Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “risk informed design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Techno-Economic Analysis for Co-Processing Fast Pyrolysis Liquid in Fossil Refineries

Recent work at the National Renewable Energy Laboratory (NREL) and throughout the bioenergy community has highlighted incentives associated with co-processing bio-intermediates in existing refineries to reduce capital costs associated with renewable fuels and chemicals production and reduce overall risk for emerging biomass conversion technologies. This presentation summarizes the techno-economic analysis results from the NREL-Petrobras collaboration that focused on refinery integration of fast pyrolysis oil through co-processing in the fluid catalytic cracking (FCC) process. The NREL-Petrobras work highlights the economic opportunity for refiners to engage in co-processing for low-carbon products and introduces the risks for refiners based on variability in crude and fossil-product markets. The NREL-Petrobras results also serve as a basis to inform policy design that reduces economic risk for refinery co-processing and repurposing opportunities. The final topics in the presentation highlight experimental capabilities and emerging analysis approaches at NREL and partner laboratories that support the development and commercial deployment of refinery utilization strategies.

bio-fuels↗

The Meaning of Risk for Safety, Security, and Safeguards in the Design of Advanced Nuclear Reactors

What is the meaning of risk as it applies to the design of advanced reactors in the disciplines of safety, security, and safeguards? How can we find common terminology for the concept of risk and how can we find interfaces between these disciplines? These are important questions that should be explored in order that they may be applied in an integrated manner for the most effective and efficient design approaches. Eliminating or minimizing risks is a key design driver that motivates and informs the development of nuclear reactors. For safety, risk is well understood and applied in Probabilistic Risk Assessments. For security, the risk-based concepts of vulnerability assessments and vital areas are all considered in designing security systems. For safeguards, the concept of risk is not formally defined, as it relates to the design and operation of nuclear reactors. International nuclear safeguards seek to reduce the risk of proliferation in the nuclear fuel cycle and as such the concept of risk does exist. Therefore, the current understanding of the “3S’ approach, which seeks to find the interfaces and conflicts between safety, security, and safeguards requires a thorough understanding of the role that the reduction of risk plays in all three disciplines. The intersection of risk for safety and security is now being developed as there is a strong correlation between reactor design and operations and their vulnerability to sabotage. The intersection of risk for security and safeguards has to date chiefly been focused on the nuclear material control and accounting systems, which are relied on by both the operator (State) and the IAEA. This paper explores the concept of risk in each of the three disciplines, how they interact, potential conflicts and interfaces , how these might be addressed and leveraged, and a notional framework for how this could be achieved.

Kovacic, Donald N↗

Utilization of the LMP Methodology in Support of the VTR Conceptual Safety Design Report

The Versatile Test Reactor (VTR) is a fast spectrum test reactor currently being developed in the United States under the direction of the US Department of Energy (DOE), Office of Nuclear Energy. The VTR is utilizing a risk-informed performance-based (RIPB) approach for design support and authorization by the DOE, derived from recent efforts by the US industry led Licensing Modernization Project (LMP). This document contains an overview of the implementation of the LMP approach in support of the VTR Conceptual Safety Design Report (CSDR). The work reported here is the result of studies supporting a VTR conceptual design, cost, and schedule estimate for DOE-NE to make a decision on procurement. As such, it is preliminary. The VTR RIPB authorization approach utilizes information from the probabilistic risk assessment (PRA), coupled with deterministic analyses, to aid in decision-making regarding the identification and categorization of safety basis events (SBEs), the classification of structures, systems, and components (SSCs), and the evaluation of defense-in-depth (DID) adequacy. As part of initial reactor design efforts, a VTR conceptual design PRA was developed to support the RIPB process, which focused on at-power internal events, with scoping analyses for seismic and sodium fire hazards. In addition to supporting numerous design studies, preliminary results from the RIPB approach and the VTR conceptual design PRA were utilized as the basis of the VTR CSDR. The initial identification and categorization of SBEs, SSC classification, and DID evaluation were contained within the CSDR, which was submitted to DOE in 2019 as part of the CD-1 submittal package. Following review, DOE approved the CSDR in April 2020 and the CD-1 package in late 2020. Valuable experience was gained through the implementation of the RIPB approach for design and authorization during the VTR conceptual design phase, which is summarized in this document. To the extent possible, this experience has been shared with the advanced reactor industry, through publications and participation in licensing tabletops, in addition to informing DOE:NE advanced reactor regulatory development efforts. Furthermore, the approval of the CSDR by the DOE as part of CD-1 represents a significant milestone in the use of RIPB approaches for advanced reactor licensing.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

Activity-based Informed Curtailment: Using Acoustics to Design and Validate Smart Curtailment to Reduce Risk to Bats at Wind Farms

Rapid expansion of renewable energy infrastructure is a key part of any global strategy to reduce the pace and severity of anthropogenic climate change, although the potential impacts of renewable energy infrastructure on wildlife are also becoming increasingly apparent. Bats appear vulnerable to population-level impacts from the cumulative effect of turbine-related fatalities at commercial wind energy facilities in North America, particularly as the industry continues to expand to meet renewable energy generation targets. Turbine curtailment is the most widely used and consistently effective method to reduce bat fatality rates and involves pitching turbine blades parallel to prevailing winds to restrict turbine rotation when turbines would otherwise be operating and capable of producing power. Recognizing the need to expand the wind industry while managing risk to bats highlights the need to understand and manage turbine-related impacts to bats more aggressively and strategically than the current use of blanket curtailment allows.

17 WIND ENERGY↗

Advancing Multi-Hazard Risk and Safety Considerations for Aging Nuclear Facilities

While probabilistic risk assessment (PRA) of nuclear facilities is expected to include internal and external hazards for a risk-informed and performance-based design, the current state of practice treats each hazard independently. However, such an independent treatment of hazards may not account for the correlations between different hazards and their response of and damage to the structures, systems, and components (SSCs) in a plant resulting in underestimating the overall risk. This project proposes to advance the multi-hazard PRA of nuclear facilities to more adequately evaluate concurrent hazards and contribute to an increased safety of nuclear plants. A framework for multi-hazard PRA will be developed by identifying concurrent hazard events (both internal and external) and event sequences that include interdependencies through the response of SSCs. An example application of the multi-hazard PRA framework will be demonstrated by considering a generic pressurized water reactor (PWR) subjected to seismic and internal flooding hazards. Computational models for the response of components will be developed to generated multi-hazard fragility surfaces under seismic and flooding loads. A PRA model consisting of event and fault trees will also be developed to quantify the multi-hazard risk profile and compare it with the independent hazard risk profile. Overall, by advancing the multi-hazard PRA of nuclear facilities, this project enhances nuclear safety and reduces costs by mitigating unforeseen consequences caused by correlations between concurrent hazards.

97 - MATHEMATICS AND COMPUTING↗

Optimizing Information Automation Using a New Method Based on System-Theoretic Process Analysis: Tool Development and Method Evaluation

This report is an update to a prior report that describes progress and findings for a program of research supporting the design and optimization of information automation systems for nuclear power plants. Much of the domestic nuclear fleet is currently focused on modernizing technologies and processes, including transitioning toward digitalization in the control room and throughout the plant, along with a greater interest in the use of automation, artificial intelligence, robotics, and other emerging technologies. While there are significant opportunities to apply these technologies toward greater plant safety, efficiency, and overall cost-effectiveness, optimizing their design and avoiding potential safety and performance risks depends on ensuring that human performance-related organizational and technical design issues are identified and addressed early in the design process. This report describes modeling tools and techniques, based on sociotechnical systems theory, to support these design goals and their application in the current research effort. The report is primarily intended for senior nuclear energy stakeholders, including regulators, corporate management, and senior plant management. We have developed and employed a method to design an optimized information automation ecosystem (IAE) based on the systems-theoretic constructs underlying sociotechnical systems theory in general and the Systems-Theoretic Accident Modeling and Processes (STAMP) approach in particular. We argue that an IAE can be modeled as an interactive information control system whose behavior can be understood in terms of dynamic control, feedback, and communication relationships amongst the system’s technical and organizational components. We have employed two STAMP-based tools in this effort. The first is Causal Analysis based on STAMP (CAST), an accident and incident analysis technique that was used to examine a performance- and safety-related incident at an industry partner’s plant involving the unintentional activation of an emergency diesel generator. This analysis provided insight into the behavior of the plant’s current information control structure within the context of a specific, significant event. The second tool is Systems Theoretic Process Analysis (STPA) which is a proactive risk analysis tool used to examine existing and potential, planned sociotechnical systems. STPA was used to identify risk factors in the current design of a generic nuclear power plant (NPP) preventive maintenance system. Our analyses focused on identifying near-term system improvements and longer-term design requirements for an optimized IAE system. CAST analysis findings indicate an important underlying contributor to the incident under investigation, and a significant risk to information automation system performance, was perceived time and schedule pressure, which exposed weaknesses in interdepartmental coordination between and within responsible plant organizations and challenged the resilience of established plant processes, until a human caused the eventual event. These findings are discussed in terms of their risk to overall system performance and their implications for information automation system resilience and brittleness. STPA findings exposed several areas of concern in the design of current preventive maintenance systems. We also present two preliminary information automation models. The proactive issue resolution (PIR) model is a test case of an information automation concept with significant near-term potential for application and subsequent reduction in significant plant events. The IAE model is a more general representation of a broader, plantwide information automation system and represents an end-state vision for our work. From our results, we have generated an initial set of preliminary system-level requirements and safety constraints for these models. We have also focused on early development of easy to learn, easy to use “transportable” tools for sociotechnical systems analysis. We intend these to be used by NPP personnel as a means of gaining reliable and relatively quick insight into (1) sociotechnical systems factors impacting incidents and accidents, (2) potential sociotechnical risk factors in existing or planned system designs, and (3) potential weaknesses in a system’s safety and/or information control structure. We conclude the report with a set of summary recommendations, a discussion of planned and potential follow-on research and development, and a draft list of system-level requirements and safety constraints for optimized information automation systems.

99 GENERAL AND MISCELLANEOUS↗

Impact of High-Reactivity Advanced Test Reactor Experiments on Photon Heating in Nearby Experiment Locations

The Advanced Test Reactor’s (ATR’s) distinctive ability to provide a wide range of irradiation conditions is attractive for programs pursuing fuel qualification experiments. These potentially high-fuel-load experiments are a relatively new development and produce unexplored effects on nearby experiments. Here, this paper explores how photon heating of such an experiment may affect other nearby experiment programs, ultimately serving to better inform decisions regarding experiment design and risks to programmatic goals. The MC21 (Monte Carlo for the 21st Century) code is used to model and study how gamma heat generation rates and axial effects impact different ATR positions. The results reveal that the proximity of a given experiment’s position to the high-fuel-load one can significantly alter that experiment’s expected axial profile.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Towards Risk-Informed Performance-Based Emergency Planning: Review of Regulation, Guidance, and Methods

At a fundamental level, nuclear facility safety is built upon the concept of defense-in-depth (DID), which entails multiple, independent layers of protection for public health and safety. Within the DID structure, emergency preparedness (EP) is the last layer of defense and provides reasonable assurance that adequate protective measures can and will be taken in the event of a radiological emergency. Over several decades, the EP regulatory framework has evolved in response to lessons learned from actual events, experience with maintaining and testing EP capabilities, and advances in a wide range of technologies. Furthering this evolution, recent developments in risk-informed performance-based (RIPB) design and licensing approaches provide an opportunity to leverage insights regarding the attributes of the specific facility and site to inform EP.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Approach and Model Used to Represent a Timeline Analysis for Security Design Enhancements

Next-generation reactors will be able to use risk to inform and performance base the licensing of many aspects of the reactor, facility, and site design, including attributes of physical security. There are several factors related to security, including site topography, reactor design, and physical protection system components, to consider when designing the physical protection system into the overall facility design and plan of operation. With the versatility of advanced reactors, especially micro reactors, methods are needed to simplify and quickly evaluate potential timelines for designing a site configuration. This report describes an approach to generate qualitative and quantitative insights using a risk-informed simulation. The modeling process is described in detail, focusing on three aspects: (1) the facility mission time (the time required to control the plant until safe), (2) the attacker timeline (the time to potential sabotage), and (3) the response timeline (the time to counter the facility attack). The modeling capabilities also are extended to include facility physical phenomena such as thermal-hydraulics and heat transfer to capture realistic representation of dynamic changes to a facility. While the plant models and examples are hypothetical and do not represent a real facility, these modeling approaches could be used for future security-by-design engineering in advanced reactors. The outputs and insights from the modeling approach may be used to modify and optimize the security posture of a facility by efficiently making modifications to the model and seeing the overall impact from the modification. Lastly, use of the approach described in this report can also provide the technical basis for a physical protection program, describing how the facility and security strategy will cope with off-normal events.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Bridging Equipment Reliability Data and Risk Informed Decisions in a Plant Operation Context

Industry equipment reliability and asset management programs are essential elements that help ensure the safe and economical operation of nuclear power plants. The effectiveness of these programs is addressed in several industry-developed and regulatory programs. The Risk-Informed Asset Management (RIAM) project is tasked to develop tools in support of the equipment reliability and asset management programs at nuclear power plants. These tools are designed to create a direct bridge between component health/lifecycle data and decision making (e.g., maintenance scheduling and project prioritization). The goal of this article is to provide a guide for specific use cases that the RIAM project is targeting. We have grouped uses cases into three main areas. The first area focuses on the analysis of equipment reliability data with a particular emphasis on condition-based data, such as test/surveillance reports and component monitoring data. The second area focuses on the integration of equipment reliability into system/plant reliability models to determine system/plant health and identify the components that are critical to maintain an operational system. Lastly, the third area manages plant resources, such as maintenance activities and replacement scheduling using optimization methods. Here the primary focus is on supporting typical system engineer decisions regarding maintenance activity scheduling and component aging management. This is performed in a risk-informed context where the term “risk” is broadly constructed to include both plant reliability and economics. This framework combines data analytics tools to analyze equipment reliability data with risk-informed methods designed to support system engineer decisions (e.g., maintenance and replacement schedules, optimal maintenance posture) in a customizable workflow.

97 - MATHEMATICS AND COMPUTING↗

Studies of Alternative Ventilation Configurations to Mitigate Airborne Exposure Risks in Office Spaces

The objective of this study was to evaluate the impact of alternative ventilation configurations on airflow patterns and potential exposure risks in office spaces. Two existing conference rooms at Sandia NM were modeled using Computational Fluid Dynamics (CFD) simulations to characterize airflow patterns and potential airborne exposure risks in well-mixed and once-through (through-flow) ventilation conditions. Multiple scenarios were studied to evaluate the impact of occupancy, Plexiglass barriers, and a modified-return airflow configuration. Experimental and visualization tests were also conducted to validate the well-mixed and through-flow models and findings. The simulations demonstrated that the modified-return airflow configuration that promoted through-flow conditions reduced pathogen concentrations within the space compared to the well-mixed airflow configuration; occupancy reduction only reduced the number of exposed individuals, and Plexiglass barriers had almost no effect. The experimentally measured air speeds at nine anemometer locations generally matched the simulated airflow velocities, and a fog-purge visualization test was also consistent with simulated results of plume movement and dissipation. The visualization tests demonstrated improvements in air change rate with the modified return, which promoted through-flow conditions, versus the original well-mixed ventilation configuration. The results of this study demonstrate that minor modifications to a space that promote through-flow conditions can improve air quality and reduce pathogen concentrations. Additional airflow modeling and testing of alternative occupied space configurations are recommended to further inform room designs that mitigate airborne exposure risks for occupants.

42 ENGINEERING↗

Software Verification and Validation Guidelines for Non-Linear Soil-Structure Interaction Analysis

Seismic analysis of structures, systems, and components (SSCs), including the consideration of soil-structure interaction (SSI) effects, is an important and required step in the design and licensing of nuclear power plant SSCs important to safety. Historically, the SSI analysis of nuclear structures has been performed using equivalent linear methods. However, there has been considerable industry investment in alternative seismic design and analysis approaches to reduce the construction cost of new reactors. Toward that goal and in alignment with the Licensing Modernization Project (LMP) framework, the Nuclear Regulatory Commission (US NRC) has proposed a risk-informed, performance-based approach to seismic design that allows inelastic response in those nuclear plant structures not required for confinement. As a complementary effort, reactor designers are exploring nonlinear seismic analysis methods to optimize structural designs and reduce construction costs.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

An Overview of the Risk Assessment Information System

This technical memorandum (TM) presents an overview of the Risk Assessment Information System (RAIS), a collection of web-based tools designed to assist with the environmental risk assessment process. The objective of the RAIS is to be a single resource for the risk assessment process, providing guidance when planning and performing the steps: data assessment, exposure assessment, toxicity assessment, and risk characterization. The RAIS evolved as a result of the initial remediation efforts at various United States (U.S.) Department of Energy (DOE) facilities. The goal was to increase the efficiency and transparency of the human health and ecological assessments being performed by DOE’s Office of Environmental Management, Oak Ridge Operations (ORO) office by providing a repository for toxicity information, physicochemical data, risk assessment procedures, standardized risk calculation methods, and web-based tools. Since the initial launch in 1996, the RAIS has expanded its user base outside of the federal government and now has users from over 100 countries, universities, states, and local governments. What sets the RAIS apart from other risk assessment sites are the publicly available, searchable toxicity and physicochemical databases and the wide range of chemical and radionuclide risk calculation tools. The purpose of this TM is to present the RAIS tools in order of the website menus and explain how they fit in the risk assessment process. In addition, this TM describes differences between the chemical and radionuclide tools of the RAIS. Screening level equations, chronic daily intake equations, and default exposure factors used in the chemical and radionuclide calculators are included in the appendices of this TM. This TM is not intended to be a detailed guide to risk assessment or the RAIS tools. The tools on the RAIS can be used to comply with procedures from multiple agencies, including but not limited to DOE, U.S. Environmental Protection Agency (EPA), U.S. Department of Defense (DoD), and many state governments. Further information on the RAIS tools can be found in the user guides and tutorials available on the webpage.

38 RADIATION CHEMISTRY, RADIOCHEMISTRY, AND NUCLEA↗

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

First-of-a-Kind Risk-Informed Digital Twin for Operational Decision Making

A digital twin (DT) is a digital model or a collection of models of a physical entity. DTs in the nuclear arena can be used from plant design through decommissioning. Decisions are typically a priori or made offline. Risk-informed decision making is identifying what can go wrong, its frequency, and the consequences of its failure. Ideally risk-informed decision making reflects the current state of the plant and provides a decision in real time. Traditionally, probabilistic risk assessments (PRAs) evaluate the failures of safety systems, the risk of core damage, and the offsite dose as the consequence. However, this DT evaluates the decisions on the control side rather than the protection side. It uses the same risk methods to probabilistically inform the decision-making process but in a different way. Rather than evaluating the risk of core damage, this DT evaluates the likelihood of avoiding a trip set point while maintaining plant safety. Performance-based assessments are identified via its probabilistic evaluation of operational alternatives based on system status. Because the purpose of the control system is to maintain system variables within prescribed operating ranges, upsets or challenges that can exceed a trip set point resulting in a plant transient and a challenge to plant mitigating systems based on actual plant conditions, are evaluated to safely maintain the plant within the operating ranges. The probabilistic portion of the model is autonomously and automatically adjusted, and the metric of interest (i.e. likelihood of avoiding a trip set point) is recalculated. The digital representation of the physical system (i.e. the DT) performs a deterministic performance–based assessment of the probabilistically identified alternatives identified to validate the probabilistic assessment. A decision-making algorithm selects the appropriate option based on the probabilistic and deterministic assessments and transmits a control signal to a component(s) to initiate a corrective action or informs an operator of its decision.

digital twin↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Georgetown University – SYSM 5630 Systems Integration Verification and Validation : Todd Noste

At Lawrence Livermore National Laboratory in the National Ignition Facility Optics Group, we use the systems engineering approach for project management and as a design tool. Systems engineering is used in a graded approach to design and project management that is based on risk, informing how much rigor to apply. The tools and techniques from systems engineering offer a framework to organize projects with everyone speaking the same language to provide consistent and repeatable project success that satisfies the stakeholders’ needs and meets the mission. The classes have provided a framework with tools for communicating system design, requirements, verification and validation, and an operational context.

42 ENGINEERING↗