Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “risk management framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Comparison of Deterministic and Statistical Models for Water Quality Compliance Forecasting in the San Joaquin River Basin, California

Model selection for water quality forecasting depends on many factors including analyst expertise and cost, stakeholder involvement and expected performance. Water quality forecasting in arid river basins is especially challenging given the importance of protecting beneficial uses in these environments and the livelihood of agricultural communities. In the agriculture-dominated San Joaquin River Basin of California, real-time salinity management (RTSM) is a state-sanctioned program that helps to maximize allowable salt export while protecting existing basin beneficial uses of water supply. The RTSM strategy supplants the federal total maximum daily load (TMDL) approach that could impose fines associated with exceedances of monthly and annual salt load allocations of up to $1 million per year based on average year hydrology and salt load export limits. The essential components of the current program include the establishment of telemetered sensor networks, a web-based information system for sharing data, a basin-scale salt load assimilative capacity forecasting model and institutional entities tasked with performing weekly forecasts of river salt assimilative capacity and scheduling west-side drainage export of salt loads. Web-based information portals have been developed to share model input data and salt assimilative capacity forecasts together with increasing stakeholder awareness and involvement in water quality resource management activities in the river basin. Two modeling approaches have been developed simultaneously. The first relies on a statistical analysis of the relationship between flow and salt concentration at three compliance monitoring sites and the use of these regression relationships for forecasting. The second salt load forecasting approach is a customized application of the Watershed Analysis Risk Management Framework (WARMF), a watershed water quality simulation model that has been configured to estimate daily river salt assimilative capacity and to provide decision support for real-time salinity management at the watershed level. Analysis of the results from both model-based forecasting approaches over a period of five years shows that the regression-based forecasting model, run daily Monday to Friday each week, provided marginally better performance. However, the regression-based forecasting model assumes the same general relationship between flow and salinity which breaks down during extreme weather events such as droughts when water allocation cutbacks among stakeholders are not evenly distributed across the basin. A recent test case shows the utility of both models in dealing with an exceedance event at one compliance monitoring site recently introduced in 2020.

54 ENVIRONMENTAL SCIENCES↗

Developing a Decision Support System for Regional Agricultural Nonpoint Salinity Pollution Management: Application to the San Joaquin River, California

Environmental problems and production losses associated with irrigated agriculture, such as salinity, degradation of receiving waters, such as rivers, and deep percolation of saline water to aquifers, highlight water-quality concerns that require a paradigm shift in resource-management policy. New tools are needed to assist environmental managers in developing sustainable solutions to these problems, given the nonpoint source nature of salt loads to surface water and groundwater from irrigated agriculture. Equity issues arise in distributing responsibility and costs to the generators of this source of pollution. This paper describes an alternative approach to salt regulation and control using the concept of “Real-Time Water Quality management”. The approach relies on a continually updateable WARMF (Watershed Analysis Risk Management Framework) forecasting model to provide daily estimates of salt load assimilative capacity in the San Joaquin River and assessments of compliance with salinity concentration objectives at key monitoring sites on the river. The results of the study showed that the policy combination of well-crafted river salinity objectives by the regulator and the application of an easy-to use and maintain decision support tool by stakeholders have succeeded in minimizing water quality (salinity) exceedances over a 20-year study period.

real-time management economics↗

Automation for Distributed Energy Resources Risk Manager Using OSCAL

The risk management framework (RMF) provides a well-organized and thorough approach to diagnose information technology (IT) system threats, to gather required materials to comply with industry standards, and to document a plan for achieving authority to operate (ATO). ATO is given by the operating authority with the awareness of vulnerabilities that arise when operating the IT system. The primary goal of the National Renewable Energy Laboratory’s (NREL’s) distributed energy resource (DER) RM application is to provide a user-friendly interface and in-depth guidance for generating the authorization package for the authorizing official to review. In other words, the application satisfies steps 1 through 7 of the RMF process with a focus on DERs.

cybersecurity↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

ARC-100 Reactor Security-by-Design Summary 2025

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the ARC-100, a sodium-cooled fast reactor (SFR) being developed by ARC Clean Technology, Inc (ARC). The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, used fuel assembly wash station, cesium trap, sodium cold trap, noble gas decay tanks, used fuel dry storage facility, damaged fuel storage facility, and radioactive waste building. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Flexibility Auctions: A Framework for Managing Imbalance Risk

As the electricity generated by variable resources grows, system operators and variable resources have to manage challenging imbalances between forward and real-time markets. The Flexibility Auction is a novel approach for managing imbalances as it will allow resources with imbalance risk to hedge their production by buying flexibility options. The flexibility options are offered by grid-connected resources that can provide physical flexibility. This presentation will focus on the design of the Flexibility Auction, its properties, and how it can complement system-level services such as CAISO's proposed imbalance reserves. The presentation will include simple examples to illustrate the impact of the Flexibility Auction on the market participants and the system's imbalance risk.

auction↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗

Resilience Metrics and Framework for Distributed Wind Presentation

This presentation communicates information about the MIRACL project Resilience Metrics report and Resilience Framework report. It was created for the 2021 MIRACL advisory board meeting. We propose a three-tiered approach for the resilience framework. At the top level, we consider the time horizons on which resilience will be evaluated and executed. At the middle level, we consider the core functions of resilience, which span across the time horizons. At the lower level, we consider the process steps that correspond to implementing practices for resilience in each of the core functions. The framework considers three time horizons in order to enable organizations to assess and improve their system’s resilience throughout its lifecycle. We call these time horizons the planning, operational, and future stages. The planning stage uses organizational needs and current system evaluation to prepare for potential hazards. The operational stage seeks to execute responses to hazards as prudently and efficiently as possible to maintain system resilience. The future stage seeks to improve on current system resilience and feeds back into the planning stage to promote continuous improvement. While all three time horizons are important when considering a specific topic, the planning and evaluation phase (i.e., what is done in advance of the event) is critical in defining a system’s resilience characteristics and in outlining how a system responds to an event. This framework intentionally emphasizes the planning stage to highlight the overarching emphasis of this effort, not to imply that the other two time-related horizons (i.e., operational and change the future) are less important. The core functions in the framework are identify, prepare, detect, adapt, and recover. These five functions stem from a rigorous analysis of definitions used across the industry, and they represent the core capabilities that an organization must have to enable lifecycle resilience. Within each core function, process steps are described that help walk an organization through the information gathering, evaluation, decision-making, and implementation processes they will need to ensure their resilience goals are maintained throughout the system and the system lifecycle. Also highlighted in the figure is the concept that a resilience framework should be cyclical in nature. Because a system’s resilience is based on finite resources and time, it must continually evolve through this framework’s risk management and capital investment steps at an appropriate level of scope and pace.

17 WIND ENERGY↗

Cybersecurity Resiliency of Marine Renewable Energy Systems Part 2: Cybersecurity Best Practices and Risk Management

Marine renewable energy (MRE) is an emerging source of power for marine applications, marine devices, and coastal communities. This energy source relies on industrial control systems and IT to support operations and maintenance activities, which create a pathway for an adversary to gain unauthorized access to systems and data and disrupt operations. Incorporating cybersecurity risk prevention measures and mitigation capabilities from inception, development, operation, to decommissioning of the MRE system and components is paramount to the protection of energy generation and the security of network architecture and infrastructure. To improve the resilience of MRE systems as a predictable, affordable, and reliable source of energy, cybersecurity guidance was developed to enable operators to assess cybersecurity risks and implement security measures commensurate with the risk. This publication is the second of a two-part series, with Part 1 addressing a framework to determine cybersecurity risk by assessing the vulnerability of an MRE system to potential cyber threats and the consequences a cyberattack would have on the end user. This Part 2 publication describes an approach to select appropriate cybersecurity best practices commensurate with the MRE system's cybersecurity risk. The guidance includes 86 cybersecurity best practices, which are associated with 36 cybersecurity domains and grouped into nine categories. The best practices follow the core functions of the National Institute of Science and Technology Cybersecurity Framework (e.g., identify, detect, protect, respond, and and recover) and insights from both maritime and energy industry guidance documents to identify security measures effective in protecting information and operational technology assets prevalent in MRE systems.

97 MATHEMATICS AND COMPUTING↗

Resilience Framework for Electric Energy Delivery Systems (R.1)

The intent of this document is to provide a Resilience Framework for electrical energy delivery systems which can be applied to Distributed Wind. However, the framework is not limited by application to any resource or system. This framework represents the defined steps to a cyclical process similar in mechanism to both cybersecurity and risk frameworks, while providing a common set of language and process for all stakeholders involved. The need for this Resilience Framework was established in a previous document, “Distributed Wind Resilience Metrics for Electric Energy Delivery Systems.” One important characteristic we see in resilience is the unique needs and perspectives of different systems, geographies, resources, stakeholders, perceived risks, and consequences, which we term the distinctiveness property. This distinctiveness property drives the requirement to have a resilience framework or methodology that can be implemented by different types of organizations and systems. The process or methodology should be cyclic. Recognizing that a system’s resilience is based on finite resources and time, it must continually evolve through this framework’s risk management and capital investment steps at an appropriate pace for its distinctiveness property.

17 WIND ENERGY↗

Energy Management Information Systems Cybersecurity Best Practices

Energy management information systems (EMIS) are a broad and rapidly evolving family of tools that monitor, analyze, and control building energy use and system performance. Critical systems are often integrated with or operate on the same networks as EMIS scope systems, necessitating stable, continuous, and secure communication. When connecting EMIS to building automation and utility control systems, there are also many physical assets that could cause harm to the building and its occupants if a malicious act or human error were introduced. It is imperative to ensure all EMIS scope systems are connected securely to the EMIS and do not open vulnerable pathways to other facility networks and operations. The Federal Energy Management Program (FEMP) promotes best practices for impactful utilization of EMIS at federal facilities. This best practice document is part of a series of fact sheets created to help accelerate the market adoption and use of EMIS in the federal sector. It provides an overview of required EMIS cybersecurity standards for compliance and authority to operate along with additional recommendations.

Cybersecurity↗

An Integrated Framework for Effective Management of Delivery Risk in Electricity Markets: From Batteries to Insurance and Beyond

Net load imbalances due to imperfect day-ahead forecasts can cause variability in real-time electricity prices and higher system operations costs. We propose a novel market product called Flexibility Options that allow participants to hedge uncertainty by buying flexibility from flexible resources. Simulations show that flexibility options can reduce total system operating costs by up to 15% and can reduce variability in market participant revenues. To better quantify the flexibility that DER aggregators can provide, we develop DER flexibility scores that account for asset flexibility and uncertainty from occupant behavior and weather. Preliminary results show that realistic sets of DERs have significant variability in flexibility and uncertainty metrics.

delivery risk↗

Integrating Cyber-Informed Engineering into Process Automation

As organizations increasingly automate their core missions and essential functions to address business risks and enhance efficiency, process automation becomes pivotal. This shift, involving minimal or no manual intervention, significantly impacts an organization's cyber-risk landscape. While automation drives efficiencies, it also introduces new cyber risks if not properly managed. Cyber-Informed Engineering (CIE) provides a proactive framework for managing these digital risks, enhancing cyber-resilience in process automation. This document supports organizations in applying CIE principles to mitigate the cyber risks associated with automation. The outlined approach can be independently implemented to improve any organization’s cyber-resilience, ensuring that the advantages of automation do not result in unaddressed or unmanaged digital risks. It serves as a starting point, offering considerations for integrating CIE principles and practices into organizational processes. CIE is presented as an iterative process, fostering continuous improvement and reinforcing the engineering and operational cultures to manage digital risks effectively. The document is structured as follows: Section 1 provides background on CIE and process automation, and their integration. Section 2 explores the twelve CIE principles in the context of process automation, highlighting key questions, engineering considerations, and implications for digital risk management. Section 3 synthesizes the findings and offers recommendations to advance resilience by design.

42 - ENGINEERING↗

Hungary 908 Event - Risk Based Graded Approach to ITM

This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.

99 - GENERAL AND MISCELLANEOUS↗

Systematic Enterprise Risk Management by Integrating the RISMC Toolkit and Cost-Benefit Analysis (Final Report)

The goal of this research is to theorize and quantify the relationships between safety and the financial performance of nuclear power plants (NPPs). The Socio-Technical Risk Analysis (SoTeRiA) theoretical framework, which connects the social aspects (e.g., safety culture) and structural features (e.g., safety practices) of an organization with organizational safety and financial risks, is used to theorize the direct and indirect relationships between safety and the financial performance of NPPs. An Integrated Enterprise Risk Management (I-ERM) methodological framework is developed to operationalize SoTeRiA to quantify NPP safety and financial performance in a unified platform where their underlying physical degradation mechanisms, coupled with maintenance performance (considering human and organizational factors), are explicitly incorporated to depict the interconnections and dependencies between safety and financial performance. In this study, NPP safety refers to both occupational safety and system safety (estimated from Probabilistic Risk Assessment, PRA), and financial performance refers to the monetary values associated with NPP operation and maintenance (O&M) strategies. This report covers a case study demonstrating the feasibility of the I-ERM methodological framework. More detailed development of one of the I-ERM modules, i.e., Probabilistic Physics-of-Failure (PPoF) analysis, and its connection with other I-ERM modules is demonstrated in a second case study. The outcome of this research will help NPP decision-makers create cost-saving maintenance strategies while maintaining safety by providing cost- and risk-informed recommendations regarding maintenance work processes and operational strategies.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Cybersecurity assessment and risk management tool

Techniques and apparatuses are described for a cybersecurity risk management tool to assess cybersecurity risk and prioritize cybersecurity correction plans. The cybersecurity risk management tool categorizes cybersecurity framework security controls into maturity indicator levels, identifies implementation states achieved by an entity with respect to the cybersecurity framework security controls, and determines which of the maturity indicator levels represents the implementation state achieved by the entity with respect to each of the cybersecurity framework security controls. A cost-benefit analysis for modifying from the implementation state achieved by the entity to a next implementation state to be achieved by the entity with respect to the cybersecurity framework security controls is also enabled. The cost-benefit analysis leverages factored weights including aspects indicative of security perspectives, Gaussian distributions, and the maturity indicator levels.

Gourisetti, Sri Nikhil Gupta↗

Application of Banking Scoring and Rating for Coherent Risk Measures in Electricity Systems ABSCORES

This project developed a framework for asset and system risk management that can be incorporated into current electricity system operations to improve economic efficiency and establish an Electric Assets Risk Bureau. We leveraged scoring and ratings from banking and financial institutions alongside current optimization methods in dispatching power systems to help system operators and electricity markets schedule resources. This approach is based on the observation that there are major discrepancies between the power scheduled by a system operator and the actual power generated/consumed. These discrepancies—exacerbated by unplanned contingencies (e.g., natural disasters)—are caused by multiple factors, including the different financial, environmental and risk preferences of power producers, consumers, and aggregators. We developed a framework that counteracts two failures in electricity system operations: imperfect information and missing markets for products. The technical approach included five tasks. Tasks 1 and 2 supported the development of risk scores at the asset level with historical data collected for this project. Tasks 3, 4, and 5 incorporated scoring into decision-making at the system level. The proposed effort achieved PERFORM's Program Objectives because the proposed outputs and algorithms do not exist in the electricity industry and are an innovative approach to managing risk. Since the acknowledged need to better assess and act upon risk profiles for grid assets has not been met by the industry, this project will also impact ARPA-E's Mission Areas, including improving energy efficiency and giving the U.S. a technological lead in advanced energy technologies.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Modeling interconnections of safety and financial performance of nuclear power plants, part 3: Spatiotemporal probabilistic physics-of-failure analysis and its connection to safety and financial performance

Here, this paper is a byproduct of a line of research by the authors to analyze interrelationships of safety and financial performance of nuclear power plants (NPPs). The result of this line of research is summarized in three parts: Part 1 covers a categorical review of relevant literature and the theoretical bases that support the methodological developments in Part 2. Part 2 introduces an Integrated Enterprise Risk Management (I-ERM) methodological framework to quantify the interconnections of safety and financial performance with a focus on operation and maintenance (O&M) of NPPs. Part 2 has also demonstrated the applicability and values of the I-ERM methodology through an NPP case study. This paper is Part 3, where detailed development and implementation of one of the I-ERM modules, i.e., probabilistic physics-of-failure (PPoF) analysis, and its connection with safety and financial performance is reported. In this article, the physical failure modeling for hardware components is advanced by incorporating finite element analysis (FEA) into PPoF analysis and coupling the FEA-based PPoF with the maintenance performance through a renewal process model. This article covers two scientific contributions: (i) first-of-its-kind incorporation of FEA into the PPoF model of thermal fatigue for NPP components; and (ii) advancing the interface between the PPoF analysis and the renewal process model in order to deal with spatiotemporal FEA outputs and to efficiently estimate the physical transition rates even when the PPoF outputs are dominated by success data. Through the incorporation of FEA, the resolution of the PPoF analysis is enhanced as spatiotemporal conditions such as stress and temperature can be considered explicitly instead of relying on simplified assumptions or analytical models with reduced spatiotemporal dimensions. To demonstrate an application of the FEA-based PPoF analysis and its coupling with maintenance through the renewal process model, a case study is conducted using excess letdown elbow piping in the chemical and volume control system of a Pressurized Water Reactor.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗