Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Efficient Extraction Of Building Elevation Attributes For Flood Risk Management Using Airborne LiDAR Data

In this paper, we address the need for extracting two key building elevation attributes—Lowest Adjacent Grade (LAG) and Highest Adjacent Grade (HAG)—which are crucial for effective flood risk management. Conventional methods, involving onsite surveying or the use of optical imagery-derived building footprints combined with Digital Elevation Models (DEMs), often face misalignment and time discrepancy issues due to varied remote sensing sources. We introduce a new, scalable method that exclusively relies on airborne LiDAR data to overcome these challenges. Our approach employs an object-based ground filtering technique, and the results were evaluated using two different DEMs and building footprint sets. The findings demonstrate that our single-source method, utilizing only airborne LiDAR data, significantly improves the accuracy of LAG and HAG calculations compared to traditional methods that use hand-digitized building footprints. The proposed approach offers a solution for comprehensive flood risk management endeavors.

Song, Hunsoo↗

Cybersecurity Supply Chain Risk Management: Forge Institute Presentation

In this talk, INL will discuss how to develop a cyber supply chain risk management program, to include assessment of vendor risk and applying appropriate mitigations. INL will discuss key risk factors and the challenges of securing supply chain in complex and dynamic vendor environments. Finally, INL will share example language that can be adopted in RFPs and procurement contracts to promote supply chain security.

battery energy storage system↗

Integrating Qualitative and Quantitative Aspects of Risk Management

This topical report summarizes the integration of qualitative and quantitative aspects of the risk management workflow for the Southwest Regional Partnership on Carbon Sequestration (SWP) Phase III Demonstration Project, located near the community of Farnsworth in northernmost Texas. Detail on some aspects of this subject has been previously provided in internal project reports on qualitative risk assessment processes, in a published paper summarizing quantitative risk modeling, and in many other published papers on specific risk modeling efforts. These prior documents are cited but the details are not repeated here. The report documents work undertaken for Task 7.4.1 of U.S. Department of Energy award number DE- FC26-05NT42591.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Solar PV, Wind Generation, and Load Forecasting Dataset for ERCOT 2018: Performance-Based Energy Resource Feedback, Optimization, and Risk Management (P.E.R.F.O.R.M.)

This report describes the Advanced Research Projects Agency-Energy Performance-Based Energy Resource Feedback, Optimization, and Risk Management (PERFORM) Electric Reliability Council of Texas (ERCOT) dataset consisting of load, solar, and wind deterministic and probabilistic forecasts at three timescales. This dataset consists of 1 year of time-coincident load, wind, and solar actuals and probabilistic forecasts for a region similar to ERCOT. All the data are stored in Hierarchical Data Format 5 (HDF5) files and have been uploaded to an Amazon Web Services repository. The ERCOT data set has 2 years (2017, 2018) of actuals and 1 year (2018) of probabilistic forecasts. These data are provided at various spatial (i.e., site-level, zone-level, and system-level) and temporal scales (i.e., day-ahead, intraday, and intra-hour). Specifically, data are provided for 125 existing wind sites, 22 existing solar sites, 139 proposed wind sites, and 204 proposed solar sites.

14 SOLAR ENERGY↗

Integrated Issues and Risk Management: A Theoretical Framework Overview

The contractor requirements document for DOE O 226.1B, Implementation of Department of Energy Oversight Policy, requires DOE/NNSA contractors to establish an assurance system that includes, among other things, “Rigorous, risk-informed, and credible self-assessment and feedback and improvement activities. Assessment programs must be risk-informed, formally described and documented, and appropriately cover potentially high consequence activities” and “Contains an issues management process that is capable of categorizing the significance of findings based on risk and priority and other appropriate factors….” However, the term “risk-informed” is not defined in this or any other DOE order, and no formal guidance on how to integrate the two concepts currently exists. The Risk Management Guide for Defense Programs released by NA-18, Office of Systems Engineering and Integration (SE&I), states it is “a framework and general guidance to program office personnel on the effective management of program risks and issues”, however it then defines issues as “events with 100% likelihood of affecting program objectives” and states “unless specified otherwise, the term “risk” will also serve to represent issues for the remainder of this plan,” severally limiting its ability to provide adequate guidance on this topic. Outside of DOE scope, the U.S. Nuclear Regulatory Commission (U.S. NRC) imposes similar requirements. ASME NQA-1-2015 Requirement 16 states “Conditions adverse to quality shall be identified promptly and corrected as soon as practicable. In the case of a significant condition adverse to quality, the cause of the condition shall be determined, and corrective action taken to preclude recurrence. The identification, cause, and corrective action for significant conditions adverse to quality shall be documented and reported to appropriate levels of management. Completion of corrective actions shall be verified”. The purpose of this document is to provide a best-in-class framework for an integrated risk and issues management process. This process would provide a robust feedback loop between risk management and issues management to: Enhance risk identification and characterization, use risk handling principles to improve corrective action planning, and ensure regulatory compliance.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

The enduring role of contracts for difference in risk management and market creation for renewables

Governments procure renewables through a variety of mechanisms. Contracts for difference (CfDs) have been used for more than 50% of the global offshore wind supply. The payments awarded through CfDs are sometimes labelled subsidies, suggesting that they support uneconomic activity. Here, in this study, we argue that the primary role of CfDs is rather risk management by creating a market for electricity supply at stable long-term prices. Similar to its use in other sectors of the economy, this contract type transforms a variable to a fixed price to reallocate volatility risks. Such long-term contracts are often necessary for renewables financing due to limited hedging options in existing markets. Our perspective could imply a shift in perception towards CfDs as a fundamental and lasting market feature. We hope to stimulate a timely discussion about the impact of greater CfD diffusion on electricity market mechanisms, risk allocation and the potential for combining fragmented streams of energy finance, market and policy research.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

A Cyber-Resilience Risk Management Architecture for Distributed Wind

Distributed wind is an electric energy resource segment with strong potential to be deployed in many applications, but special consideration of resilience and cybersecurity is needed to address the unique conditions associated with distributed wind. Distributed wind is a strong candidate to help meet renewable energy and carbon-free energy goals. However, care must be taken as more systems are installed to ensure that the systems are reliable, resilient, and secure. The physical and communications requirements for distributed wind mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity risk management for distributed wind systems specifically. This research develops an architecture for the consideration of cyber risks associated with distributed wind systems. The architecture takes into account the configurations, challenges, and standards for distributed wind to create a risk-focused perspective that considers of threats, vulnerabilities, and consequences, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). We discuss common distributed wind architectures and how they are interconnected to larger power systems. Because cybersecurity cannot exist independently, the cyber-resilience architecture must consider the system holistically. Finally, we discuss the implementation of a risk assessment process that uses the cyber-resilience framework to address challenges specific to distributed wind.

17 WIND ENERGY↗

Guide to the Distributed Energy Resource Risk Management Framework

The emergence of distributed energy resources (DERs) has transformed the electric power sector and will likely have even more profound impacts on the future evolution of the United States energy sector as it modernizes and becomes more reliant upon complex informatics programming and systems to ensure that our power grid remains safe from malicious interference. To mitigate risks associated with the increased and diversified use of DERs, the Distributed Energy Resource Cybersecurity Framework (DER-CF) was developed in 2019. The National Renewable Energy Laboratory extended the scope of the DER-CF to include the RMF. To address the challenges faced by federal energy managers and energy system stakeholders in applying the RMF to DER systems, the Distributed Energy Resource Risk Manager (DER-RM) is a six-step process to proactively manage cybersecurity risk in a methodical manner. The DER-RM is independent of the DER-CF's existing assessment, allowing users to focus specifically on the RMF steps. The tools are targeted to different processes - DER-CF enables organizations to perform self-assessments to improve their cybersecurity posture, while DER-RM assists organizations in achieving compliance with specific requirements. This document provides an overview of the DER-RM. The RMF process outlined in this report serves as a guide to diagnose information and operational system threats, gather required materials to comply with industry standards, and document plans for achieving Authority to Operate. Using the DER-RM, federal agencies and other organizations can easily and intuitively follow the RMF process, manage the risks to their grid-edge infrastructure through the integration of their on-site DERs, and comply with appropriate requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Stochastic Distribution Control Theory-Its Potential Application in Risk Management in Financial Systems

Stochastic Distribution Control (SDC) theory [1], originated by the author in 1996, aims at developing modeling and control strategies for dynamic and non-Gaussian stochastic systems by controlling the shape of the probability density functions of some concerned variables and parameters in stochastic systems. It generalizes the capability of standard stochastic differential equations and can therefore be applied to generic non-Gaussian systems. Since it was established in 1996, it has found a wide spectrum of applications in non-Gaussian stochastic system control, data mining, filtering and optimization for uncertain systems. In this short opinion article, discussions will be made on potential applications of SDC theory to financial systems in terms of risk analysis and management.

97 MATHEMATICS AND COMPUTING↗

Hydropower Cybersecurity Risk Management and Valuation

Advancements to DOE WPTO funded Hydropower Cybersecurity Value-at-Risk Framework application allows stakeholder to translate risk-based assessments to quantitative scores allowing to better decision making for cybersecurity investments.

13 HYDRO ENERGY↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session Two

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. A comprehensive exploration of BESS cybersecurity supply chain risks, systematic vendor risk assessment through the BESS Procurement Guide, and practical application of the INL SCRM Chatbot for enhanced supply chain resilience. This is Session 2 of 3. (Full Version)

25 - ENERGY STORAGE↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3. (Full Version)

25 - ENERGY STORAGE↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One - Abridged

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3.

25 - ENERGY STORAGE↗

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE↗