Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “consequence prioritization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Risk Management and Risk Aversion, from Benefit to Impediment

Risk management is a critical tool for improving the probability of project success by identifying, assessing, prioritizing, and attempting to control threats to project realization. For industries that require high operational reliability due to the potential consequences of off-normal events, such as the nuclear, aerospace, and chemical sectors, a major focus of risk management is the preservation of process safety. Due to the nature of the processes or systems under consideration, the associated process safety analyses (such as risk and safety assessments) and safety features can require significant resources. These costs are typically tolerated either due to the need to satisfy regulatory requirements or based on the assumption that they generally decrease the occurrence of unwanted events and therefore improve the probability of project success. However, as the level of acceptable or tolerable risk from unwanted events decreases, the required resources necessary for ensuring and demonstrating satisfaction of these criteria can grow and in turn can become one of the dominant impediments to project success. This paper outlines a high-level theoretical framework for the consideration of dominant project risks, which includes potential project failure from both the occurrence of high consequence off-normal events and the inability to achieve project completion due to the resource needs and innovation losses associated with extreme risk aversion. Utilizing such an integrated approach permits an attempt to optimize the probability of successful project realization while also providing valuable insight into the proper level of acceptable risk. The work is presented as a first step, in hopes of spurring additional discussion and analysis regarding appropriate levels of risk tolerance and the balance of project benefits.

Grabaskas, David↗

Comprehensive characterization of protein–protein interactions perturbed by disease mutations

Technological and computational advances in genomics and interactomics have made it possible to identify how disease mutations perturb protein–protein interaction (PPI) networks within human cells. Here, we show that disease-associated germline variants are significantly enriched in sequences encoding PPI interfaces compared to variants identified in healthy participants from the projects 1000 Genomes and ExAC. Somatic missense mutations are also significantly enriched in PPI interfaces compared to noninterfaces in 10,861 tumor exomes. We computationally identified 470 putative oncoPPIs in a pan-cancer analysis and demonstrate that oncoPPIs are highly correlated with patient survival and drug resistance/sensitivity. Further, we experimentally validate the network effects of 13 oncoPPIs using a systematic binary interaction assay, and also demonstrate the functional consequences of two of these on tumor cell growth. In summary, this human interactome network framework provides a powerful tool for prioritization of alleles with PPI-perturbing mutations to inform pathobiological mechanism- and genotype-based therapeutic discovery.

59 BASIC BIOLOGICAL SCIENCES↗

Developing a Supply Chain Security Program

Amid growing concerns over foreign manufacturing for components and devices deployed in critical energy infrastructure, this research from the national labs will highlight best practices for developing and maintaining a supply chain security program. Tools for asset inventory, tips for developing and maintaining software- and hardware-bills-of-materials (SBOMs and HBOMs), recommended contractual language for vendor agreements, and identification of responsibilities will be shared. We discuss the one-time requirements to enable a successful supply chain security program and the best ways to operationalize this program for maximum impact, including development of robust practices for vulnerability tracking, patch management, and workarounds, with understanding of the reliability and uptime requirements for utilities. The recommendations shared are based on a cyber-informed engineering approach to identification of high-consequence impacts and the engineering controls related to supply chain management that can best mitigate these impacts. This approach allows for prioritization of resources. Additionally, we highlight relative up-front and ongoing costs associated with recommended controls. Viewers will leave with an understanding what a supply chain security program is, and what steps, prioritized for resource-constrained organizations, can build a robust program.

14 SOLAR ENERGY↗

Alignment of NASA’s Human System Risks with Technological Capability Gaps to Enable Integrated Research and Technology Development Strategic Planning

BACKGROUND: Radiation, reduced gravity, distance from earth, isolation and confinement, and habitation within artificially created and controlled life support environments are hazards that present risk to human space explorers. NASA’s Human System Risk Board (HSRB) maintains a set of twenty-nine different Human System Risks with subject matter experts from across the agency providing regular updates to the estimated likelihood and consequence associated with each risk. The Human Research Program (HRP) has historically used these risk classifications as a primary basis for identifying and prioritizing human research investments aimed at characterizing and/or mitigating the respective human system risks. In many cases, technology development is required to mature and validate risk mitigation strategies, however, NASA’s primary technology development programs have not typically used Human System Risks as a basis for strategic planning. A primary function of the Environmental Control and Life Support Systems (ECLSS) – Crew Health and Performance (CHP) System Capability Leadership Team (SCLT) is to continually identify, review, and update technological capability gaps and to establish and oversee multiyear strategic roadmaps aimed at guiding NASA’s technology development priorities in these areas. These roadmaps are intended to be agency-wide and independent of any program, directorate, or other organization within NASA. DESCRIPTION: The SCLT and HRP collaborated to establish a set of Human System Capability Gaps, which establish a formal linkage between the capability gaps used to prioritize investments across much of NASA, and the Human System Risks that are primarily used to inform and prioritize human research. This set of twenty-eight gaps was developed by subject matter experts, and each gap mapped to the primary associated Human System Risks. The gaps and risk mapping were then reviewed and approved via the HSRB, thereby formally aligning the research-focused Human System Risks with the technology-focused capability gaps. DISCUSSION: This effort has enabled development of integrated roadmaps and budget coordination with research and technology development activities that are formally linked to agency-recognized capability gaps and Human System Risks. Close and ongoing coordination between the SCLT, HRP, Mars Campaign Office, and the Health & Medical Technical Authority (HMTA) is essential to ensure alignment and prioritization of CHP-related research and technology development to enable NASA’s future exploration missions.

Andrew F J Abercromby↗

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS↗

Microcalorimeters with Germanium Thermistors for High Resolution Soft and Hard X-ray Astronomy

This is a progress report for the first year of a three year Space Research and Technology (SR&T) grant to continue the advancement of neutron transmutation doped (NTD-based) microcalorimeters. We have re-prioritized certain aspects of the statement of work and chose to emphasize issues of array development in the first year rather than wait until year two. Consequently, some of the projects scheduled for the first year were delayed to the second year. Here we report on our progress to: a) Build and test a 1 x 4 element array and to investigate electrical and thermal cross-talk; b) Build a multiplexed 4 channel analog pulse processor; c) Build a digital pulse processor that can accommodate 4 channels with independent triggers; d) Develop a proportional thermal baseline restoration system compatible with the constant voltage mode of microcalorimeter operation.

Silver, E.↗

Microcalorimeters with NTD and Expitaxial Germanium Thermistors for High Resolution X-Ray Spectroscopy

This is a progress report for the second year of a three year SR&T grant to continue the advancement of NTD-based microcalorimeters. We reported last year that we re-prioritized certain aspects of the statement of work and chose to emphasize issues of array development in the first year rather than wait until year two. Consequently, some of the projects scheduled for the first year were delayed to the second year and we report on those topics here. These include: a) Measurements that map out JFET , thermistor, l/f and feedback resistor noise; b) Investigations that evaluate the limits of the JFET preamplifier circuitry as it pertains to stability at the 2 eV level; The results of a) and b) have led to preliminary measurements that demonstrate 3.08 eV resolution at 6 keV. c) Calculations that can predict the current performance.

Silver, Eric↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Training for Aviation Decision Making: The Naturalistic Decision Making Perspective

This paper describes the implications of a naturalistic decision making (NDM) perspective for training air crews to make flight-related decisions. The implications are based on two types of analyses: (a) identification of distinctive features that serve as a basis for classifying a diverse set of decision events actually encountered by flight crews, and (b) performance strategies that distinguished more from less effective crews flying full-mission simulators, as well as performance analyses from NTSB accident investigations. Six training recommendations are offered: (1) Because of the diversity of decision situations, crews need to be aware that different strategies may be appropriate for different problems; (2) Given that situation assessment is essential to making a good decision, it is important to train specific content knowledge needed to recognize critical conditions, to assess risks and available time, and to develop strategies to verify or diagnose the problem; (3) Tendencies to oversimplify problems may be overcome by training to evaluate options in terms of goals, constraints, consequences, and prevailing conditions; (4) In order to provide the time to gather information and consider options, it is essential to manage the situation, which includes managing crew workload, prioritizing tasks, contingency planning, buying time (e.g., requesting holding or vectors), and using low workload periods to prepare for high workload; (5) Evaluating resource requirements ("What do I need?") and capabilities ("'What do I have?" ) are essential to making good decisions. Using resources to meet requirements may involve the cabin crew, ATC, dispatchers, and maintenance personnel; (6) Given that decisions must often be made under high risk, time pressure, and workload, train under realistic flight conditions to promote the development of robust decision skills.

Orasanu, Judith↗

Securing Distributed Energy Resource Integration

The penetration of distributed energy resources (DER) is growing at much higher rates than predicted 20 years ago. Far from being used only in residential settings, DER are now installed on distribution and transmission circuits. In this position, they do not have the same properties as traditional generators and are more flexible in many cases. The growing penetration and range of uses for DER motivate the need to reliably and safely integrate them into the grid. Operators must be able to rely on them not only for normal operation, but also during abnormal conditions like black starts or adverse cyber scenarios. To that end, we study the communications, device interfaces, and potential consequences of DER operation under abnormal and adversarial conditions. The weaknesses of communications networks are studied based on the industrial protocols used, and the benefits of security features are examined. The device interfaces are found to be vulnerable to attack based on the requirements in the IEEE-1547 standard for DER interconnection and interoperability, which is expected to be adopted in the next ten years. In addition to exploring the requirements of the standard, we show that these vulnerabilities and others do exist and can be used maliciously in a modern storage system DER. Consequences of these vulnerabilities range from exacerbated grid instability, to simultaneous loss of large portions of DER penetration, to physical damage to inverters or DER themselves and other sensitive equipment. We tie these outcomes to specific attacker actions in an effort to give operators a better threat intelligence view that allows them to prioritize mitigations. Finally, we discuss mitigations that could prevent many of the adversarial scenarios described. Some solutions can be added to existing infrastructure, while others may require longer term planning for grid modernization with consideration for security.

25 ENERGY STORAGE↗

Determining the Relative Criticality of Diverse Exploration Risks in NASA's Human Research Program

The mission of NASA s Human Research Program (HRP) is to understand and reduce the risk to crew health and performance in exploration missions. The HRP addresses 27 specific risks, primarily in the context of Continuous Risk Management. Each risk is evaluated in terms of two missions (a six month stay on the Moon and a thirty month round trip to Mars) and three types of consequences (in-mission crew health, post-mission crew health, and in-mission performance). The lack of a common metric between the three consequence scales, such as financial costs or quality adjusted life years lost, makes it difficult to compare the relative criticality of the risks. We are, therefore, exploring the use of a ternary scale of criticality based on the common metric of influencing an operational decision. The three levels correspond to the level of concern the risk generates for a "go/no-go" decision to launch a mission: 1) no-go; 2) go with significant reservations; 3) go. The criticality of each of the 27 risks is scored for the three types of consequence in both types of mission. The scores are combined to produce an overall criticality rating for each risk. The overall criticality rating can then be used to guide the prioritization of resources to affect the greatest amount of risk reduction.

Kundrot, Craig E.↗

Development of Integrated Safety and Security Models for Comprehensive Reliability and Resiliency Evaluation

The security of the electric grid and supporting energy systems is crucial to national security. One of the complexities in analyzing the security of energy systems is the safety consequences that may result from accidents. For energy systems, the goal is to ensure that they operate as intended and that any consequences are mitigated or prevented. The integration of safety and security is paramount to protecting these systems from attacks and ensuring that large consequences are prevented. This report describes an integrated safety and security methodology to evaluate cybersecurity events that can lead to large consequences. This novel approach first describes how Systems-Theoretic Process Analysis (STPA) provides a digital causal analysis for Bayesian Networks (BNs). The use of STPA causal analysis provides a systematic approach to constructing BNs that adequately model cyber scenarios that result in consequences. When combined with the technical principles described in Risk-Informed Management of Enterprise Systems (RIMES), a comprehensive risk-informed cybersecurity analysis results that allows decision-makers to prioritize systems that most impact risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The NASA Continuous Risk Management Process

As an intern this summer in the GRC Risk Management Office, I have become familiar with the NASA Continuous Risk Management Process. In this process, risk is considered in terms of the probability that an undesired event will occur and the impact of the event, should it occur (ref., NASA-NPG: 7120.5). Risk management belongs in every part of every project and should be ongoing from start to finish. Another key point is that a risk is not a problem until it has happened. With that in mind, there is a six step cycle for continuous risk management that prevents risks from becoming problems. The steps are: identify, analyze, plan, track, control, and communicate & document. Incorporated in the first step are several methods to identify risks such as brainstorming and using lessons learned. Once a risk is identified, a risk statement is made on a risk information sheet consisting of a single condition and one or more consequences. There can also be a context section where the risk is explained in more detail. Additionally there are three main goals of analyzing a risk, which are evaluate, classify, and prioritize. Here is where a value is given to the attributes of a risk &e., probability, impact, and timeframe) based on a multi-level classification system (e.g., low, medium, high). It is important to keep in mind that the definitions of these levels are probably different for each project. Furthermore the risks can be combined into groups. Then, the risks are prioritized to see what risk is necessary to mitigate first. After the risks are analyzed, a plan is made to mitigate as many risks as feasible. Each risk should be assigned to someone in the project with knowledge in the area of the risk. Then the possible approaches to choose from are: research, accept, watch, or mitigate. Next, all risks, mitigated or not, are tracked either individually or in groups. As the plan is executed, risks are re-evaluated, and the attribute values are adjusted as necessary. Metrics are established and monitored as tools for risk tracking. Also a trigger or threshold should be set on the metric data that indicates when an action is needed. Results of this tracking are usually evaluated and reported in a relevant format at weekly or monthly meetings. Choosing controls is the subsequent step, which involves the effects of the tracking. The three basic controls are: close, continue tracking, and re- plan. Finally communicate & document is the last step, but occurs throughout the process. It is vital that main risks, plans, changes, and progress are known by everyone in the project. A good way to keep everyone updated and inform other projects of common issues is by thoroughly documenting project risks. NASA sees value in risk management and believes that projects have greater probability or success by using the NASA Continuous Risk Management Process.

Pokorny, Frank M.↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Aerocapture Systems Analysis for a Titan Mission

Performance projections for aerocapture show a vehicle mass savings of between 40 and 80%, dependent on destination, for an aerocapture vehicle compared to an all-propulsive chemical vehicle. In addition aerocapture is applicable to multiple planetary exploration destinations of interest to NASA. The 2001 NASA In-Space Propulsion Program (ISP) technology prioritization effort identified aerocapture as one of the top three propulsion technologies for solar system exploration missions. An additional finding was that aerocapture needed a better system definition and that supporting technology gaps needed to be identified. Consequently, the ISP program sponsored an aerocapture systems analysis effort that was completed in 2002. The focus of the effort was on aerocapture at Titan with a rigid aeroshell system. Titan was selected as the initial destination for the study due to potential interest in a follow-on mission to Cassini/Huygens. Aerocapture is feasible, and the performance is adequate, for the Titan mission and it can deliver 2.4 times more mass to Titan than an all-propulsive system for the same launch vehicle.

Lockwood, Mary K.↗

Current Practices in Distribution Utility Resilience Planning for Winter Storms

This report is part of a series of hazard-focused case studies examining common practices in electric utility resilience planning. We use standard terminology defining resilience as the ability to anticipate, withstand, absorb, and recover from hazards that cause long duration outages. We distinguish between reliability and resilience using Institute of Electrical and Electronics Engineers (IEEE) 1366-2022, which defines major events as an event that exceeds reasonable design and/or operational limits of the electric power system. Resilience planning is focused on major event days and reliability planning is focused on nonmajor event days. Utility resilience plans are assessed according to common resilience components identified in existing resilience frameworks. The focus of this report is on winter storms in which the primary hazards are heavy snowfall, freezing rain, ice, extreme cold, severe wind, and flooding. These hazards can also contribute to generation shortages, resulting in bulk power system impacts that have consequences for the distribution system, such as load shedding. Stand-alone reports focusing on wildfires and nonwinter storms have been published in parallel with this report. This report can be used as a starting point for understanding potential investment prioritization processes and investment options. This report is intended to improve utility resilience planning by supporting constructive dialogue among utilities, regulators, and other stakeholders.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Bridging the Divide between Safety and Risk Management for your Project or Program

This presentation will bridge the divide between these separate but overlapping disciplines and help explain how to use Risk Management as an effective management decision support tool that includes safety. Risk Management is an over arching communication tool used by management to prioritize and effectively mitigate potential problems before they concur. Risk Management encompasses every kind of potential problem that can occur on a program or project. Some of these are safety issues such as hazards that have a specific likelihood and consequence that need to be controlled and included to show an integrated picture of accepted) mitigated, and residual risk. Integrating safety and other assurance disciplines is paramount to accurately representing a program s or projects risk posture. Risk is made up of several components such as technical) cost, schedule, or supportability. Safety should also be a consideration for every risk. The safety component can also have an impact on the technical, cost, and schedule aspect of a given risk. The current formats used for communication of safety and risk issues are not consistent or integrated. The presentation will explore the history of these disciplines, current work to integrate them, and suggestions for integration for the future.

Lutomski, Mike↗

Baseline Medical System Translation for the Impact Medical Database

NASA has developed a new evidence-based data-driven probabilistic risk assessment and tradespace analysis tool as a successor to the Integrated Medical Model (IMM). This updated decision support tool is known as IMPACT (Informing Mission Planning via Analysis of Complex Tradespaces). Whereas IMM focuses on the resources and risks associated with International Space Station (ISS) and Low Earth Orbit (LEO) missions, IMPACT estimates the frequency and consequences of medical conditions that might arise during exploration missions. One of the services offered by IMM is a series of generic or baseline medical systems associated with typical mission types or DRMs (Design Reference Missions), such that requestors may prioritize questions pertaining to the mission itself over the medical supplies indicated by the model outputs for that DRM. In a mission focused request, the appropriate baseline medical system is used in place of a prepared or optimized medical kit. In preparation, an effort was undertaken to create baseline systems of medical resources within IMPACT suitable for typical DRMs. Using an existing baseline medical system within IMM’s Integrated Medical Evidence Database (iMED) as a starting point, the resources found within the medical kit were compared to and substituted for equivalent resources available within the IMPACT MD (Medical Database). In consultation with clinicians with knowledge of IMPACT’s MD, each resource was matched as closely as possible to a similarly purposed resource in IMPACT, seeking to preserve the treatment capabilities and procedures offered by the IMM medical system while reconciling the differences in modeled resources and medical conditions between the models. To demonstrate the efficacy of this work, a prototype ISS medical system in IMPACT was translated from the baseline used in the IMM. The appropriate medical system was then run through its associated medical model to compare and validate the resultant risks and risk mitigation provided by each baseline ISS medical kit.

S Schwartz↗