Developing a Framework for Using In-Process Monitoring Data to Manage Risk in AM Hardware
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
The goal of this research is to theorize and quantify the relationships between safety and the financial performance of nuclear power plants (NPPs). The Socio-Technical Risk Analysis (SoTeRiA) theoretical framework, which connects the social aspects (e.g., safety culture) and structural features (e.g., safety practices) of an organization with organizational safety and financial risks, is used to theorize the direct and indirect relationships between safety and the financial performance of NPPs. An Integrated Enterprise Risk Management (I-ERM) methodological framework is developed to operationalize SoTeRiA to quantify NPP safety and financial performance in a unified platform where their underlying physical degradation mechanisms, coupled with maintenance performance (considering human and organizational factors), are explicitly incorporated to depict the interconnections and dependencies between safety and financial performance. In this study, NPP safety refers to both occupational safety and system safety (estimated from Probabilistic Risk Assessment, PRA), and financial performance refers to the monetary values associated with NPP operation and maintenance (O&M) strategies. This report covers a case study demonstrating the feasibility of the I-ERM methodological framework. More detailed development of one of the I-ERM modules, i.e., Probabilistic Physics-of-Failure (PPoF) analysis, and its connection with other I-ERM modules is demonstrated in a second case study. The outcome of this research will help NPP decision-makers create cost-saving maintenance strategies while maintaining safety by providing cost- and risk-informed recommendations regarding maintenance work processes and operational strategies.
The SOVA algorithm was originally developed under the Resilient Systems and Operations Project of the Engineering for Complex Systems Program from NASA s Aerospace Technology Enterprise as a conceptual framework to support real-time autonomous system mission and contingency management. The algorithm and its software implementation were formulated for generic application to autonomous flight vehicle systems, and its efficacy was demonstrated by simulation within the problem domain of Unmanned Aerial Vehicle autonomous flight management. The approach itself is based upon the precept that autonomous decision making for a very complex system can be made tractable by distillation of the system state to a manageable set of strategic objectives (e.g. maintain power margin, maintain mission timeline, and et cetera), which if attended to, will result in a favorable outcome. From any given starting point, the attainability of the end-states resulting from a set of candidate decisions is assessed by propagating a system model forward in time while qualitatively mapping simulated states into margins on strategic objectives using fuzzy inference systems. The expected return value of each candidate decision is evaluated as the product of the assigned value of the end-state with the assessed attainability of the end-state. The candidate decision yielding the highest expected return value is selected for implementation; thus, the approach provides a software framework for intelligent autonomous risk management. The name adopted for the technique incorporates its essential elements: Strategic Objective Valuation and Attainability (SOVA). Maximum value of the approach is realized for systems where human intervention is unavailable in the timeframe within which critical control decisions must be made. The Far Ultraviolet Spectroscopic Explorer (FUSE) satellite, launched in 1999, has been collecting science data for eight years.[1] At its beginning of life, FUSE had six gyros in two IRUs and four reaction wheels. Over time through various failures, the satellite has been left with one reaction wheel on the vehicle skew axis and two gyros. To remain operational, a control scheme has been implemented using the magnetic torque rods and the remaining momentum wheel.[2] As a consequence, there are attitude regions where there is insufficient torque authority to overcome environmental disturbances (e.g. gravity gradient torques). The situation is further complicated by the fact that these attitude regions shift inertially with time as the spacecraft moves through earth s magnetic field during the course of its orbit. Under these conditions, the burden of planning targets and target-to-target slew maneuvers has increased significantly since the beginning of the mission.[3] Individual targets must be selected so that the magnetic field remains roughly aligned with the skew wheel axis to provide enough control authority to the other two orthogonal axes. If the field moves too far away from the skew axis, the lack of control authority allows environmental torques to pull the satellite away from the target and can potentially cause it to tumble. Slew maneuver planning must factor the stability of targets at the beginning and end, and the torque authority at all points along the slew. Due to the time varying magnetic field geometry relative to any two inertial targets, small modifications in slew maneuver timing can make large differences in the achievability of a maneuver.
The Space Life Sciences Directorate (SLSD) and Human Research Program (HRP) at the NASA/Johnson Space Center work together to address and manage the human health and performance risks associated with human space flight. This includes all human system requirements before, during, and after space flight, providing for research, and managing the risk of adverse long-term health outcomes for the crew. We previously described the framework and processes developed for identifying and managing these human system risks. The focus of this panel is to demonstrate how the implementation of the framework and associated processes has provided guidance in the management and communication of human system risks. The risks of early onset osteoporosis, CO2 exposure, and intracranial hypertension in particular have all benefitted from the processes developed for human system risk management. Moreover, we are continuing to develop capabilities, particularly in the area of information architecture, which will also be described. We are working to create a system whereby all risks and associated actions can be tracked and related to one another electronically. Such a system will enhance the management and communication capabilities for the human system risks, thereby increasing the benefit to researchers and flight surgeons.
Introduction: This case series describes the medical clearance of NASA astronauts after diagnosis of atrial fibrillation seeking to fly to the International Space Station (ISS). BACKGROUND: Atrial fibrillation is the most common sustained arrhythmia with increasing incidence with age and is associated with increased lifetime risk of stroke. Treatment may consist of pharmacologic rate control and anticoagulation. Although it is not yet known how spaceflight modifies risk of cardioembolic event or adverse treatment effects, these can have significant impact on mission and crew health for spaceflight and granting a medical waiver for flight is a complex, case-by-case consideration. Case Presentation: We reviewed all records of waivers granted by NASA for atrial fibrillation and flutter, and identified 6 cases (4 short-duration [<18 days] and 2 long-duration missions [>60 days]) where waiver was granted with subsequent spaceflight. DISCUSSION: NASA has approved astronauts with a history of atrial fibrillation or flutter for flight following an appropriate medical evaluation. With the high prevalence of atrial fibrillation in the general population, we anticipate that consideration of medical waiver will become increasingly common as commercial spaceflight grows. These cases provide a potential framework for risk assessment and management of this population, to balance potential risk modification inherent in the microgravity environment against implications to crew performance, mission success, and personal health of spaceflight participants
Techniques and apparatuses are described for a cybersecurity risk management tool to assess cybersecurity risk and prioritize cybersecurity correction plans. The cybersecurity risk management tool categorizes cybersecurity framework security controls into maturity indicator levels, identifies implementation states achieved by an entity with respect to the cybersecurity framework security controls, and determines which of the maturity indicator levels represents the implementation state achieved by the entity with respect to each of the cybersecurity framework security controls. A cost-benefit analysis for modifying from the implementation state achieved by the entity to a next implementation state to be achieved by the entity with respect to the cybersecurity framework security controls is also enabled. The cost-benefit analysis leverages factored weights including aspects indicative of security perspectives, Gaussian distributions, and the maturity indicator levels.
This project developed a framework for asset and system risk management that can be incorporated into current electricity system operations to improve economic efficiency and establish an Electric Assets Risk Bureau. We leveraged scoring and ratings from banking and financial institutions alongside current optimization methods in dispatching power systems to help system operators and electricity markets schedule resources. This approach is based on the observation that there are major discrepancies between the power scheduled by a system operator and the actual power generated/consumed. These discrepancies—exacerbated by unplanned contingencies (e.g., natural disasters)—are caused by multiple factors, including the different financial, environmental and risk preferences of power producers, consumers, and aggregators. We developed a framework that counteracts two failures in electricity system operations: imperfect information and missing markets for products. The technical approach included five tasks. Tasks 1 and 2 supported the development of risk scores at the asset level with historical data collected for this project. Tasks 3, 4, and 5 incorporated scoring into decision-making at the system level. The proposed effort achieved PERFORM's Program Objectives because the proposed outputs and algorithms do not exist in the electricity industry and are an innovative approach to managing risk. Since the acknowledged need to better assess and act upon risk profiles for grid assets has not been met by the industry, this project will also impact ARPA-E's Mission Areas, including improving energy efficiency and giving the U.S. a technological lead in advanced energy technologies.
This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.
This story is about an unlikely NASA mission to the Moon. It was unlikely because it was started with far too little time and too-little money to complete. It was unlikely because it was able to take chances to accept risk of failure. It was unlikely because it was searching for the unthinkable: water-ice on the moon... Figure 1-1: LCROSS Mission. The mission of the Lunar CRater Observation and Sensing Satellite (LCROSS) was to investigate the possibility of water ice in craters on the Moon s poles. This is certainly an interesting scientific topic in itself, but I intend to focus on the compelling experience of managing the LCROSS Project in the context of this storied Agency. Perhaps most interesting are the implications this story has for managing any development effort, lunar or not, and working a balance to achieve success. NASA is by design a risk-taking agency within the US Government. It could be argued that NASA s purpose in the aerospace community is to take on the really big challenges that either the corporate world can t afford, are not yet profitable endeavors, or are just too risky for private corporations to entertain. However, expectations of the Agency have evolved. A combination of grim human tragedies and some very public cost and schedule overruns have challenged the public s and Congress s tolerance for risk-taking within the Agency. NASA, which is supposed to be in the business of taking risks to do bold, difficult things, has become less and less able to do so within its cost framework. Yet effectively replacing prudent risk management with attempts to "risk-eliminate" is completely unaffordable. So where does risk-taking fit within the Agency, or within private/corporate organizations for that matter? Where astronauts play there is clearly concern about risk. When an organization puts humans in harm s way, it is understandably going to take extra effort to assure nobody gets hurt. Doing so, of course, costs money - a lot of money to pay for labor and hardware which is attempting to assure nothing will go wrong. Sophisticated designs, with doubly- or triply-redundant systems, extensive testing to verify those systems, and numerous engineering test units built to learn and evolve a hardware design, all drive the cost and time required to implement. Human spaceflight is an expensive business because of the exceptional system complexity and levels of assurance required for human space travel. What about missions that do not involve human spaceflight? What about missions whose potential failure will not take a human life, whose costs are small and whose urgency and importance are limited by design? A portfolio consisting of this type of mission can be designed to be risk tolerant, not requiring large expenditures to guarantee against failure. With the money saved, the number of missions that can be executed within the portfolio grows, or the total cost of the portfolio can be reduced. The NASA LCROSS mission is a pathfinder example of a low-cost, quick turn-around mission which struck a balance on mission risk, while accomplishing big objectives, like defining how we understand the Moon.
Here, this paper is a byproduct of a line of research by the authors to analyze interrelationships of safety and financial performance of nuclear power plants (NPPs). The result of this line of research is summarized in three parts: Part 1 covers a categorical review of relevant literature and the theoretical bases that support the methodological developments in Part 2. Part 2 introduces an Integrated Enterprise Risk Management (I-ERM) methodological framework to quantify the interconnections of safety and financial performance with a focus on operation and maintenance (O&M) of NPPs. Part 2 has also demonstrated the applicability and values of the I-ERM methodology through an NPP case study. This paper is Part 3, where detailed development and implementation of one of the I-ERM modules, i.e., probabilistic physics-of-failure (PPoF) analysis, and its connection with safety and financial performance is reported. In this article, the physical failure modeling for hardware components is advanced by incorporating finite element analysis (FEA) into PPoF analysis and coupling the FEA-based PPoF with the maintenance performance through a renewal process model. This article covers two scientific contributions: (i) first-of-its-kind incorporation of FEA into the PPoF model of thermal fatigue for NPP components; and (ii) advancing the interface between the PPoF analysis and the renewal process model in order to deal with spatiotemporal FEA outputs and to efficiently estimate the physical transition rates even when the PPoF outputs are dominated by success data. Through the incorporation of FEA, the resolution of the PPoF analysis is enhanced as spatiotemporal conditions such as stress and temperature can be considered explicitly instead of relying on simplified assumptions or analytical models with reduced spatiotemporal dimensions. To demonstrate an application of the FEA-based PPoF analysis and its coupling with maintenance through the renewal process model, a case study is conducted using excess letdown elbow piping in the chemical and volume control system of a Pressurized Water Reactor.
The proposed work will provide a holistic framework for cost-minimizing risk-informed maintenance planning, including inspection, in light water reactors (LWRs). Specifically, we develop a two-tier framework that (a) coarsely minimizes the total maintenance cost during the remaining normal operating cycle of the plant prior to the next scheduled outage (long-term), subject to safety requirements, and (b) uses the outputs of the first model to develop a secondary optimization model to finely schedule maintenance activities to maximize the financial impact of these activities in the next week (short-term).
Cybersecurity for industrial control systems is an important consideration that advance reactor designers will need to consider. How cyber risk is managed is the subject of on-going research and debate in the nuclear industry. This report seeks to identify potential cyber risks for advance reactors. Identified risks are divided into absorbed risk and licensee managed risk to clearly show how cyber risks for advance reactors can potentially be transferred. Absorbed risks are risks that originate external to the licensee but may unknowingly propagate into the plant. Insights include (1) the need for unification of safety, physical security, and cybersecurity risk assessment frameworks to ensure optimal coordination of risk, (2) a quantitative risk assessment methodology in conjunction with qualitative assessments may be useful in efficiently and sufficiently managing cyber risks, and (3) cyber risk management techniques should align with a risked informed regulatory framework for advance reactors.
With India’s ambitious renewable energy targets and decreasing rooftop solar prices, customer adoption of rooftop solar on Tamil Nadu’s distribution network is set to increase in the coming years. With that comes the challenge of how to assess the impact of these emerging distributed energy resources. In an effort to help with such an assessment, NREL has created a holistic analysis framework for Tamil Nadu Generation and Distribution Company (TANGEDCO). The Emerging technologies Management and Risk evaluation on distribution Grids Evolution (EMeRGE) analysis framework and tool will help TANGEDCO and other distribution companies (DISCOMs) in India analyze new interconnection applications and evaluate the system risk impact over time with new emerging DERs.
Previous planning and prioritization for LWR SNF management investigated the risks and uncertainties of deploying facilities such as consolidated interim storage [1, 2, 3, 4]. As part of that work, activities and milestones were collected into success precedence diagrams that charted a path to achieving facility deployment [1]. In that framework, activities are any research, development, design, or decision required to achieve an intermediate goal; milestones are activity endpoints and mark the completion of deliverables. Milestones can be thought of as achievements required to reach the final goal of facility deployment; activities are the means by which milestones are accomplished. In planning, activities and milestones are compiled into comprehensive flow charts that visualize the steps necessary for deployment. This framework has been used to quantify risks, timelines, and costs of deploying SNF management facilities.
The geologic storage of carbon dioxide (CO 2 ) is one method to help reduce or eliminate atmospheric CO 2 emissions. The sequestered CO 2 is originally captured from the atmosphere or from a stationary industrial source and subsequently injected into a deep subsurface porous rock formation. To facilitate the successful deployment of field scale carbon storage projects, the U.S. Department of Energy (DOE) is developing tools and protocols for defensible, science-based frameworks to quantify and mitigate risks associated with the long-term storage of CO 2 . This protocol specifically addresses the risk of induced seismicity due to injection in a geologic carbon storage (GCS) site. This integrated and risk-based protocol is a product of the U.S. DOE Fossil Energy’s National Risk Assessment Partnership (NRAP), a multi-year collaborative research effort of Los Alamos National Laboratory (LANL), Lawrence Berkeley National Laboratory (LBNL), Lawrence Livermore National Laboratory (LLNL), National Energy Technology Laboratory (NETL), and Pacific Northwest National Laboratory (PNNL). These recommended practices describe a set of 7 steps to evaluate, manage, communicate, and mitigate the risk of induced seismicity at GCS sites. The base methodology of the recommended practices follows a framework similar to the Protocol for Addressing Induced Seismicity Associated with Enhanced Geothermal Systems (Majer et al., 2012), developed for the Geothermal Technology Office of the U.S. DOE. These recommended practices present a framework to systematically assess the induced seismicity risk and quantify the associated uncertainties. These recommendations are based on current research and are sufficiently general to allow for modification and application to a variety of different types of sites. The substance of the recommended practices contained herein includes both technical and non-technical issues, and covers all operational stages of the GCS project lifecycle. They start at the preliminary risk assessment phase, continue through site assessment and characterization, include best practice communication and seismic monitoring plan methodologies, discuss the evaluation and mitigation of seismic hazard and risk, and closes with an exploration of operational management plans, which conclude when the induced seismicity risk abates back to background level. The focus of these recommendations is on actively managing the risks associated with induced seismicity by developing an actionable risk management plan that starts at the project proposal stage and continues through site closure through an iterative assessment and improvement process. The audience of this document is expected to include all interested stakeholders (e.g., operators, project developers, regulators, and the general public) and is expressly written to be accessible to this broad range of partners. This document is intended to disseminate knowledge gained through recent advances in the science of induced seismicity hazard and risk assessments, to provide updates based on recent experience gained by similar corollary injection-induced seismicity cases, and most importantly to establish a uniform framework to carry out a successful induced seismicity risk management plan for carbon storage projects in the future. These recommendations do not directly address any domestic or international regulations or standards. A complementary NRAP report makes recommendations for the assessment and management of environmental subsurface risks associated with unwanted fluid migration at GCS sites (Thomas et al., 2021) and should be referred to in order to address those additional GCS site risks.
The geologic storage of carbon dioxide (CO 2 ) is one method to help reduce or eliminate atmospheric CO 2 emissions. The sequestered CO 2 is originally captured from the atmosphere or from a stationary industrial source and subsequently injected into a deep subsurface porous rock formation. To facilitate the successful deployment of field scale carbon storage projects, the U.S. Department of Energy (DOE) is developing tools and protocols for defensible, science-based frameworks to quantify and mitigate risks associated with the long-term storage of CO 2 . This protocol specifically addresses the risk of induced seismicity due to injection in a geologic carbon storage (GCS) site. This integrated and risk-based protocol is a product of the U.S. DOE Fossil Energy’s National Risk Assessment Partnership (NRAP), a multi-year collaborative research effort of Los Alamos National Laboratory (LANL), Lawrence Berkeley National Laboratory (LBNL), Lawrence Livermore National Laboratory (LLNL), National Energy Technology Laboratory (NETL), and Pacific Northwest National Laboratory (PNNL). These recommended practices describe a set of 7 steps to evaluate, manage, communicate, and mitigate the risk of induced seismicity at GCS sites. The base methodology of the recommended practices follows a framework similar to the $\textit{Protocol for Addressing Induced Seismicity Associated with Enhanced Geothermal Systems}$ (Majer et al., 2012), developed for the Geothermal Technology Office of the U.S. DOE. These recommended practices present a framework to systematically assess the induced seismicity risk and quantify the associated uncertainties. These recommendations are based on current research and are sufficiently general to allow for modification and application to a variety of different types of sites. The substance of the recommended practices contained herein includes both technical and non-technical issues, and covers all operational stages of the GCS project lifecycle. They start at the preliminary risk assessment phase, continue through site assessment and characterization, include best practice communication and seismic monitoring plan methodologies, discuss the evaluation and mitigation of seismic hazard and risk, and closes with an exploration of operational management plans, which conclude when the induced seismicity risk abates back to background level. The focus of these recommendations is on actively managing the risks associated with induced seismicity by developing an actionable risk management plan that starts at the project proposal stage and continues through site closure through an iterative assessment and improvement process. The audience of this document is expected to include all interested stakeholders (e.g., operators, project developers, regulators, and the general public) and is expressly written to be accessible to this broad range of partners. This document is intended to disseminate knowledge gained through recent advances in the science of induced seismicity hazard and risk assessments, to provide updates based on recent experience gained by similar corollary injection-induced seismicity cases, and most importantly to establish a uniform framework to carry out a successful induced seismicity risk management plan for carbon storage projects in the future. These recommendations do not directly address any domestic or international regulations or standards. A complementary NRAP report makes recommendations for the assessment and management of environmental subsurface risks associated with unwanted fluid migration at GCS sites (Thomas et al., 2021) and should be referred to in order to address those additional GCS site risks
The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.
Recent studies have showcased the use of process-based hydrological models with Stochastic Storm Transposition (SST) techniques to conduct Flood Frequency Analysis (FFA). This framework, referred hereby FFA-SST, has proved to be a robust strategy to estimate peak flows of specific annual exceedance probability (e.g., 100-year peak flow) that can reflect natural and anthropogenic disturbances, including changes in land use and meteorological patterns. With the objective of advancing the FFA-SST framework, this study presents for the first time the use of an Integrated Surface-Subsurface Hydrological Model (ISSHM) to conduct FFA-SST by extending the analysis from peak flow responses to flood extent, enabling a unique view and analysis of flood hazard and population flood exposure at the basin scale. As a proof-of-concept, we used the ISSHM, Advanced Terrestrial Simulator (Amanzi-ATS) model, and the SST model, RainyDay, to conduct FFA-SST by simulating the flood response to 5,000 annual synthetic storm events in a 2,227 $km^2$ Southeast Texas watershed. We demonstrate that ATS, without site-specific calibration, provides a robust process-based representation of peak flows, flood extent, streamflow, evapotranspiration, soil moisture content, and water storage changes. Our results and analyses, covering frequency curves up to a 500-year return period for peak flows, basin inundation fractions, and the number of people exposed to flooding, offer a unique perspective to analyze flood impacts across spatial scales. Overall, this study provides critical insights for flood risk management by extending the FFA-SST framework to include both flood hazard and population flood exposure analyses at the basin scale. Such an approach will empower stakeholders and disaster emergency agencies with a more comprehensive understanding of flood impacts across the entire basin domain, facilitating informed decision-making for flood risk assessment and management.