Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “risk management framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper

data links↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper.

Iannicca, Dennis C.↗

Integrating Spaceflight Human System Risk Research

NASA is working to increase the likelihoods of human health and performance success during exploration missions, and subsequent crew long-term health. To manage the risks in achieving these goals, a system modeled after a Continuous Risk Management framework is in place. "Human System Risks" (Risks) have been identified, and approximately 30 are being actively addressed by NASA's Human Research Program (HRP). Research plans for each of HRP's Risks have been developed and are being executed. Ties between the research efforts supporting each Risk have been identified, however, this has been in an ad hoc fashion. There is growing recognition that solutions developed to address the full set of Risks covering medical, physiological, behavioral, vehicle, and organizational aspects of the exploration missions must be integrated across Risks and disciplines. We will discuss how a framework of factors influencing human health and performance in space is being applied as the backbone for bringing together sometimes disparate information relevant to the individual Risks. The resulting interrelated information is allowing us to identify and visualize connections between Risks and research efforts in a systematic and standardized way. We will discuss the applications of the visualizations and insights to research planning, solicitation, and decision-making processes.

Mindock, J.↗

Integrating Spaceflight Human System Risk Research

NASA is working to increase the likelihood of human health and performance success during exploration missions as well as to maintain the subsequent long-term health of the crew. To manage the risks in achieving these goals, a system modelled after a Continuous Risk Management framework is in place. "Human System Risks" (Risks) have been identified, and approximately 30 are being actively addressed by NASA's Human Research Program (HRP). Research plans for each of HRP's Risks have been developed and are being executed. Inter-disciplinary ties between the research efforts supporting each Risk have been identified; however, efforts to identify and benefit from these connections have been mostly ad hoc. There is growing recognition that solutions developed to address the full set of Risks covering medical, physiological, behavioural, vehicle, and organizational aspects of exploration missions must be integrated across Risks and disciplines. This paper discusses how a framework of factors influencing human health and performance in space is being applied as the backbone for bringing together sometimes disparate information relevant to the individual Risks. The resulting interrelated information enables identification and visualization of connections between Risks and research efforts in a systematic and standardized manner. This paper also discusses the applications of the visualizations and insights into research planning, solicitation, and decision-making processes.

Mindock, Jennifer↗

Integrated Issues and Risk Management: A Theoretical Framework Overview

The contractor requirements document for DOE O 226.1B, Implementation of Department of Energy Oversight Policy, requires DOE/NNSA contractors to establish an assurance system that includes, among other things, “Rigorous, risk-informed, and credible self-assessment and feedback and improvement activities. Assessment programs must be risk-informed, formally described and documented, and appropriately cover potentially high consequence activities” and “Contains an issues management process that is capable of categorizing the significance of findings based on risk and priority and other appropriate factors….” However, the term “risk-informed” is not defined in this or any other DOE order, and no formal guidance on how to integrate the two concepts currently exists. The Risk Management Guide for Defense Programs released by NA-18, Office of Systems Engineering and Integration (SE&I), states it is “a framework and general guidance to program office personnel on the effective management of program risks and issues”, however it then defines issues as “events with 100% likelihood of affecting program objectives” and states “unless specified otherwise, the term “risk” will also serve to represent issues for the remainder of this plan,” severally limiting its ability to provide adequate guidance on this topic. Outside of DOE scope, the U.S. Nuclear Regulatory Commission (U.S. NRC) imposes similar requirements. ASME NQA-1-2015 Requirement 16 states “Conditions adverse to quality shall be identified promptly and corrected as soon as practicable. In the case of a significant condition adverse to quality, the cause of the condition shall be determined, and corrective action taken to preclude recurrence. The identification, cause, and corrective action for significant conditions adverse to quality shall be documented and reported to appropriate levels of management. Completion of corrective actions shall be verified”. The purpose of this document is to provide a best-in-class framework for an integrated risk and issues management process. This process would provide a robust feedback loop between risk management and issues management to: Enhance risk identification and characterization, use risk handling principles to improve corrective action planning, and ensure regulatory compliance.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Cybersecurity Assessment Tools for Distributed Energy Resources

This growing number of smart devices that support DERs can increase the number of access points outside a utility’s administrative domain, which can increase the potential for cyberattack. With the integration of DERs at federal sites, the cybersecurity vulnerabilities of DER systems must be understood and addressed. This presentation covers two NREL tools available. The Distributed Energy Resource Cybersecurity Framework (DER-CF) is a web-based holistic tool for evaluating cybersecurity posture including governance, physical security and technical management. The Distributed Energy Resource Risk Manager (DER-RM) extends the DER-CF by applying it to the NIST risk management framework process. It will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Cost-benefit based assurance planning

We have extended an existing risk management framework with a refined cost-benefit model. Benefits are measured in terms of reduction of risk.

risk requirements tradeoffs design quality assuran↗

Cybersecurity for Distributed Wind: MIRACL Advisory Board Meeting 2022

This presentation for the MIRACL Industry Advisory Board summarizes the cybersecurity research for distributed wind that was performed during the project. Highlights include an overview of the distributed wind reference architecture, descriptions of the unique needs and challenges for securing distributed wind, the cyber risk management framework that was developed for this project, and key takeaways for various stakeholders.

17 WIND ENERGY↗

Incorporating cost-benefit analyses into software assurance planning

The objective is to use cost-benefit analyses to identify, for a given project, optimal sets of software assurance activities. Towards this end we have incorporated cost-benefit calculations into a risk management framework.

investment software quality software process impro↗

Risk Management for Ocean-Based Technologies [Slides]

This presentation discusses risk management for ocean-based technologies by stepping through elements of the National Laboratory of the Rockies' 2024 Marine Energy Technology Development Risk Management Framework.

16 TIDAL AND WAVE POWER↗

A History of Space Toxicology Mishaps: Lessons Learned and Risk Management

After several decades of human spaceflight, the community of space-faring nations has accumulated a diverse and sometimes harrowing history of toxicological events that have plagued human space endeavors almost from the very beginning. Lessons have been learned in ground-based test beds and others were discovered the hard way - when human lives were at stake in space. From such lessons one can build a risk-management framework for toxicological events to minimize the probability of a harmful exposure, while recognizing that we cannot foresee all events. Space toxicologists have learned that relatively harmless compounds can be converted by air revitalization systems into compounds that cause serious harm to the crew. Our toxic risk management strategy now includes an assessment of the fate of any compound that might be released into the atmosphere. Propellants are highly toxic compounds, yet we have not always been able to thoroughly isolate the crew from exposure to these toxicants. Leakage of fluids from systems has resulted in hazardous conditions at times, and the behavior of such compounds inside a spacecraft has taught us how to manage potentially harmful escapes should they occur. Potential combustion events are an ever-present threat to the wellbeing of the crew. Such events have been sufficiently common that we have learned that one cannot judge the health threat of a given fire by the magnitude of the event. Management of such risks demands monitoring of combustion products. In the category of unpredictable toxic events, if one assumes that fires are predictable, we can place experience with toxic microbial metabolites, upsets during repair operations, and discharges from filters that have accumulated a substantial load of pollutants in their absorption beds. Management of such events requires a broad-spectrum, real-time analytical capability to discern the identity and concentrations of pollutants if they enter the atmosphere. Adverse events are an integral part of any human activity, and the spacefaring community must learn as much as possible from mistakes and near misses.

James, John T.↗

Risk Management for Distributed Energy Resources

The National Institute of Standards and Technology will be hosting on Tuesday, February 2 and Wednesday, February 3, 2021, the second workshop in a new series focusing on the Open Security Controls Assessment Language. NREL extended the scope of the DERCF to include the NIST Risk Management Framework (RMF), addressing the challenges faced by federal energy managers when complying with the NIST RMF for DER systems. The NIST RMF is a cyclical process designed to incorporate principles of security and risk management into an organization’s system policies and procedures. The DER-RM will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

cybersecurity↗

MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons Learned

As the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multiorganizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other's, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission's leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA's requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.

FISMA↗

Comparison of Deterministic and Statistical Models for Water Quality Compliance Forecasting in the San Joaquin River Basin, California

Model selection for water quality forecasting depends on many factors including analyst expertise and cost, stakeholder involvement and expected performance. Water quality forecasting in arid river basins is especially challenging given the importance of protecting beneficial uses in these environments and the livelihood of agricultural communities. In the agriculture-dominated San Joaquin River Basin of California, real-time salinity management (RTSM) is a state-sanctioned program that helps to maximize allowable salt export while protecting existing basin beneficial uses of water supply. The RTSM strategy supplants the federal total maximum daily load (TMDL) approach that could impose fines associated with exceedances of monthly and annual salt load allocations of up to $1 million per year based on average year hydrology and salt load export limits. The essential components of the current program include the establishment of telemetered sensor networks, a web-based information system for sharing data, a basin-scale salt load assimilative capacity forecasting model and institutional entities tasked with performing weekly forecasts of river salt assimilative capacity and scheduling west-side drainage export of salt loads. Web-based information portals have been developed to share model input data and salt assimilative capacity forecasts together with increasing stakeholder awareness and involvement in water quality resource management activities in the river basin. Two modeling approaches have been developed simultaneously. The first relies on a statistical analysis of the relationship between flow and salt concentration at three compliance monitoring sites and the use of these regression relationships for forecasting. The second salt load forecasting approach is a customized application of the Watershed Analysis Risk Management Framework (WARMF), a watershed water quality simulation model that has been configured to estimate daily river salt assimilative capacity and to provide decision support for real-time salinity management at the watershed level. Analysis of the results from both model-based forecasting approaches over a period of five years shows that the regression-based forecasting model, run daily Monday to Friday each week, provided marginally better performance. However, the regression-based forecasting model assumes the same general relationship between flow and salinity which breaks down during extreme weather events such as droughts when water allocation cutbacks among stakeholders are not evenly distributed across the basin. A recent test case shows the utility of both models in dealing with an exceedance event at one compliance monitoring site recently introduced in 2020.

54 ENVIRONMENTAL SCIENCES↗

Developing a Decision Support System for Regional Agricultural Nonpoint Salinity Pollution Management: Application to the San Joaquin River, California

Environmental problems and production losses associated with irrigated agriculture, such as salinity, degradation of receiving waters, such as rivers, and deep percolation of saline water to aquifers, highlight water-quality concerns that require a paradigm shift in resource-management policy. New tools are needed to assist environmental managers in developing sustainable solutions to these problems, given the nonpoint source nature of salt loads to surface water and groundwater from irrigated agriculture. Equity issues arise in distributing responsibility and costs to the generators of this source of pollution. This paper describes an alternative approach to salt regulation and control using the concept of “Real-Time Water Quality management”. The approach relies on a continually updateable WARMF (Watershed Analysis Risk Management Framework) forecasting model to provide daily estimates of salt load assimilative capacity in the San Joaquin River and assessments of compliance with salinity concentration objectives at key monitoring sites on the river. The results of the study showed that the policy combination of well-crafted river salinity objectives by the regulator and the application of an easy-to use and maintain decision support tool by stakeholders have succeeded in minimizing water quality (salinity) exceedances over a 20-year study period.

real-time management economics↗

Automation for Distributed Energy Resources Risk Manager Using OSCAL

The risk management framework (RMF) provides a well-organized and thorough approach to diagnose information technology (IT) system threats, to gather required materials to comply with industry standards, and to document a plan for achieving authority to operate (ATO). ATO is given by the operating authority with the awareness of vulnerabilities that arise when operating the IT system. The primary goal of the National Renewable Energy Laboratory’s (NREL’s) distributed energy resource (DER) RM application is to provide a user-friendly interface and in-depth guidance for generating the authorization package for the authorizing official to review. In other words, the application satisfies steps 1 through 7 of the RMF process with a focus on DERs.

cybersecurity↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

ARC-100 Reactor Security-by-Design Summary 2025

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the ARC-100, a sodium-cooled fast reactor (SFR) being developed by ARC Clean Technology, Inc (ARC). The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, used fuel assembly wash station, cesium trap, sodium cold trap, noble gas decay tanks, used fuel dry storage facility, damaged fuel storage facility, and radioactive waste building. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗