Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “consequence prioritization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a framework for consequence-driven applied risk analysis, enabling utilities to prioritize and mitigate potential threats effectively, and responsibly deploy cloud applications. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Evaluation of the Los Alamos Nuclear Material Packaging Risk Ranking Method

Repackaging nuclear material into robust containers to protect workers and the public has been ongoing at LANL and around the DOE complex for nearly two decades. The number of containers at LANL is around 5,000; limited resources for repackaging material has led to extended repackaging campaigns and the need to prioritize repackaging. Various methodologies have been used to prioritize the repackaging efforts and to demonstrate progress in risk reduction over time (e.g., Boerigter, 1997). The 2000-1 DNFSB recommendation recognized the limited DOE resources for repackaging, and acknowledged the need to “prioritize and schedule tasks to be undertaken with available funds according to consideration of risks.” Later, in DNFSB recommendation 2005-1, in addition to recommending that DOE develop a packaging standard, the Board recommended that “Characterization information should also be used to develop a surveillance program prioritized according to expected material and container risk (including, for example, material type, material form, and the age and type of container).” In response to requests and recommendations from the DOE and DNSFB to prioritize according to worker risk, a risk ranking method based on the potential consequence of dropping a container from 3 meters was developed in 2007 (Smith, 2007) and updated in 2014 (Hoffman, 2014). Various LANL implementation plans for repackaging were developed over the years using this methodology (Stone, 2014). Currently, this method is utilized in conjunction with an algorithm to mitigate programmatic risk to prioritize container repackaging and material processing (Prochnow, 2015). The purpose of this study is to document how the current risk ranking method works, how it is used and potential limitations.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Fire as a fundamental ecological process: Research advances and frontiers

Fire is a powerful ecological and evolutionary force that regulates organismal traits, population sizes, species interactions, community composition, carbon and nutrient cycling and ecosystem function. It also presents a rapidly growing societal challenge, due to both increasingly destructive wildfires and fire exclusion in fire–dependent ecosystems. As an ecological process, fire integrates complex feedbacks among biological, social and geophysical processes, requiring coordination across several fields and scales of study. Here, we describe the diversity of ways in which fire operates as a fundamental ecological and evolutionary process on Earth. We explore research priorities in six categories of fire ecology: (a) characteristics of fire regimes, (b) changing fire regimes, (c) fire effects on above–ground ecology, (d) fire effects on below–ground ecology, (e) fire behaviour and (f) fire ecology modelling. We identify three emergent themes: the need to study fire across temporal scales, to assess the mechanisms underlying a variety of ecological feedbacks involving fire and to improve representation of fire in a range of modelling contexts. As fire regimes and our relationships with fire continue to change, prioritizing these research areas will facilitate understanding of the ecological causes and consequences of future fires and rethinking fire management alternatives.

54 ENVIRONMENTAL SCIENCES↗

LDRD23-0184: Resilience and Hazard Risk Assessment to Prioritize Security Operations for Decisions and Impacts (RHAPSODI)

Recent examples provide a significant concern for the resilience of the U.S. electric grid and represent a need for enhanced decision-making to address an increasingly wide range of complex system interactions and potential consequences. In response, this LDRD project produced a proof-of-concept evaluation called the Resilience and Hazard Assessment to Prioritize Security Operations for Decisions and Impacts (RHAPSODI) methodology as an agile and flexible analytic framework capable of addressing multiple, diverse threats to desired electric grid performance. After empirically grounding needs for the future of U.S. electric grid resilience, this project employed the systems-theoretic process analysis (STPA) to develop a systems engineering risk model. The results of a completed feasibility study of a notional high voltage transmission system demonstrate an improved ability to incorporate both spatial (e.g., geographically distributed) and temporal (e.g., dynamic and time-dependent) elements of security risk to the gird. The success of this LDRD project provides the foundation for further evolution of the systems engineering risk model for the grid; derivation of quantitative approaches to evaluate risk and resilience performance; facilitation of agile experimenting and grid sensitivity to a range of vulnerabilities; and development of tools to assist decision-makers in enhancing U.S. electrical grid resilience.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Building a Just Transition to a Sustainable Energy Future

Residential and commercial buildings consume roughly 74% of U.S. electricity and are responsible for approximately 35% of carbon emissions. As a result, there is no pathway to a sustainable energy future that does not prioritize a transformation in how we use, store, and generate energy in our nation’s buildings. Consequently, the importance and timeliness of research, development, demonstration, and deployment of clean energy building technologies is more pressing than ever. However, inequities that permeate society are acutely prevalent in the energy economy, particularly in the buildings sector. Therefore, as we transition to a sustainable energy future, we should prioritize a “just transition,” where we ensure the benefits, as well as costs, are more equitably distributed. As a scientific and technical community, we should take the lead in centering equity in clean energy technology innovation by permeating equity throughout the RDD&D spectrum. This talk will discuss pathways to achieving a just transition toward a sustainable energy future. It will highlight current Department of Energy and national laboratory RDD&D efforts that advance clean energy goals. The talk will conclude by challenging the ASME community to look through a lens of equity that prioritizes an equitable distribution of benefits and costs for our sustainable energy future.

30 DIRECT ENERGY CONVERSION↗

Safety and Security Defense-in-Depth for Nuclear Power Plants

This report describes the risk-informed technical elements that will contribute to a defense-in-depth assessment for cybersecurity. Risk-informed cybersecurity must leverage the technical elements of a risk-informed approach appropriately in order to evaluate cybersecurity risk insights. HAZCADS and HAZOP+ are suitable methodologies to model the connection between digital harm and process hazards. Risk assessment modeling needs to be expanded beyond HAZCADS and HAZOP+ to consider the sequence of events that lead to plant consequences. Leveraging current practices in PRA can lead to categorization of digital assets and prioritizing digital assets commensurate with the risk. Ultimately, the culmination of cyber hazard methodologies, event sequence modeling, and digital asset categorization will facilitate a defense-in-depth assessment of cybersecurity.

97 MATHEMATICS AND COMPUTING↗

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE↗

End-Use Load Profiles for the U.S. Building Stock: Practical Guidance on Accessing and Using the Data

End-use load profiles (EULP), which quantify how and when energy is used, are critically important to utilities, public utility commissions, state energy offices, and other stakeholders. Applications of EULPs focus on understanding how efficiency, demand response, and other distributed energy resources are valued and used in R&D prioritization, utility resource and distribution system planning, and state and local energy planning and regulations. Consequently, high-quality EULPs are critical for widespread adoption of electrification, demand flexibility, and grid-interactive efficient buildings. For example, EULPs can be used to forecast energy savings in buildings or to identify energy using activities that can be shifted to different times of the day.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Applications of Measuring and Valuing Resilience in Energy Systems

The electricity sector is vulnerable to numerous hazards that are being exacerbated by climate change, which can cause an increase in the hazards' frequency and intensity. Consumers, system regulators, system operators, and communities are now preparing to mitigate the increased risks posed by climate change. New York State's energy infrastructure resilience can be increased with targeted investments including but not limited to installing emergency backup systems, integrating microgrid solutions, weatherizing buildings, increasing energy efficiency, adding redundancy, investing in restoration and recovery, and hardening critical components. Such investments can reduce the likelihood, impact, and consequences of disruptive events but can also increase capital and operating costs. A barrier to prioritizing investments in resilience is that there is no widely established method for quantifying and assigning the benefits of resilience investments across various stakeholders. Decision-makers need better information detailing the value of resilience improvements. Developing methods to quantify, value, and price resilience helps meet resilience needs in an effective manner that also supports broader societal welfare. This report lays out considerations for quantifying and valuing resilience, discusses the current state of resilience valuation tools, and provides case studies of resilience projects that demonstrate how resilience attributes could be measured while highlighting broader, project-specific challenges to increasing resilience. Further, we present insights into methods and challenges to measuring, valuing, and enacting resilience investments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Addressing Consequence within Operational Risk: An Approach for Understanding an Organization’s Unique Infrastructure Environment

The endeavor of tackling operational risk focused on consequences is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure landscape in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure landscape as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space.

99 GENERAL AND MISCELLANEOUS↗

Identifying University Chemicals That Pose Security Risks: A Simple Qualitative Approach

Various laboratory-focused tools and methodologies for completing a safety risk assessment have been published, yet few similar resources to address chemical security exist. Herein, we describe a chemical security risk assessment case study at a university in a developing country. In this case study, we demonstrate a chemical security risk assessment for a university chemistry department, using an original inventory of 645 entries which was condensed to 295 chemicals after removing duplicates and erroneous entries. We then prioritized to highlight 83 chemicals of interest based on hazardous or dual-use properties that could lead to unacceptable consequences. We further refined to a list of 34 high-risk chemicals that required action, 48 chemicals that may need further justification and consideration for additional protection, and 1 chemical that did not need further consideration for additional protection.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Risk Management and Risk Aversion, from Benefit to Impediment

Risk management is a critical tool for improving the probability of project success by identifying, assessing, prioritizing, and attempting to control threats to project realization. For industries that require high operational reliability due to the potential consequences of off-normal events, such as the nuclear, aerospace, and chemical sectors, a major focus of risk management is the preservation of process safety. Due to the nature of the processes or systems under consideration, the associated process safety analyses (such as risk and safety assessments) and safety features can require significant resources. These costs are typically tolerated either due to the need to satisfy regulatory requirements or based on the assumption that they generally decrease the occurrence of unwanted events and therefore improve the probability of project success. However, as the level of acceptable or tolerable risk from unwanted events decreases, the required resources necessary for ensuring and demonstrating satisfaction of these criteria can grow and in turn can become one of the dominant impediments to project success. This paper outlines a high-level theoretical framework for the consideration of dominant project risks, which includes potential project failure from both the occurrence of high consequence off-normal events and the inability to achieve project completion due to the resource needs and innovation losses associated with extreme risk aversion. Utilizing such an integrated approach permits an attempt to optimize the probability of successful project realization while also providing valuable insight into the proper level of acceptable risk. The work is presented as a first step, in hopes of spurring additional discussion and analysis regarding appropriate levels of risk tolerance and the balance of project benefits.

Grabaskas, David↗

Comprehensive characterization of protein–protein interactions perturbed by disease mutations

Technological and computational advances in genomics and interactomics have made it possible to identify how disease mutations perturb protein–protein interaction (PPI) networks within human cells. Here, we show that disease-associated germline variants are significantly enriched in sequences encoding PPI interfaces compared to variants identified in healthy participants from the projects 1000 Genomes and ExAC. Somatic missense mutations are also significantly enriched in PPI interfaces compared to noninterfaces in 10,861 tumor exomes. We computationally identified 470 putative oncoPPIs in a pan-cancer analysis and demonstrate that oncoPPIs are highly correlated with patient survival and drug resistance/sensitivity. Further, we experimentally validate the network effects of 13 oncoPPIs using a systematic binary interaction assay, and also demonstrate the functional consequences of two of these on tumor cell growth. In summary, this human interactome network framework provides a powerful tool for prioritization of alleles with PPI-perturbing mutations to inform pathobiological mechanism- and genotype-based therapeutic discovery.

59 BASIC BIOLOGICAL SCIENCES↗

Developing a Supply Chain Security Program

Amid growing concerns over foreign manufacturing for components and devices deployed in critical energy infrastructure, this research from the national labs will highlight best practices for developing and maintaining a supply chain security program. Tools for asset inventory, tips for developing and maintaining software- and hardware-bills-of-materials (SBOMs and HBOMs), recommended contractual language for vendor agreements, and identification of responsibilities will be shared. We discuss the one-time requirements to enable a successful supply chain security program and the best ways to operationalize this program for maximum impact, including development of robust practices for vulnerability tracking, patch management, and workarounds, with understanding of the reliability and uptime requirements for utilities. The recommendations shared are based on a cyber-informed engineering approach to identification of high-consequence impacts and the engineering controls related to supply chain management that can best mitigate these impacts. This approach allows for prioritization of resources. Additionally, we highlight relative up-front and ongoing costs associated with recommended controls. Viewers will leave with an understanding what a supply chain security program is, and what steps, prioritized for resource-constrained organizations, can build a robust program.

14 SOLAR ENERGY↗

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Securing Distributed Energy Resource Integration

The penetration of distributed energy resources (DER) is growing at much higher rates than predicted 20 years ago. Far from being used only in residential settings, DER are now installed on distribution and transmission circuits. In this position, they do not have the same properties as traditional generators and are more flexible in many cases. The growing penetration and range of uses for DER motivate the need to reliably and safely integrate them into the grid. Operators must be able to rely on them not only for normal operation, but also during abnormal conditions like black starts or adverse cyber scenarios. To that end, we study the communications, device interfaces, and potential consequences of DER operation under abnormal and adversarial conditions. The weaknesses of communications networks are studied based on the industrial protocols used, and the benefits of security features are examined. The device interfaces are found to be vulnerable to attack based on the requirements in the IEEE-1547 standard for DER interconnection and interoperability, which is expected to be adopted in the next ten years. In addition to exploring the requirements of the standard, we show that these vulnerabilities and others do exist and can be used maliciously in a modern storage system DER. Consequences of these vulnerabilities range from exacerbated grid instability, to simultaneous loss of large portions of DER penetration, to physical damage to inverters or DER themselves and other sensitive equipment. We tie these outcomes to specific attacker actions in an effort to give operators a better threat intelligence view that allows them to prioritize mitigations. Finally, we discuss mitigations that could prevent many of the adversarial scenarios described. Some solutions can be added to existing infrastructure, while others may require longer term planning for grid modernization with consideration for security.

25 ENERGY STORAGE↗

Development of Integrated Safety and Security Models for Comprehensive Reliability and Resiliency Evaluation

The security of the electric grid and supporting energy systems is crucial to national security. One of the complexities in analyzing the security of energy systems is the safety consequences that may result from accidents. For energy systems, the goal is to ensure that they operate as intended and that any consequences are mitigated or prevented. The integration of safety and security is paramount to protecting these systems from attacks and ensuring that large consequences are prevented. This report describes an integrated safety and security methodology to evaluate cybersecurity events that can lead to large consequences. This novel approach first describes how Systems-Theoretic Process Analysis (STPA) provides a digital causal analysis for Bayesian Networks (BNs). The use of STPA causal analysis provides a systematic approach to constructing BNs that adequately model cyber scenarios that result in consequences. When combined with the technical principles described in Risk-Informed Management of Enterprise Systems (RIMES), a comprehensive risk-informed cybersecurity analysis results that allows decision-makers to prioritize systems that most impact risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗