Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Threat Landscape for BESS and IBR

The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.

14 - SOLAR ENERGY↗

The hack attack - Increasing computer system awareness of vulnerability threats

The paper discusses the issue of electronic vulnerability of computer based systems supporting NASA Goddard Space Flight Center (GSFC) by unauthorized users. To test the security of the system and increase security awareness, NYMA, Inc. employed computer 'hackers' to attempt to infiltrate the system(s) under controlled conditions. Penetration procedures, methods, and descriptions are detailed in the paper. The procedure increased the security consciousness of GSFC management to the electronic vulnerability of the system(s).

Quann, John↗

Yesterday’s extremes, today’s new normal: flood risk in the Kathmandu Valley, Nepal

Unplanned urban growth has left many cities increasingly vulnerable to extreme rainfall events, particularly in regions with inadequate drainage infrastructures and development encroaching on natural floodplains. Here, in this perspective paper, we examine the September 2024 floods that struck Central Nepal, triggered by a persistent low-pressure system and enhanced by converging moisture flows from the Arabian Sea and the Bay of Bengal which led to widespread catastrophic damage. In the Kathmandu Valley, floodwaters expanded to more than 2.5 times the bankfull water extent, causing significant damage to housing, transportation network, and critical infrastructure, displacing thousands of residents, and severely disrupting urban services. This event highlights the urgent need for improved flood management strategies that integrate both structural and non-structural measures into the infrastructure development. While early warning systems provided critical lead time, challenges remain in reducing forecasting uncertainties and improving communication across government agencies and with local communities. A forward-looking approach is essential, including probabilistic flood forecasting systems, sustainable floodplain management, risk-sensitive land use planning, climate- and disaster- resilient infrastructure development, and the integration of nature-based solutions like urban green and blue spaces to mitigate flood impacts. By involving local communities in planning and preparedness efforts, particularly through citizen science initiatives, and engagement with underserved and disadvantaged communities, Nepal can better adapt to the growing risks posed by extreme rainfall and urban flooding and enhance long-term disaster resilience in rapidly urbanizing areas like Kathmandu Valley.

Kathmandu Valley↗

Roadmap for the future of extreme wildfire events

Background Extreme wildfire events (EWEs) represent a growing threat globally, posing substantial risks to ecosystems, human communities, and infrastructure. Despite increased recognition of their ecological, social, and economic significance, current definitions of EWEs vary widely, reflecting disciplinary biases and regional contexts. This article emerges from an interdisciplinary workshop convened to reassess and refine the definition of EWEs, examine their impacts across ecological and social dimensions, and identify critical knowledge gaps impeding our understanding of these infrequent but important events. Results Our synthesis highlights significant limitations with existing definitions, particularly their reliance on subjective thresholds and their emphasis on extreme fire behavior alone. EWEs encompass a spectrum of complex, multi-dimensional phenomena that extend beyond immediate biophysical characteristics to include cumulative social, economic, and ecological impacts. These impacts often manifest over extended timeframes and include hazardous environmental contamination, severe geomorphic disturbances, ecosystem transformations, and unintended consequences of post-fire management actions. Current wildfire modeling frameworks inadequately capture these compounding factors, particularly the interactions among social systems, ecological conditions, and extreme fire behavior. To overcome these issues, we advocate for an interdisciplinary and context-sensitive approach to defining and studying EWEs. This revised definition emphasizes wildfires exhibiting anomalies in fire behavior, ecological outcomes, or social impacts relative to historically observed baselines, accommodating variability across different geographic regions and ecological settings. Conclusions Adopting an interdisciplinary framework that integrates biophysical and social sciences will enhance the predictive capability of wildfire models and improve resilience planning and response strategies. Filling identified knowledge gaps—such as limited high-quality empirical fire behavior data and insufficient integration of social dynamics into modeling—will better prepare communities and ecosystems to cope with and adapt to EWEs. This inclusive approach underscores the necessity for collaboration across disciplines and sectors, essential to managing extreme wildfires in an era of increasing climatic and ecological uncertainty.

54 ENVIRONMENTAL SCIENCES↗

Toward Global Drought Early Warning Capability - Expanding International Cooperation for the Development of a Framework for Monitoring and Forecasting

Drought has had a significant impact on civilization throughout history in terms of reductions in agricultural productivity, potable water supply, and economic activity, and in extreme cases this has led to famine. Every continent has semiarid areas, which are especially vulnerable to drought. The Intergovernmental Panel on Climate Change has noted that average annual river runoff and water availability are projected to decrease by 10 percent-13 percent over some dry and semiarid regions in mid and low latitudes, increasing the frequency, intensity, and duration of drought, along with its associated impacts. The sheer magnitude of the problem demands efforts to reduce vulnerability to drought by moving away from the reactive, crisis management approach of the past toward a more proactive, risk management approach that is centered on reducing vulnerability to drought as much as possible while providing early warning of evolving drought conditions and possible impacts. Many countries, unfortunately, do not have adequate resources to provide early warning, but require outside support to provide the necessary early warning information for risk management. Furthermore, in an interconnected world, the need for information on a global scale is crucial for understanding the prospect of declines in agricultural productivity and associated impacts on food prices, food security, and potential for civil conflict. This paper highlights the recent progress made toward a Global Drought Early Warning Monitoring Framework (GDEWF), an underlying partnership and framework, along with its Global Drought Early Warning System (GDEWS), which is its interoperable information system, and the organizations that have begun working together to make it a reality. The GDEWF aims to improve existing regional and national drought monitoring and forecasting capabilities by adding a global component, facilitating continental monitoring and forecasting (where lacking), and improving these tools at various scales, thereby increasing the capacity of national and regional institutions that lack drought early warning systems or complementing existing ones. A further goal is to improve coordination of information delivery for drought-related activities and relief efforts across the world. This is especially relevant for regions and nations with low capacity for drought early warning. To do this requires a global partnership that leverages the resources necessary and develops capabilities at the global level, such as global drought forecasting combined with early warning tools, global real-time monitoring, and harmonized methods to identify critical areas vulnerable to drought. Although the path to a fully functional GDEWS is challenging, multiple partners and organizations within the drought, forecasting, agricultural, and water-cycle communities are committed to working toward its success.

GDEWS↗

Unsupervised Detection of SOC Spoofing in OCPP 2.0.1 EV Charging Communication Protocol Using One-Class SVM

The electric vehicles (EVs) market keeps growing globally; thus, it is critical to secure the EV charging communication protocols in order to guarantee reliable and fair charging operations among the customers. The Open Charge Point Protocol (OCPP) 2.0.1 supports the communication between the Electric Vehicle Supply Equipment (EVSE) and Charging Station Management Systems (CSMSs); therefore, it becomes vulnerable to several types of attacks, which aim to jeopardize smart charging, billing, and energy management. Specifically, OCPP 2.0.1 allows the self-reporting of the State of Charge (SOC) values, which makes it vulnerable to spoofing-based cyberattacks, which target manipulating the scheduling priorities, distorting the load forecasts, and extending the charging sessions in an unfair manner. In this paper, we try to address this type of attack by providing a comprehensive analysis of the SOC spoofing attacks and introducing a novel unsupervised detection framework based on the One-Class Support Vector Machine (OCSVM) algorithm. Specifically, two types of attack scenarios are analyzed (i.e., priority manipulation and session extension) by deriving engineered features that capture the nonlinear relationships under normal charging behavior. Detailed simulation-based results are derived by utilizing the DESL-EPFL Level 3 EV charging dataset. Our results demonstrate high F1-score and recall in identifying spoofed SOC values and that the proposed OCSVM model demonstrates superior performance compared to alternative clustering and deep-learning based detectors.

EV charging↗

Youngstown and Warren Disasters: Mapping Flood Susceptibility, Vulnerability, and Risk and Tree Canopy Coverage in Northern Ohio to Inform Stormwater Management and Flood Mitigation Efforts

Both pluvial and fluvial flooding events pose direct challenges on urban infrastructure and communities across the United States. Heavy rainfall events oversaturate the ground, overflow waterbodies, and overwhelm stormwater infrastructure. Vulnerable areas receive heavy damage from flooding events due to physical factors like increased impervious surfaces, poor stormwater systems, and limited greenspaces. These vulnerable neighborhoods are comprised of aging populations, minority communities, and lower income levels. Lack of data in these communities have made it difficult to implement policymaking and flood mitigation strategies. Using the Urban Flood Risk Mitigation model (InVEST) and the PlanetScope satellite constellation, the team visualized historical flooding and tree canopy coverage as a measure of flood susceptibility. The team also used the Arc-Malstrom model to provide further insight into where flooding accumulates via surface elevation depressions in the study area. To validate these models, the team explored the spatial variation of rainfall events using NASA’s Integrated Multi-satellite Retrievals for Global Precipitation Measurement (GPM IMERG). The resulting maps highlight areas surrounding the cities of Youngstown and Warren as being the most flood susceptible and socially vulnerable, while the city centers contain the lowest tree canopy coverage. The DEVELOP team collaborated with the Environmental Collaborative of Ohio (ECO) to create products for end users within the City of Warren’s Water Pollution Control Department, the Eastgate Regional Council of Governments and the Healthy Community Partnership of Mahoning Valley. These products help identify target areas for preventative flood mitigation measures as well as areas ideal for green infrastructure intervention.

InVEST Urban Flood Risk Mitigation Model↗

Coordinating AgMIP Data and Models Across Global and Regional Scales for 1.5°C and 2.0°C Assessments

The Agricultural Model Intercomparison and Improvement Project (AgMIP) has developed novel methods for Coordinated Global and Regional Assessments (CGRA) of agriculture and food security in a changing world. The present study aims to perform a proof of concept of the CGRA to demonstrate advantages and challenges of the proposed framework. This effort responds to the request by the UN Framework Convention on Climate Change (UNFCCC) for the implications of limiting global temperature increases to 1.5°C and 2.0°C above pre-industrial conditions. The protocols for the 1.5°C/2.0°C assessment establish explicit and testable linkages across disciplines and scales, connecting outputs and inputs from the Shared Socio-economic Pathways (SSPs), Representative Agricultural Pathways (RAPs), Half a degree Additional warming, Prognosis and Projected Impacts (HAPPI) and Coupled Model Intercomparison Project Phase 5 (CMIP5) ensemble scenarios, global gridded crop models, global agricultural economics models, site-based crop models and within-country regional economics models. The CGRA consistently links disciplines, models and scales in order to track the complex chain of climate impacts and identify key vulnerabilities, feedbacks and uncertainties in managing future risk. CGRA proof-of-concept results show that, at the global scale, there are mixed areas of positive and negative simulated wheat and maize yield changes, with declines in some bread basket regions, at both 1.5°C and 2.0°C. Declines are especially evident in simulations that do not take into account direct CO2 effects on crops. These projected global yield changes mostly resulted in increases in prices and areas of wheat and maize in two global economics models. Regional simulations for 1.5°C and 2.0°C using site-based crop models had mixed results depending on the region and the crop. In conjunction with price changes from the global economics models, productivity declines in the Punjab, Pakistan, resulted in an increase in vulnerable households and the poverty rate. This article is part of the theme issue ‘The Paris Agreement: understanding the physical and social challenges for a warming world of 1.5°C above pre-industrial levels’.

interdisciplinary↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper

data links↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper.

Iannicca, Dennis C.↗

Cyber-Threat Assessment for the Air Traffic Management System: A Network Controls Approach

Air transportation networks are being disrupted with increasing frequency by failures in their cyber- (computing, communication, control) systems. Whether these cyber- failures arise due to deliberate attacks or incidental errors, they can have far-reaching impact on the performance of the air traffic control and management systems. For instance, a computer failure in the Washington DC Air Route Traffic Control Center (ZDC) on August 15, 2015, caused nearly complete closure of the Centers airspace for several hours. This closure had a propagative impact across the United States National Airspace System, causing changed congestion patterns and requiring placement of a suite of traffic management initiatives to address the capacity reduction and congestion. A snapshot of traffic on that day clearly shows the closure of the ZDC airspace and the resulting congestion at its boundary, which required augmented traffic management at multiple locations. Cyber- events also have important ramifications for private stakeholders, particularly the airlines. During the last few months, computer-system issues have caused several airlines fleets to be grounded for significant periods of time: these include United Airlines (twice), LOT Polish Airlines, and American Airlines. Delays and regional stoppages due to cyber- events are even more common, and may have myriad causes (e.g., failure of the Department of Homeland Security systems needed for security check of passengers, see [3]). The growing frequency of cyber- disruptions in the air transportation system reflects a much broader trend in the modern society: cyber- failures and threats are becoming increasingly pervasive, varied, and impactful. In consequence, an intense effort is underway to develop secure and resilient cyber- systems that can protect against, detect, and remove threats, see e.g. and its many citations. The outcomes of this wide effort on cyber- security are applicable to the air transportation infrastructure, and indeed security solutions are being implemented in the current system. While these security solutions are important, they only provide a piecemeal solution. Particular computers or communication channels are protected from particular attacks, without a holistic view of the air transportation infrastructure. On the other hand, the above-listed incidents highlight that a holistic approach is needed, for several reasons. First, the air transportation infrastructure is a large scale cyber-physical system with multiple stakeholders and diverse legacy assets. It is impractical to protect every cyber- asset from known and unknown disruptions, and instead a strategic view of security is needed. Second, disruptions to the cyber- system can incur complex propagative impacts across the air transportation network, including its physical and human assets. Also, these implications of cyber- events are exacerbated or modulated by other disruptions and operational specifics, e.g. severe weather, operator fatigue or error, etc. These characteristics motivate a holistic and strategic perspective on protecting the air transportation infrastructure from cyber- events. The analysis of cyber- threats to the air traffic system is also inextricably tied to the integration of new autonomy into the airspace. The replacement of human operators with cyber functions leaves the network open to new cyber threats, which must be modeled and managed. Paradoxically, the mitigation of cyber events in the airspace will also likely require additional autonomy, given the fast time scale and myriad pathways of cyber-attacks which must be managed. The assessment of new vulnerabilities upon integration of new autonomy is also a key motivation for a holistic perspective on cyber threats.

Complex Networks↗

Coordinated Thermal Safety Attack and Defense on EV Battery Management Systems

Battery temperature sensor and battery current sensor data which are key sensing inputs to the Battery Management Controllers in electric vehicles, are vulnerable to possible cyber/ physical manipulation due to known vulnerabilities inherited from CAN bus technology that is used for in-vehicle communications between electronic control units that transfer sensing and control data. In this paper, we first create a simulation that enables us to evaluate impact of cyber physical attacks on electric vehicle battery management system in a controlled environment that violates thermal safety. Specifically, we emulate a Level 3 - DC fast charging system with SAE J1772/CCS, integrated with standard charging controls and thermal safety controls on EVs, and various sensing data flows. Second, we propose a coordinated current and battery temperature attack that has crippling economic, and safety impacts. Third, we quantify the usability, economic and safety impacts of such attacks as a function of the extent of data manipulation. Finally, we propose a physics model driven detection technique to detect presence of such attacks.

25 ENERGY STORAGE↗

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION↗

IT Security Support for the Spaceport Command Control Systems Development Ground Support Development Operations

Security is one of the most if not the most important areas today. After the several attacks on the United States, security everywhere was heightened from Airports to the communication among the military branches legionnaires. With advanced persistent threats (APTs) on the rise following Stuxnet, government branches and agencies are required, more than ever, to follow several standards, policies and procedures to reduce the likelihood of a breach. Attack vectors today are very advanced and are going to continue to get more and more advanced as security controls advance. This creates a need for networks and systems to be in an updated and secured state in a launch control system environment. FISMA is a law that is mandated by the government to follow when government agencies secure networks and devices. My role on this project is to ensure network devices and systems are in compliance with NIST, as outlined in FISMA. I will achieve this by providing assistance with security plan documentation and collection, system hardware and software inventory, malicious code and malware scanning and configuration of network devices i.e. routers and IDSsIPSs. In addition I will be completing security assessments on software and hardware, vulnerability assessments and reporting, conducting patch management and risk assessments. A guideline that will help with compliance with NIST is the SANS Top 20 Critical Controls. SANS Top 20 Critical Controls as well as numerous security tools, security software and the conduction of research will be used to successfully complete the tasks given to me. This will ensure compliance with FISMA and NIST, secure systems and a secured network. By the end of this project, I hope to have carried out stated above as well as gain an immense knowledge about compliance, security tools, networks and network devices, policies and procedures.

computer information security↗

TASTI-GRID: Improving Electric Grid Resilience across the State of Tennessee

Residential, industrial, and large load data center facility expansion have exacerbated management backlogs. Additionally, as newer technologies emerge in larger utility providers, a chasm between urban and rural resilience grows – creating segmentation across the state. With new development, industries, and large load additions to the electric grid across the Volunteer state, utilities must contend with these new connections, management backlogs, and technology gaps – while addressing an increase in major outages with more frequent extreme weather events, such as Hurricane Helene in 2024. This issues, in turn, have given way to greater vulnerabilities in adjacent infrastructure – including transportation and emergency management services, among others.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Process Effectiveness to Reduce Risk

It is well documented that government agencies do not have the same incentive as the private sector to focus on process effectiveness and continual improvement of those processes. It is also well documented whenever government agencies fail to deliver efficient, effective, consistent, and fair services to the citizens. In spite of the various "reinventing government" and "effectiveness initiatives" of the past decades, and in spite of the efforts on the part of many agencies to improve, government in general still lags behind industry in creating a culture of effective processes and systems. While the tragic events that unfolded recently in Flint, Michigan, teach us that running government "like a business" does not always take the needs of the citizenry into account, there are many lessons and techniques from the private sector that government agencies can use to improve. The incentive to improve, while mandated by various administrations1, needs to come from within the workforce, in order to effectively take root. The best, most effective incentive is to reduce, control or eliminate risk. Government agencies face some of the same risks as the private sector, while some are unique. While ISO 310002 has been around since 2009, risk has taken on increased visibility within the private sector with the advent of the emphasis on risk-based thinking in ISO 9001:20153. The relationship between risk-based thinking and effective processes is simple and direct. Those processes that are well thought out and standardized (i.e. Plan-Do-Check-Act), will have taken into account the applicable policy, statutory, regulatory, safety, quality and technical parameters, which may not occur to someone performing the process with minimal experience or training; and thus protect the employees, the public and the agency from statutory and regulatory violations; delay in providing services; non-delivery of services; harm to public or employee safety and health; cost overruns; breaches in security; loss of confidence in government; failure of publicly funded projects; damage to the environment; ethics violations, and the list goes on; with local, national and even international consequences. The Plan-Do-Check-Act process, also known as the "process approach" can be used at any time to establish and standardize a process, and it can also be used to check periodically for "process creep" (i.e., informal, unauthorized changes that have occurred over time), any necessary updates and improvements. While ISO 9001 compliance is not mandated for all government agencies, if interpreted correctly, it can be useful in establishing a framework and implementing effective management systems and processes.4 Another method that can be used to evaluate effectiveness is the scorecard definitions in Mallory's Process Management Standard5 as a basis for evaluating work on the process level on effective, and continuously improved and improving processes. With processes on the lower end of the scale, agencies are vulnerable to a great many risks, with employees and managers making up many of the rules as they go, leading to the above listed negative results. Without clear guidance for nominal operations, off-nominal situations can, and do, increase the likelihood of chaos. In an increasingly technical environment, with inter-agency communication and collaboration becoming the norm, agencies need to come to grips with the fact that processes can become rapidly outdated, and that the technical community should take on an increased role in the maturation of the agency's processes. Industry has long known that effective processes are also efficient, and process improvement methods such as Kaizen, Lean, Six Sigma, 5S, and mistake proofing lead to increased productivity, improved quality, and decreased cost. Again, government agencies have different concerns, but inefficiencies and mistakes can have dire and wide reaching consequences for the public that they serve. While no one goes to work planning to cause harm, it is up to agencies to establish upper level systems, which make establishment and compliance with processes possible. Again, Mallory provides us with a Systems Management Standard6, similar to the Process Management Standard, with a scale of 0-5 for systems effectiveness and maturity. Deming determined that "eighty-five percent of the reasons for failure are deficiencies in the systems and process rather than the employee. The role of management is to change the process rather than badgering individual employees to do better." 7 It is not just the working level employees who need effective processes, but the mid-and upper level managers as well. A disciplined management culture sets the tone for the employees, aids both routine and off-nominal decision-making, and incorporates risk -based thinking into the systems and processes as a matter of normal activity. Figure 1, illustrates the relationship between ineffective and effective processes and risk, through the use of the "stoplight" colors that are commonly used to show serious situations (red), situations which may be improving or deteriorating depending on trends (yellow), and situations that are under control and continuously improved (green).

Shepherd, Christena C.↗