm to the building and its occupants if a malicious act or human error were introduced. It is imperative to ensure all EMIS scope systems are connected securely to the EMIS and do not open vulnerable pathways to other facility networks and operations. The Federal Energy Management Program (FEMP) promotes best practices for impactful utilization of EMIS at federal facilities. This best practice document is part of a series of fact sheets created to help accelerate the market adoption and use of EMIS in the federal sector. It provides an overview of required EMIS cybersecurity standards for compliance and authority to operate along with additional recommendations.
Net load imbalances due to imperfect day-ahead forecasts can cause variability in real-time electricity prices and higher system operations costs. We propose a novel market product called Flexibility Options that allow participants to hedge uncertainty by buying flexibility from flexible resources. Simulations show that flexibility options can reduce total system operating costs by up to 15% and can reduce variability in market participant revenues. To better quantify the flexibility that DER aggregators can provide, we develop DER flexibility scores that account for asset flexibility and uncertainty from occupant behavior and weather. Preliminary results show that realistic sets of DERs have significant variability in flexibility and uncertainty metrics.
ePORT (electronic Project Online Risk Tool) provides a systematic approach to using an electronic database program to manage a program/project risk management processes. This presentation will briefly cover the standard risk management procedures, then thoroughly cover NASA's Risk Management tool called ePORT. This electronic Project Online Risk Tool (ePORT) is a web-based risk management program that provides a common framework to capture and manage risks, independent of a programs/projects size and budget. It is used to thoroughly cover the risk management paradigm providing standardized evaluation criterion for common management reporting, ePORT improves Product Line, Center and Corporate Management insight, simplifies program/project manager reporting, and maintains an archive of data for historical reference.
The new Federal Aviation Administration (FAA) Small Unmanned Aircraft rule (Part 107) marks the first national regulations for commercial operation of small unmanned aircraft systems (sUAS) under 55 pounds within the National Airspace System (NAS). Although sUAS flights may not be performed beyond visual line-of-sight or over non- participant structures and people, safety of sUAS operations must still be maintained and tracked at all times. Moreover, future safety-critical operation of sUAS (e.g., for package delivery) are already being conceived and tested. NASA's Unmanned Aircraft System Trac Management (UTM) concept aims to facilitate the safe use of low-altitude airspace for sUAS operations. This paper introduces the UTM Risk Assessment Framework (URAF) which was developed to provide real-time safety evaluation and tracking capability within the UTM concept. The URAF uses Bayesian Belief Networks (BBNs) to propagate off -nominal condition probabilities based on real-time component failure indicators. This information is then used to assess the risk to people on the ground by calculating the potential impact area and the effects of the impact. The visual representation of the expected area of impact and the nominal risk level can assist operators and controllers with dynamic trajectory planning and execution. The URAF was applied to a case study to illustrate the concept.
As organizations increasingly automate their core missions and essential functions to address business risks and enhance efficiency, process automation becomes pivotal. This shift, involving minimal or no manual intervention, significantly impacts an organization's cyber-risk landscape. While automation drives efficiencies, it also introduces new cyber risks if not properly managed. Cyber-Informed Engineering (CIE) provides a proactive framework for managing these digital risks, enhancing cyber-resilience in process automation. This document supports organizations in applying CIE principles to mitigate the cyber risks associated with automation. The outlined approach can be independently implemented to improve any organization’s cyber-resilience, ensuring that the advantages of automation do not result in unaddressed or unmanaged digital risks. It serves as a starting point, offering considerations for integrating CIE principles and practices into organizational processes. CIE is presented as an iterative process, fostering continuous improvement and reinforcing the engineering and operational cultures to manage digital risks effectively. The document is structured as follows: Section 1 provides background on CIE and process automation, and their integration. Section 2 explores the twelve CIE principles in the context of process automation, highlighting key questions, engineering considerations, and implications for digital risk management. Section 3 synthesizes the findings and offers recommendations to advance resilience by design.
This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.