Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk-Informed Approach”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Regulatory Considerations for Domestic Reprocessing Facility Physical Security

U.S. advanced non-light-water reactor vendors may pursue collocated on-site reprocessing activities. Therefore, these facilities are likely to possess formula quantities, or Category I quantities, of special nuclear material (SNM) during normal operations. The U.S. Nuclear Regulatory Commission (U.S. NRC) has yet to formally establish a regulatory framework for commercial reprocessing. While Category I requirements would explicitly not apply in this circumstance under current regulatory requirements, regulatory certainty does not exist. A novel framework should be developed to ensure public health and safety while also risk-informing the physical security requirements. This report reviews the relevant background of related rulemaking activities and proposes risk-informed physical protection requirements to satisfy these objectives. Insights from NRC security-related rulemaking activities provide a substantial technical basis to approach potential establishment of physical security requirements for reprocessing facilities. If a licensee can provide justification that the material satisfies a sufficient self-protecting radiation dose threshold, the material may not be subject to theft or diversion requirements and only potential sabotage requirements would apply. Furthermore, if the material can be justified to be moderately dilute, a set of risk-informed requirements could provide adequate protection of public health and safety. A revised performance objective for prevention of theft of moderately dilute Category I SNM may be detection to allow prompt recovery by a local law enforcement agency. However, a significant caveat to the proposed categorization scheme is the unknown integration of radiological sabotage with requirements for the protection against theft. Future licensees should consult with the NRC regarding treatment of this regulatory topic. Additionally, the self-protecting radiation dose threshold (either the existing or a proposed future threshold) would need to be considered. An integrated approach may apply graded potential requirements for protection against the design basis threat of radiological sabotage currently applicable to commercial nuclear power plants and Category I SNM facilities defined within 10 CFR 73.1(a).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Altair Lunar Lander Development Status: Enabling Human Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a minimum functionality approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicles safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to begin Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. A blended NASA-industry team will continue to refine the lander configuration and mature the vehicle design over the next few years. This paper will update the international community on the status of the Altair Project as it addresses the challenges of project formulation, including optimizing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

Altair Lunar Lander Development Status: Enabling Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a "minimum functionality" approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicle's safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to began Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. NASA intends to continue to seek industry involvement in project formulation activities. This paper will update the international coimmunity on the status of the Altair Project as it addresses the challenges of project formulation, including optinuzing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer Based Hydrogen Production Facility

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at NREL's Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer-Based Hydrogen Production Facility: Preprint

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at the National Renewable Energy Laboratory (NREL)'s Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Developing a Process for Collaboration-Based Siting of a Federal Consolidated Interim Storage Facility in the United States: Learning from Communities Living with Legacy Waste

In June of 2023, the U.S. Department of Energy (DOE), Office of Nuclear Energy (NE) announced the selection of its Collaboration-Based Siting (CBS) Consortia, a group of 12 awardees, including the Consortium for Risk Evaluation with Stakeholder Participation (CRESP) (led by Vanderbilt University) to assist DOE-NE with the development of its process for siting a federal consolidated interim storage facility (FCISF) for spent nuclear fuel (SNF) storage. At this time, DOE NE is not soliciting interested host communities, rather the CBS Consortia are tasked with in-depth engagement, mutual learning, and capacity building to provide DOE NE with feedback on the CBS process. CRESP’s objective is to engage communities in two regions (the Pacific Northwest and the Southeast) with sites currently storing defense- and research-related SNF to foster learning concerning the best and worst practices in community participation in risk-informed decision making. This includes learning from existing structures for public input in radioactive waste management decision making [e.g. citizen advisory boards (CABs)] and other local parties about how to build and sustain trust among the parties. CRESP has been working to engage stakeholders and Tribes surrounding two DOE sites historically differing in receptiveness to engaging with DOE and trusting in DOE to accomplish its missions. CRESP’s approach to date has consisted of (1) engaging voluntarily members and former members of the DOE Office of Environmental Management’s CABs to develop a mutual understanding of their perspectives, values, and experiences related to risk and participatory decision making; (2) engaging members of those communities that would likely be part of any radioactive waste management discussions and who may provide valuable feedback for the development of the CBS process; and in the longer term, (3) engaging communities to foster knowledge sharing on understanding and definitions of risk and how risk is factored into community decision making. Our emphasis is to identify opportunities for improving risk communication frameworks, strategies, and decision making. The selection of a future FCISF site is likely to result in the creation of a structure similar to a CAB composed of members of the local community. We anticipate that these insights can help DOE NE learn from existing participatory risk communication structures in place at sites storing defenseor research-related SNF to understand best practices for fostering enduring and participatory relationships with future CABs. Within this paper, we (1) describe CRESP’s overall approach to assisting DOE NE with maturing the CBS process; (2) present a summary of preliminary phase 1 project results, including the development of a body of knowledge (describing available resources to support community engagement, risk communica tion, and participatory decision making) and community ecosystem information (leveraging demographic, social, economic, and environmental attribute mapping and advanced sentiment analysis of social media data); and (3) based on these results, provide observations for future research opportunities to support the development of CBS processes for radioactive waste management facilities, generally.

collaboration-based siting↗

Promoting a Culture of Tailoring for Systems Engineering Policy Expectations

NASA's Marshall Space Flight Center (MSFC) has developed an integrated systems engineering approach to promote a culture of tailoring for program and project policy requirements. MSFC's culture encourages and supports tailoring, with an emphasis on risk-based decision making, for enhanced affordability and efficiency. MSFC's policy structure integrates the various Agency requirements into a single, streamlined implementation approach which serves as a "one-stop-shop" for our programs and projects to follow. The engineers gain an enhanced understanding of policy and technical expectations, as well as lesson's learned from MSFC's history of spaceflight and science missions, to enable them to make appropriate, risk-based tailoring recommendations. The tailoring approach utilizes a standard methodology to classify projects into predefined levels using selected mission and programmatic scaling factors related to risk tolerance. Policy requirements are then selectively applied and tailored, with appropriate rationale, and approved by the governing authorities, to support risk-informed decisions to achieve the desired cost and schedule efficiencies. The policy is further augmented by implementation tools and lifecycle planning aids which help promote and support the cultural shift toward more tailoring. The MSFC Customization Tool is an integrated spreadsheet that ties together everything that projects need to understand, navigate, and tailor the policy. It helps them classify their project, understand the intent of the requirements, determine their tailoring approach, and document the necessary governance approvals. It also helps them plan for and conduct technical reviews throughout the lifecycle. Policy tailoring is thus established as a normal part of project execution, with the tools provided to facilitate and enable the tailoring process. MSFC's approach to changing the culture emphasizes risk-based tailoring of policy to achieve increased flexibility, efficiency, and effectiveness in project execution, while maintaining appropriate rigor to ensure mission success.

Blankenship, Van A.↗

Templates for Risk Informed Assurance with Curvature Embeddings (TRACE)

We investigate recovery of geometric structure from networks embedded in manifolds with spatially varying curvature, extending the constant-curvature framework of Lubold et al. (2023). Our work supports cascade risk assessment in critical infrastructure through the Templates for Risk-informed Assurance with Curvature Embeddings (TRACE) framework. Simulations on a bi-modal Gaussian surface show that constant-curvature methods yield weighted averages shaped by clique patterns, while hierarchical clustering identifies distinct regimes. Localized estimation, however, reveals boundary contamination in transitional regions. To address heterogeneity, we develop distance metrics for graphs with edge and node features, proving their metric validity, and validate them via deterministic graph generation from canonical tilings. We further propose a diffusion-based anomaly detection approach that treats networks as glued manifolds, using curvature discontinuities to detect structural anomalies. Employing the carré-du-champ operator and scalar curvature, we achieve robust anomaly discrimination, demonstrated on the Singapore Water Treatment (SWaT) dataset with joint network-traffic and sensor features. Integration with TRACE reveals how curvature shapes cascade dynamics: positive curvature impedes, while negative curvature accelerates propagation. This geometric perspective provides interpretable risk metrics and visualization tools for critical infrastructure managers. While full validation remains ongoing, our contributions establish a rigorous foundation for geometric analysis of network resilience and cascade vulnerability.

97 MATHEMATICS AND COMPUTING↗

An Integrated Approach to Life Cycle Analysis

Life Cycle Analysis (LCA) is the evaluation of the impacts that design decisions have on a system and provides a framework for identifying and evaluating design benefits and burdens associated with the life cycles of space transportation systems from a "cradle-to-grave" approach. Sometimes called life cycle assessment, life cycle approach, or "cradle to grave analysis", it represents a rapidly emerging family of tools and techniques designed to be a decision support methodology and aid in the development of sustainable systems. The implementation of a Life Cycle Analysis can vary and may take many forms; from global system-level uncertainty-centered analysis to the assessment of individualized discriminatory metrics. This paper will focus on a proven LCA methodology developed by the Systems Analysis and Concepts Directorate (SACD) at NASA Langley Research Center to quantify and assess key LCA discriminatory metrics, in particular affordability, reliability, maintainability, and operability. This paper will address issues inherent in Life Cycle Analysis including direct impacts, such as system development cost and crew safety, as well as indirect impacts, which often take the form of coupled metrics (i.e., the cost of system unreliability). Since LCA deals with the analysis of space vehicle system conceptual designs, it is imperative to stress that the goal of LCA is not to arrive at the answer but, rather, to provide important inputs to a broader strategic planning process, allowing the managers to make risk-informed decisions, and increase the likelihood of meeting mission success criteria.

Chytka, T. M.↗

Risk assessment of wellbore leakage during underground hydrogen storage

The expansion of renewable energy sources would require large-scale energy storage options to overcome the intermittent nature of these sources. Underground hydrogen storage (UHS) in depleted hydrocarbon reservoirs offers a scalable and practical energy storage solution. These reservoirs are chosen for their availability and large capacity, but the unique properties of hydrogen raise concerns about potential leakage pathways, particularly through wellbores. In this study, we develop and apply, for the first time, reduced-order models (ROMs) specifically designed for efficient leakage risk prediction in UHS systems operating in depleted hydrocarbon reservoirs. Using 3,000 high-fidelity simulation scenarios, we examine the influence of 11 key parameters, including reservoir and aquifer depths, wellbore permeability and porosity, initial saturations of water, oil and gas fractions (hydrogen, light, intermediate, and heavy hydrocarbons), reservoir pressure multiplier, and the aquifer-to-reservoir volume ratio, to simulate leakage behavior over a 1,000-year timescale. We train ROMs using a two-step classification-regression approach, achieving R 2 values exceeding 99 % across all targets. These ROMs effectively capture the leakage evolution and identify critical controls of leakage, guiding the design of mitigation strategies. Results indicate that gas leakage occurs in about 27 % of scenarios as early as five years post-operation, reaching volumes of up to 106 ft3. Oil leakage is less frequent (~17 %) and typically begins decades later. Our findings also show that hydrogen often migrates first, owing to its smaller molecular size and higher buoyancy, followed by heavier hydrocarbons. Over time, these heavier components contribute significantly to the total leaked volume, reinforcing the need for targeted monitoring and remediation strategies. Our analysis highlights that deeper storage reservoirs, shallower aquifers, and low-permeability wellbores significantly reduce leakage risks. In conclusion, this work offers a robust framework for risk-informed UHS deployment, supporting energy security through reliable large-scale hydrogen storage while safeguarding environmental integrity.

08 HYDROGEN↗

ARCADE Analysis Methods & Validation Pathway

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) provides an automated analysis system which supports risk-informed performance based (RIPB) evaluations of nuclear control systems. Every possible cyber threat which could lead to consequence is identified by simulating the unsafe control action sequences which transform digital harm into physical harm. Eliminating the simulation of complex digital cyber attack chains cuts out unnecessary computational overhead and focuses directly on the physics of cyber-physical attacks. This focus enables designers to make informed decisions which can entirely eliminate categories of cyber threats against advanced reactors through the physical nature of the plant design. This narrowing of cyber threat against nuclear power plants through the physics of the system is intended to make any remaining threat management and cost efficient. This is the goal of the Tiered Cyber Analysis (TCA) outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors. ARCADE has been custom developed to meet the demands of the rigorous analysis required in Tier 1 of the TCA, which forms the foundation of the TCA process. Currently, ARCADE is still under development, but has made significant leaps in capability. A pilot analysis on the opensource Asherah simulator was performed which demonstrated key functionality goals. The next stage of ARCADE development involves improvements to the applications which support the analysis system, and enabling the analysis system to utilize the full suite of unsafe control action simulations. Since the analysis method’s core functions are complete, validation of the analysis method will be started concurrent to the next development stages. The automated analysis ARCADE will provide can radically change the cybersecurity design process for advanced reactors, reducing the cost of security implementation while enhancing cyber resilience. The pathway for ARCADE’s development to this goal has become much clearer. The majority of technical hurdles have been cleared, and the remaining development needs have been solidified. ARCADE is now capable of assisting the advanced reactor design process and directly support advanced reactor industry RIPB practices.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Achieving a Risk-Informed Decision-Making Environment at NASA: The Emphasis of NASA's Risk Management Policy

This slide presentation reviews the evolution of risk management (RM) at NASA. The aim of the RM approach at NASA is to promote an approach that is heuristic, proactive, and coherent across all of NASA. Risk Informed Decision Making (RIDM) is a decision making process that uses a diverse set of performance measures along with other considerations within a deliberative process to inform decision making. RIDM is invoked for key decisions such as architecture and design decisions, make-buy decisions, and budget reallocation. The RIDM process and how it relates to the continuous Risk Management (CRM) process is reviewed.

Dezfuli, Homayoon↗

A Proactive and Top-Down Approach to Managing Risk at NASA

Our ultimate goal is to manage risk in a holistic and coherent fashion across the Agency: a) The RIDM process is intended to risk-inform direction-setting decisions. c) The CRM process is intended to manage risk associated with the implementation of baseline performance requirements. Currently we are working on: a) Enhancements to the CRM process. b) Better integration of the RIDM and CRM processes. c) Better integration of institutional risk considerations into RM framework.

Dezfuli, Homayoon↗

NASA Accident Precursor Analysis Handbook, Version 1.0

Catastrophic accidents are usually preceded by precursory events that, although observable, are not recognized as harbingers of a tragedy until after the fact. In the nuclear industry, the Three Mile Island accident was preceded by at least two events portending the potential for severe consequences from an underappreciated causal mechanism. Anomalies whose failure mechanisms were integral to the losses of Space Transportation Systems (STS) Challenger and Columbia had been occurring within the STS fleet prior to those accidents. Both the Rogers Commission Report and the Columbia Accident Investigation Board report found that processes in place at the time did not respond to the prior anomalies in a way that shed light on their true risk implications. This includes the concern that, in the words of the NASA Aerospace Safety Advisory Panel (ASAP), "no process addresses the need to update a hazard analysis when anomalies occur" At a broader level, the ASAP noted in 2007 that NASA "could better gauge the likelihood of losses by developing leading indicators, rather than continue to depend on lagging indicators". These observations suggest a need to revalidate prior assumptions and conclusions of existing safety (and reliability) analyses, as well as to consider the potential for previously unrecognized accident scenarios, when unexpected or otherwise undesired behaviors of the system are observed. This need is also discussed in NASA's system safety handbook, which advocates a view of safety assurance as driving a program to take steps that are necessary to establish and maintain a valid and credible argument for the safety of its missions. It is the premise of this handbook that making cases for safety more experience-based allows NASA to be better informed about the safety performance of its systems, and will ultimately help it to manage safety in a more effective manner. The APA process described in this handbook provides a systematic means of analyzing candidate accident precursors by evaluating anomaly occurrences for their system safety implications and, through both analytical and deliberative methods used to project to other circumstances, identifying those that portend more serious consequences to come if effective corrective action is not taken. APA builds upon existing safety analysis processes currently in practice within NASA, leveraging their results to provide an improved understanding of overall system risk. As such, APA represents an important dimension of safety evaluation; as operational experience is acquired, precursor information is generated such that it can be fed back into system safety analyses to risk-inform safety improvements. Importantly, APA utilizes anomaly data to predict risk whereas standard reliability and PRA approaches utilize failure data which often is limited and rare.

Groen, Frank↗

Sustaining a Mature Risk Management Process: Ensuring the International Space Station for a Vibrant Future

The International Space Station (ISS) risk management methodology is an example of a mature and sustainable process. Risk management is a systematic approach used to proactively identify, analyze, plan, track, control, communicate, and document risks to help management make risk-informed decisions that increase the likelihood of achieving program objectives. The ISS has been operating in space for over 14 years and permanently crewed for over 12 years. It is the longest surviving habitable vehicle in low Earth orbit history. Without a mature and proven risk management plan, it would be increasingly difficult to achieve mission success throughout the life of the ISS Program. A successful risk management process must be able to adapt to a dynamic program. As ISS program-level decision processes have evolved, so too has the ISS risk management process continued to innovate, improve, and adapt. Constant adaptation of risk management tools and an ever-improving process is essential to the continued success of the ISS Program. Above all, sustained support from program management is vital to risk management continued effectiveness. Risk management is valued and stressed as an important process by the ISS Program.

Raftery, Michael↗

Considering Risk and Resilience in Decision-Making

This paper examines the concepts of decision-making, risk analysis, uncertainty and resilience analysis. The relation between risk, vulnerability, and resilience is analyzed. The paper describes how complexity, uncertainty, and ambiguity are the most critical factors in the definition of the approach and criteria for decision-making. Uncertainty in its various forms is what limits our ability to offer definitive answers to questions about the outcomes of alternatives in a decision-making process. It is shown that, although resilience-informed decision-making would seem fundamentally different from risk-informed decision-making, this is not the case as resilience-analysis can be easily incorporated within existing analytic-deliberative decision-making frameworks.

Torres-Pomales, Wilfredo↗

Comparative Analysis of Static and Dynamic Probabilistic Risk Assessment

Implementation of risk-informed design allows the design team to thoroughly explore the risks of a system while iterating the operations concept, design, and requirements until the system meets mission objects and is achievable within constraints. To arrive at a space system design that is likely to meet all constraints placed upon mass, cost, performance and risk, the system requirements must be understood and traded against each other as early as the conceptual design phase. Depending on the project phase and the goals of the risk analysis, various PRA methodologies could be used to produce quantitative risk estimates to enable such a process. In order to better understand the applicability, advantages, and limitations of various PRA methodologies, a comparative analysis of three bottom-up, component-based PRA approaches was performed. The three methods examined are a traditional static fault tree, a fault tree hybrid, and a dynamic Monte Carlo simulation. Each approach was used to assess a generic reaction control system (RCS) thruster pod and mission. The methods are assessed in terms of the process of modeling a system, the actionable information produced for the design team, and the overall fidelity of the quantitative risk evaluation generated. The paper also discusses the applicability of each methodology to the different phases of system development.

Probablistic↗