Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Total Probability of Collision as a Metric for Finite Conjunction Assessment and Collision Risk Management

On-orbit collision risk is becoming an increasing mission risk to all operational satellites in Earth orbit. Managing this risk can be disruptive to mission and operations, present challenges for decision-makers, and is time-consuming for all parties involved. With the planned capability improvements to detecting and tracking smaller orbital debris and capacity improvements to routinely predict on-orbit conjunctions, this mission risk will continue to grow in terms of likelihood and effort. It is very real possibility that the future space environment will not allow collision risk management and mission operations to be conducted in the same manner as it is today. This paper presents the concept of a finite conjunction assessment-one where each discrete conjunction is not treated separately but, rather, as a continuous event that must be managed concurrently. The paper also introduces the Total Probability of Collision as an analogous metric for finite conjunction assessment operations and provides several options for its usage in a Concept of Operations.

Conjunction Assessment

Risk Management for Ocean-Based Technologies [Slides]

This presentation discusses risk management for ocean-based technologies by stepping through elements of the National Laboratory of the Rockies' 2024 Marine Energy Technology Development Risk Management Framework.

16 TIDAL AND WAVE POWER

Improving Our Odds: Success through Continuous Risk Management

Launching a rocket, running a business, driving to work and even day-to-day living all involve some degree of risk. Risk is ever present yet not always recognized, adequately assessed and appropriately mitigated. Identification, assessment and mitigation of risk are elements of the risk management component of the "continuous improvement" way of life that has become a hallmark of successful and progressive enterprises. While the application of risk management techniques to provide continuous improvement may be detailed and extensive, the philosophy, ideals and tools can be beneficially applied to all situations. Experiences with the use of risk identification, assessment and mitigation techniques for complex systems and processes are described. System safety efforts and tools used to examine potential risks of the Ares I First Stage of NASA s new Constellation Crew Launch Vehicle (CLV) presently being designed are noted as examples. Recommendations from lessons learned are provided for the application of risk management during the development of new systems as well as for the improvement of existing systems. Lessons learned and suggestions given are also examined for applicability to simple systems, uncomplicated processes and routine personal daily tasks. This paper informs the reader of varied uses of risk management efforts and techniques to identify, assess and mitigate risk for improvement of products, success of business, protection of people and enhancement of personal life.

Greenhalgh, Phillip O.

Guidelines for developing NASA (National Aeronautics and Space Administration) ADP security risk management plans

This report presents guidance to NASA Computer security officials for developing ADP security risk management plans. The six components of the risk management process are identified and discussed. Guidance is presented on how to manage security risks that have been identified during a risk analysis performed at a data processing facility or during the security evaluation of an application system.

Tompkins, F. G.

Summary of Results from the Risk Management Program for the Mars Microrover Flight Experiment

On 4 July 1997, the Mars Pathfinder landed on the surface of Mars carrying the first planetary rover, known as the Sojourner. Formally known as the Microrover Flight Experiment (MFEX), the Sojourner was a low cost, high-risk technology demonstration, in which new risk management techniques were tried. This paper summarizes the activities and results of the effort to conduct a low-cost, yet meaningful risk management program for the MFEX. The specific activities focused on cost, performance, schedule, and operations risks. Just as the systems engineering process was iterative and produced successive refinements of requirements, designs, etc., so was the risk management process. Qualitative risk assessments were performed first to gain some insights for refining the microrover design and operations concept. These then evolved into more quantitative analyses. Risk management lessons from the manager's perspective is presented for other low-cost, high-risk space missions.

Shishko, Robert

Obstacles to Practical Digital Supply Chain Risk Management in the Energy Sector

Cyber supply chain risk management (C-SCRM) programs must consider operations that depend on the lifecycles of digital components such as hardware, firmware, software, and services. We integrate academic literature, historical incidents, and existing standards to identify obstacles faced by C-SCRM programs.

Business Process Management & Integration

Bridging the Divide between Safety and Risk Management for your Project or Program

This presentation will bridge the divide between these separate but overlapping disciplines and help explain how to use Risk Management as an effective management decision support tool that includes safety. Risk Management is an over arching communication tool used by management to prioritize and effectively mitigate potential problems before they concur. Risk Management encompasses every kind of potential problem that can occur on a program or project. Some of these are safety issues such as hazards that have a specific likelihood and consequence that need to be controlled and included to show an integrated picture of accepted) mitigated, and residual risk. Integrating safety and other assurance disciplines is paramount to accurately representing a program s or projects risk posture. Risk is made up of several components such as technical) cost, schedule, or supportability. Safety should also be a consideration for every risk. The safety component can also have an impact on the technical, cost, and schedule aspect of a given risk. The current formats used for communication of safety and risk issues are not consistent or integrated. The presentation will explore the history of these disciplines, current work to integrate them, and suggestions for integration for the future.

Lutomski, Mike

Achieving a Risk-Informed Decision-Making Environment at NASA: The Emphasis of NASA's Risk Management Policy

This slide presentation reviews the evolution of risk management (RM) at NASA. The aim of the RM approach at NASA is to promote an approach that is heuristic, proactive, and coherent across all of NASA. Risk Informed Decision Making (RIDM) is a decision making process that uses a diverse set of performance measures along with other considerations within a deliberative process to inform decision making. RIDM is invoked for key decisions such as architecture and design decisions, make-buy decisions, and budget reallocation. The RIDM process and how it relates to the continuous Risk Management (CRM) process is reviewed.

Dezfuli, Homayoon

Security Risks: Management and Mitigation in the Software Life Cycle

A formal approach to managing and mitigating security risks in the software life cycle is requisite to developing software that has a higher degree of assurance that it is free of security defects which pose risk to the computing environment and the organization. Due to its criticality, security should be integrated as a formal approach in the software life cycle. Both a software security checklist and assessment tools should be incorporated into this life cycle process and integrated with a security risk assessment and mitigation tool. The current research at JPL addresses these areas through the development of a Sotfware Security Assessment Instrument (SSAI) and integrating it with a Defect Detection and Prevention (DDP) risk management tool.

securiy

Integrated risk management

The purpose of this report is to first present a basis or foundation for the building of an integrated risk management plan and them to present the plan. The integration referred to is across both the temporal and the hierarchical dimensions. Complexity, consequence, and credibility seem to be driving the need for the consideration of risk. Reduction of personal bias and reproducibility of the decision making process seem to be driving the consideration of a formal risk plan. While risk can be used as either a selection tool or a control tool, this paper concentrates on the selection usage. Risk relies on stated purpose. The tightness of the definition of purpose and success is directly reflected in the definition and control of risk. Much of a risk management plan could be designed by the answers to the questions of why, what, who, when, and where. However, any plan must provide the following information about a threat or risk: likelihood, consequence, predictability, reliability, and reproducibility. While the environment at NASA is seen as warm, but not hot, for the introduction of a risk program, some encouragement is seen if the following problems are addressed: no champion, no commitment of resource, confused definitions, lack of direction and focus, a hard sell, NASA culture, many choices of assessment methods, and cost. The plan is designed to follow the normal method of doing work and is structured to follow either the work break down structure or a functional structure very well. The parts of the plan include: defining purpose and success, initial threat assessment, initial risk assessment, reconciling threats and parameters, putting part of the information down and factoring the information back into the decision process as it comes back up, and developing inferences. Two major suggestions are presented. One is to build an office of risk management to be used as a resource by managers in doing the risk process. Another is to form a pilot program to try out the details in the plan and modify the method where needed.

Hunsucker, J. L.

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING

The background and theory of integrated risk management

While all good managers have always considered risk in their decision making, only recently have formal programs to do so been introduced. This report covers the logical structure behind the formulation of an integrated risk management plan (IRM). Included in the report are factors forcing the development of a formal plan to consider risk, the basic objective or purpose of an IRM, and desirable traits of such a plan. The report moves on to a discussion of background issues, seeks to formalize some definitions, and then discusses required information on threats. The report concludes with the steps for an IRM.

Hunsucker, John L.

A hierarchical-multiobjective framework for risk management

A broad hierarchical-multiobjective framework is established and utilized to methodologically address the management of risk. United into the framework are the hierarchical character of decision-making, the multiple decision-makers at separate levels within the hierarchy, the multiobjective character of large-scale systems, the quantitative/empirical aspects, and the qualitative/normative/judgmental aspects. The methodological components essentially consist of hierarchical-multiobjective coordination, risk of extreme events, and impact analysis. Examples of applications of the framework are presented. It is concluded that complex and interrelated forces require an analysis of trade-offs between engineering analysis and societal preferences, as in the hierarchical-multiobjective framework, to successfully address inherent risk.

Haimes, Yacov Y.

A Holistic Approach for Risk Management During Design

In this paper, an approach for the identification, assessment, mitigation and continuous management of risks during the process of designing a space mission is presented. This approach has been developed by observing the risk patterns that occur at the Project Design Center of the Jet Propulsion Laboratory (TeamX) which develops conceptual, concurrent design of Space Missions. TeamX develops an end-to-end conceptual design of a Space Mission in a matter of one or two weeks. As the risk chair in TeamX, the author has had the opportunity to observe the risk patterns that occur during design over the course of many design sessions. This paper introduces an abstraction and generalization of those patterns. Risk is defined as anything that can go wrong, along with its approximate likelihood and consequence. The indicators, and causes, and effects of these risks are cross cutting across the multiple levels of people and processes involved in the design, and the actual design product itself.

reliability analysis

Design and Testing of an Approach to Automated In-Flight Safety Risk Management for sUAS Operations

An onboard risk management automation design is presented based on run-time assurance principles, as well as the concept for In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. The automation is designed to operate independently of the autopilot and perform real-time risk assessment spanning multiple classes of hazards, predict constraint violations, and track autopilot states. In the event of elevated risk conditions or predicted constraint violations, the automation will select from a set of available contingencies and trigger autopilot mode changes if necessary to mitigate risk exposure. The onboard automation also informs the remote operator/pilot of what the independent monitor is observing and any contingency decisions or actions that may arise during flight. Details of an implementation of this design and results of verification and validation activities, as required to meet stringent NASA software and system assurance standards, are also presented. This includes simulation and flight testing using small unmanned aircraft systems.

Ersin Ancel

System-Level Integration of Modular Language Models for Real-Time Risk Assessment in Third-Party Risk Management Systems

Large enterprises typically rely on dedicated teams to govern and implement security measures throughout their supply chains, ensuring compliance with enterprise security procedures. There is a significant reliance on Third-Party Risk Management (TPRM) platforms, which often require complete, highly structured information from potential vendors. The review and compliance assurance processes are time- and labor intensive, often requiring several rounds of review between the supply chain security risk management teams, business users, and potential vendors, leading to delays in the supply chain processing and consumer experience. Significant challenges in the risk management paradigm include handling unstructured data in various formats and providing real-time feedback to users to reduce the required review time. This paper presents a novel solution to these challenges. A modular multi-step system architecture is proposed using advances in language processing, specifically for unstructured responses and provides real-time feedback (i.e., 3 seconds) so that users can improve their responses before the TPSRM team review. This novel system architecture will increase information accuracy and significantly reduce time and labor during the review process.

99 - GENERAL AND MISCELLANEOUS