Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Ground Risk Assessment Service Provider (GRASP) Development Effort as a Supplemental Data Service Provider (SDSP) for Urban Unmanned Aircraft System (UAS) Operations

NASA’s Unmanned Aircraft System (UAS) Traffic Management (UTM) project aims to enable the integration of new aviation paradigms such as Unmanned Aircraft Systems (UAS) while providing the necessary infrastructure for future concepts such as On-Demand Mobility (ODM) and Urban Air Mobility (UAM) operations in the National Airspace System (NAS). In order to do so, the UTM project has developed an architecture to allow communication among UAS operators, UAS Service Suppliers (USS), Air Navigation Service Providers (ANSP), and the public. As part of this framework, the Supplemental Data Service Providers (SDSP) are envisioned as model and/or data based services that disseminate essential or enhanced information to ensure safe operations within low-altitude airspace. These services include terrain and obstacle data, specialized weather data, surveillance, constraint information, risk monitoring, etc. This paper highlights the development efforts of a non-participant casualty risk assessment SDSP called Ground Risk Assessment Service Provider (GRASP) which assists operators with preflight planning. GRASP is based on the previously introduced UTM Risk Assessment Framework (URAF) and allows UAS operators to simulate and visualize potential non-participant casualty risks associated with their proposed flight. The risk assessment capability also allows operators to revise their flight plans if the casualty risks are determined to be above acceptable thresholds. GRASP is configured to account for future improvements including servicing airborne aircraft as part of NASA’s System-Wide Safety (SWS) project.

Ancel, Ersin↗

Automated Contingency Management for Water Recycling System

To enable effective management, planning, and operations for future missions that involve a crewed space habitat, operational support must be migrated from Earth to the habitat. Intelligent System Health Management technologies (ISHM) promise to enable the future space habitats to increase the safety and mission success while minimizing operational risks. In this paper, Water Recycling System (WRS) deployed at NASA Ames Research Center's Sustainability Base is used for verification and validation of the proposed solution. Our work includes the development of the WRS simulation model based on its dynamic physical characteristics and the design of Automatic Contingency Management (ACM) framework that integrates fault diagnosis and optimization. In WRS modeling, a nominal model with fault injectors is developed. Fault detection and isolation techniques are then developed for isolating causes and identifying the severity of the faults. Dynamic Programming (DP) based fault mitigation strategies are designed to accommodate the faults in the system. A series of simulations are presented with different fault modes and the results indicate that the proposed ACM system can alleviate the fault in the WRS optimally regarding energy consumption and effects of the fault.

Systems Health Management↗

Characterization of Evidence for Human System Risk Assessment

Understanding the kinds of evidence available and using the best evidence to answer a question is critical to evidenced-based decision-making, and it requires synthesis of evidence from a variety of sources. Categorization of human system risks in spaceflight, in particular, focuses on how well the integration and interpretation of all available evidence informs the risk statement that describes the relationship between spaceflight hazards and an outcome of interest. A mature understanding and categorization of these risks requires: 1) sufficient characterization of risk, 2) sufficient knowledge to determine an acceptable level of risk (i.e., a standard), 3) development of mitigations to meet the acceptable level of risk, and 4) identification of factors affecting generalizability of the evidence to different design reference missions. In the medical research community, evidence is often ranked by increasing confidence in findings gleaned from observational and experimental research (e.g., "levels of evidence"). However, an approach based solely on aspects of experimental design is problematic in assessing human system risks for spaceflight. For spaceflight, the unique challenges and opportunities include: (1) The independent variables in most evidence are the hazards of spaceflight, such as space radiation or low gravity, which cannot be entirely duplicated in terrestrial (Earth-based) analogs, (2) Evidence is drawn from multiple sources including medical and mission operations, Lifetime Surveillance of Astronaut Health (LSAH), spaceflight research (LSDA), and relevant environmental & terrestrial databases, (3) Risk metrics based primarily on LSAH data are typically derived from available prevalence or incidence data, which may limit rigorous interpretation, (4) The timeframe for obtaining adequate spaceflight sample size (n) is very long, given the small population, (5) Randomized controlled trials are unattainable in spaceflight, (6) Collection of personal and environmental data on the astronaut population may create opportunities for advanced analytics and human-environment modeling that goes beyond that achieved in isolated experimental designs; and (7) Translation of relevant research to operations is a complex, transdisciplinary enterprise in which the approach must apply across the physical, biological, behavioral, and social sciences. The approach to synthesizing evidence must address both source and fidelity of data, and reflect the most general attributes of quality of evidence in science and engineering: reliability and validity. The authors are developing a two-factor approach which includes the various kinds of evidence required to understand risks and for the integrated interpretation of all evidence that is essential to develop standards and countermeasures. A unified framework for aggregating and assessing different kinds of evidence provides a consistent, traceable, evidence-based decision-making process to translate research to operations in an environment where engineers, scientists, physicians, and managers all engage in analyzing the trade space of vehicle design, standards, requirements and solutions for spaceflight.

Steinberg, S. L.↗

Quantifying Cybersecurity Risk for NASA Missions

An end-to-end cyber risk assessment process is presented that is based on the combination of guidelines from the National Institute of Standards & Technology (NIST), the standard 5x5 risk matrix, and quantitative methods for generating loss exceedance curves. The NIST guidelines provide a framework for cyber risk assessment, and the standard 5x5 matrix is widely used across the industry for the representation of risk across multiple disciplines. Loss exceedance curves are a means of quantitatively assessing the loss that occurs due to a given risk profile. Combining these different techniques enables us to follow the guidelines, adhere to standard 5x5 risk management practices and develop quantitative metrics simultaneously. Our quantification process is based on the consideration of the NASA and JPL Cost Risk assessment modeling techniques as we define the cost associated with the cybersecurity risk profile of a mission as a function of the mission cost.

Miller, Robert L.↗

Mars Sample Return: Risk Management & Sample Safety Assessment

Returning samples from Mars has long been a major planetary science objective due to the high scientific value and transformative potential of the resulting data. An exciting dimension of this objective is the potential for the detection of ancient microbiological life, and the possibility of improving our understanding of the evolution of habitable environments on Mars and the development of life on Earth. To ensure that returned samples meet stringent planetary protection requirements and do not expose Earth to potential biohazards, the joint NASA/ESA Sample Receiving Project (SRP) assembled the Sample Safety Assessment Protocol Tiger Team (SSAP-TT). Members were recruited with the specific goal of creating a multi-disciplinary and internationally distributed team of experts in their respective fields across the federal government, academia, and private industry. This team was chartered with reassessing previous sample safety assessment strategies, defining what constitutes a biological hazard, developing a protocol to test for potential biohazards, and establishing a statistical framework to determine if samples are “safe” for release. The team developed a three-step protocol, supported by a Bayesian statistical framework, to assess whether returned samples contain potential biohazards that could present a risk to Earth’s biosphere. Initial conclusions indicated that an effective and comprehensive safety assessment protocol is feasible using modern techniques and does not require an excessive amount of sample consumption or traditional microbiological detection methodology. Herein, we will present an overview of the MSR SRP, the proposed safety assessment protocol, and how aspects of this novel approach can be applied to biological assessment in healthcare product manufacturing practices.

Alvin L Smith↗

Technology Readiness Level as the Foundation of Human Readiness Level

Communication of the maturity of technology through the program/product life cycles helps enhance risk management from the beginning and support decision-making strategies for research, development, and allocation of resources. Currently, many organizations use the technology readiness level (TRL) as a simple metric to indicate the maturity of the technology. This article will discuss the TRL history, define the TRL levels, show how the TRL relates to the technology life cycle, and how the TRL framework contributes to the human readiness level (HRL) structure. Through the TRL advantages and disadvantages, this article will show how the TRL falls short in numerous areas of engineering, including the integration readiness of system/subsystem components and assessment of the readiness of the technology to operate within the human capabilities and limitations. Yet the article also shows how the TRL serves as the foundation for HRL.

George Salazar↗

Separation Assurance in Urban Air Mobility Systems Using Shared Scheduling Protocols

Ensuring safe separation between aircraft is a critical challenge in air traffic management, particularly in urban air mobility (UAM) environments where high traffic density and low altitudes require precise control. In these environments, conflicts often arise at the intersections of flight corridors, posing significant risks. We propose a tactical separation approach leveraging shared scheduling protocols, originally designed for Ethernet networks and operating systems, to coordinate access to these intersections. Using a decentralized Markov decision process framework, the proposed approach enables aircraft to autonomously adjust their speed and timing as they navigate these critical areas, maintaining safe separation without a central controller. We evaluate the effectiveness of this approach in simulated UAM scenarios, demonstrating its ability to reduce separation violations to zero while acknowledging trade-offs in flight times as traffic density increases. Additionally, we explore the impact of non-compliant aircraft, showing that while shared scheduling protocols can no longer guarantee safe separation, they still provide significant improvements over systems without scheduling protocols.

Separation Assurance↗

Evaluating near-real time satellite flood mapping for humanitarian early action: a case study on the 2020 Cambodia floods

Forecast-based early action is an increasingly popular framework advocating for the use of numerical weather prediction to set objective, automatic conditions for roll-out of proactive flood risk reduction efforts. Within this field, there is a relatively young discourse regarding the potential value of satellite Earth observations and the optimal role that remote sensing should play in improving the efficacy and value of forecast-based early action for flood management. The Hydrological Remote Sensing Analysis for Floods tool (HYDRAFloods) was developed to provide automated, near real-time satellite-based flood extent maps to local governments, disaster managers, and humanitarian organizations. This research evaluates (a.) whether HYDRAFloods satisfactorily met needs identified by humanitarian partners during the October 2020 floods in Cambodia, and (b.) whether the novel additions of near real-time data and flood extent mapping resulted in demonstrable advantages over previous forecast-based flood early action systems as identified in the literature. From these results, the authors identify the technological and logistical limitations of the HYDRAFloods methodology and synthesize actionable recommendations for Earth observations practitioners seeking to better support forecast-based early action.

floods↗

SafeMAP: Safe Multi-Agent Planning Framework Based on Dynamic Probabilistic Risk Assessment

This paper proposes a risk-aware framework for Safe Multi-Agent Planning (SafeMAP) that unifies disparate models for multi-agent systems in a Markovian process that allows for simultaneous system health monitoring, decision making under uncertainty, and multi-agent system collaboration. As operations beyond low earth orbit mature, there is an increased need for autonomous cyber-physical systems with onboard decision making capabilities. Multi-agent cyber-physical systems in particular offer the potential of increased efficiency, resiliency, and mission capabilities for future applications such as multi-rover terrain operations, distributed satellite operations, and management of smart lunar habitats. SafeMAP utilizes physics-based models of each agent and the relevant components, probability models of the environment and component operational states, and reward models for mission-specific objectives such as scientific task completion or resource consumption. The output of SafeMAP is a set of mission plans that satisfy the mission objective under specified risk/reward constraints. A readable interpretation of each of these generated mission plans is provided as an additional output. SafeMAP has been demonstrated on a simulated case study involving a four-rover system performing surface mapping operations and science tasks. Results of this paper demonstrate SafeMAP’s ability to generate explainable mission plans that satisfy the mission objective while minimizing risk under nominal and off-nominal conditions.

Mohammad Hejase↗

SafeMAP: Safe Multi-Agent Planning framework based on Dynamic Probabilistic Risk Assessment

This paper proposes a risk-aware framework for Safe Multi-Agent Planning (SafeMAP) that unifies disparate models for multi-agent systems in a Markovian process that allows for simultaneous system health monitoring, decision making under uncertainty, and multi-agent system collaboration. As operations beyond low earth orbit mature, there is an increased need for autonomous cyber-physical systems with onboard decision making capabilities. Multi-agent cyber-physical systems in particular offer the potential of increased efficiency, resiliency, and mission capabilities for future applications such as multi-rover terrain operations, distributed satellite operations, and management of smart lunar habitats. SafeMAP utilizes physics-based models of each agent and the relevant components, probability models of the environment and component operational states, and reward models for mission-specific objectives such as scientific task completion or resource consumption. The output of SafeMAP is a set of mission plans that satisfy the mission objective under specified risk/reward constraints. A readable interpretation of each of these generated mission plans is provided as an additional output. SafeMAP has been demonstrated on a simulated case study involving a four-rover system performing surface mapping operations and science tasks. Results of this paper demonstrate SafeMAP’s ability to generate explainable mission plans that satisfy the mission objective while minimizing risk under nominal and off-nominal conditions.

Mohammad Hejase↗

Investigating Risks Due to Artemis EVA Tempo Via Probabilistic Risk Assessment

Spaceflight operations pose unique challenges to crew health, safety, and resource management. As space agencies and private companies continue to push the boundaries of human exploration, it is essential to understand the risks associated with Extravehicular Activities (EVAs) and develop strategies to mitigate them. The tempo at which EVAs are conducted – the total number and frequency of these activities – can have a profound impact on medical risks, resource consumption, and overall mission success. Probabilistic risk assessment (PRA) provides a powerful framework for evaluating complex systems and identifying potential hazards. Our work employs the Medical Extensible Dynamic Probabilistic Risk Assessment Tool (MEDPRAT) [1] to simulate mission events, occurrence and treatment of medical conditions, and track the utilization of resources. Coupled with the Evidence Library [2], a medical evidence base for exploration-class missions developed by the Exploration Medical Capability within NASA’s Human Research Program, we can estimate these risks with increased fidelity and optimize medical kit contents to meet specific mission requirements. This presentation provides a detailed examination of how EVA tempo influences medical risk estimates for a lunar surface design reference mission. A comprehensive analysis is conducted to assess the additional mass and volume burden imposed on medical kits required to maintain adequate levels of risk mitigation. Furthermore, we estimate the distribution of the number of successful EVAs completed based on the level of task impairment imposed by medical events and flight rules related to specific medical events, such as decompression sickness.

Modeling↗

An Approach for Identifying IASMS Services, Functions, and Capabilities From Data Sources

Assuring safety in the NAS with the inclusion of new entrants that are part of Advanced Air Mobility (AAM) will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using semi-autonomous/autonomous vehicles. Overcoming these AAM safety assurance challenges is the focus of the In-time Aviation Safety Management System (IASMS). The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs)designed to manage operational risks, identify unknown risks, and inform system design to mitigate risk. This paper describes a broad approach for identifying SFCs involving technology trends in research, assessment of known and unknown risks in safety reports, and causal and contributing factors in aviation accidents and incidents. This approach leverages these sources to identify potential SFCs that enable the Monitor, Assess, and Mitigate (M-A-M)functionality that represents the enabling framework of the IASMS.

Kyle Ellis↗

Resource Prospector (RP): A Cost-Effective Lunar Resource Pathfinder

Resource Prospector (RP) is an in-situ resource utilization (ISRU) technology demonstration mission under study by the NASA Human Exploration and Operations Mission Directorates (HEOMD). This clever mission is currently planned to launch in 2020 and will demonstrate extraction of oxygen, water and other volatiles, as well measure mineralogical content such as silicon and light metals, like aluminum and titanium, from lunar regolith. Expanding human presence beyond low-Earth orbit to asteroids and Mars will require the maximum possible use of local materials, so-called in-situ resources, and the moon presents a unique destination to conduct robotic investigations that advance ISRU capabilities, as well as providing significant exploration and science value. This mission is equally important; however, for how it executes as a risk-tolerant, cost-effective mission. RP follows on the path-finding approaches of the Lunar Crater Observation and Sensing Satellite (LCROSS) mission. The LCROSS mission confirmed the presence of water-ice on the moon, but also established a new lightweight-approach to project and mission execution which was considerably cheaper and faster than traditional NASA missions. RP has been designated as a Class D mission, just as LCROSS. This mission classification is the most risk-tolerant class of mission within the NASA risk framework and as such, is given more latitude to accept higher-levels of residual risk. The intention is that by saving monies normally spent attempting to assure a single missions success, more missions can be funded. A well-designed portfolio can accept occasional mission failure, as it still gets more done for the same investment of resources. This classification enables tailoring the NASA Policy Requirements (NPRs) to lighter-weight approaches to mission management and execution. RP is also studying both international and commercial partnerships as a means to maximize return on the investment. International partnerships provide both capabilities synergies and cost-sharing opportunities, while the evolving new space commercial options are revealing new approaches to acquiring cost-effective services, including the benefits of bundling services. Even the world of launch vehicles is changing, offering much less expensive access to space, especially if NASA is able to be flexible in how it approaches mission assurance. Finally, leveraging investments being made elsewhere within a program portfolio, can enable cost-savings by enabling two applications with one investment. RP will be the next pathfinder mission to both enable exploration capabilities for future missions, and continue to evolve cost-effective approaches for NASA.

Lunar↗

Adaptive Independent Verification and Validation (IV&V) Reduces Risk of Software Impacting Safety in Artemis Missions

The National Aeronautics and Space Administration (NASA) is asking more of its human spaceflight programs than ever before through the collective Artemis Missions. The NASA Independent Verification and Validation (IV&V) Program contributes to NASA’s human spaceflight goals by providing IV&V services for NASA’s critical spacecraft and ground software. The IV&V Program is tasked with providing assurance from both individual and integrated mission software perspectives. The Artemis IV&V organization is actively supporting six distinct development efforts: Orion, the Space Launch System (SLS), Exploration Ground Systems (EGS), Mission Control Center (MCC), the Lunar Gateway, and the Human Landing System (HLS), representing a wide diversity of developer organizations, management structures, and development approaches. With much of this extremely complex flight and ground software being essential to human safety both on the ground and in space, Artemis IV&V is likewise challenged to provide more value-added assurance to future Artemis missions within a constrained budget. To meet this challenge, Artemis IV&V employs a variety of novel and evolving “Adaptive IV&V” approaches for planning and executing IV&V analysis to increase both the efficiency and effectiveness of the IV&V Program’s assurance activities, and to address the difficulties imposed by assuring software for a large, highly integrated, multi-mission enterprise managed and executed by physically and organizationally distinct programs. Instilling agile principles like iterative planning cycles, self-organizing teams, and regular retrospectives, into IV&V planning and execution has led to a more rapid turnaround of a minimum viable assurance product and allowed for increased alignment of assurance activities with development progress. Adopting an assurance case methodology has led to greater consistency and clearer communication of assurance design and provided a foundation for long-term maintenance of assurance plans, products, and results across missions. The IV&V-developed Assurance / Safety Case Analytical Network (A-SCAN) framework and tool has enabled the quantification and tracking of system/software risk and confidence. These confidence measures provide a means to repeatedly express the impact of planned and completed assurance work and the remaining residual risk. Applied as part of a “Follow-the-Risk” organizational ethos, this allows consistent rightsizing of analysis rigor and intensity commensurate with the perceived risk of defects, as well as appropriate targeting of the highest risk areas of the software to find safety issues before they can manifest. Finally, the development of the IV&V Advanced Risk Reduction Integrated Software Test and Operations Tri-program Lightweight Environment (ARRISTOTLE), an integrated software-only simulation of Orion, SLS, and EGS systems, has made it possible to independently test integrated pad and flight scenarios and inject faults to observe how the Artemis multi-program, mission software behaves in degraded modes and in response to hazards. These adaptive IV&V investments have enabled Artemis IV&V to become more efficient and effective in IV&V planning and execution and respond more readily to changes in the risk landscape, increasing the breadth and depth of risk reduction possible within the available resources. Residual risk tracking allows IV&V to communicate more effectively with stakeholders, both internal and external at all levels, and inform key decision-making personnel. This evolving assurance design approach provides IV&V surety that work is performed in the highest risk, most value-added areas of the software, to keep our astronauts and ground crews safe and ensure mission success.

Gerek A Whitman↗

Adaptive Independent Verification and Validation (IV&V) Reduces Risk of Software Impacting Safety in Artemis Missions

The National Aeronautics and Space Administration (NASA) is asking more of its human spaceflight programs than ever before through the collective Artemis Missions. The NASA Independent Verification and Validation (IV&V) Program contributes to NASA’s human spaceflight goals by providing IV&V services for NASA’s critical spacecraft and ground software. The IV&V Program is tasked with providing assurance from both individual and integrated mission software perspectives. The Artemis IV&V organization is actively supporting six distinct development efforts: Orion, the Space Launch System (SLS), Exploration Ground Systems (EGS), Mission Control Center (MCC), the Lunar Gateway, and the Human Landing System (HLS), representing a wide diversity of developer organizations, management structures, and development approaches. With much of this extremely complex flight and ground software being essential to human safety both on the ground and in space, Artemis IV&V is likewise challenged to provide more value-added assurance to future Artemis missions within a constrained budget. To meet this challenge, Artemis IV&V employs a variety of novel and evolving “Adaptive IV&V” approaches for planning and executing IV&V analysis to increase both the efficiency and effectiveness of the IV&V Program’s assurance activities, and to address the difficulties imposed by assuring software for a large, highly integrated, multi-mission enterprise managed and executed by physically and organizationally distinct programs. Instilling agile principles like iterative planning cycles, self-organizing teams, and regular retrospectives, into IV&V planning and execution has led to a more rapid turnaround of a minimum viable assurance product and allowed for increased alignment of assurance activities with development progress. Adopting an assurance case methodology has led to greater consistency and clearer communication of assurance design and provided a foundation for long-term maintenance of assurance plans, products, and results across missions. The IV&V-developed Assurance / Safety Case Analytical Network (A-SCAN) framework and tool has enabled the quantification and tracking of system/software risk and confidence. These confidence measures provide a means to repeatedly express the impact of planned and completed assurance work and the remaining residual risk. Applied as part of a “Follow-the-Risk” organizational ethos, this allows consistent rightsizing of analysis rigor and intensity commensurate with the perceived risk of defects, as well as appropriate targeting of the highest risk areas of the software to find safety issues before they can manifest. Finally, the development of the IV&V Advanced Risk Reduction Integrated Software Test and Operations Tri-program Lightweight Environment (ARRISTOTLE), an integrated software-only simulation of Orion, SLS, and EGS systems, has made it possible to independently test integrated pad and flight scenarios and inject faults to observe how the Artemis multi-program, mission software behaves in degraded modes and in response to hazards. These adaptive IV&V investments have enabled Artemis IV&V to become more efficient and effective in IV&V planning and execution and respond more readily to changes in the risk landscape, increasing the breadth and depth of risk reduction possible within the available resources. Residual risk tracking allows IV&V to communicate more effectively with stakeholders, both internal and external at all levels, and inform key decision-making personnel. This evolving assurance design approach provides IV&V surety that work is performed in the highest risk, most value-added areas of the software, to keep our astronauts and ground crews safe and ensure mission success.

Gerek Whitman↗

Systemic Risk

Systemic risk is the name given to impacts that spread within and across systems and sectors (e.g. ecosystems, health, infrastructure and the food sector) via the movements of people, goods, capital and information within and across boundaries (e.g. regions, countries and continents). The spread of these impacts can lead to potentially existential consequences and system collapse across a range of time horizons. Globalization contributes to systemic risk affecting people worldwide. The impacts of climate change or COVID-19 show how the challenges of addressing systemic risk go beyond conventional risk management and governance. Critical system interdependencies, amplified by underlying vulnerabilities, highlight that there is a growing need to better understand cascading impacts, systemic risks and the possible political (governance) and societal responses. This includes improving our understanding of the root causes of systemic risk, both biophysical and socio-economic, and related information needs. Addressing contemporary challenges in terms of systemic risk requires integrating different systems perspectives and fostering system thinking, while implementing key intergovernmental agendas, such as the Paris Agreement, the Sendai Framework for Disaster Risk Reduction and the Sustainable Development Goals.

systemic risk↗

Human Systems Integration (HSI) Framework and Training - Shifting the View of HSI for Better Implementation

The Implementation of Human Systems Integration (HSI) presents challenges within the acquisition community for two reasons. The first is that misconceptions of HSI still exist, with many Program Managers (PMs) and leadership uncertain of the value or where to begin. The second is due to an unbalanced approach to HSI in its own framework. These implementation challenges lead to barriers in the early prevention of mishaps. Understanding HSI practices and how they should be implemented in the Acquisition Product Life Cycle (PLC) has been a challenge across the government, leaving the value of HSI unknown and misunderstood with Program Managers. In the case for many acquisition programs, HSI is not implemented in early design, losing the perspective on human capabilities and limitations, creating impacts on human-centered design. Expectations in human performance are not clearly set and operations are baselined with no margin for changes in technology and processes that will affect system performance. The HSI framework addresses total system performance holistically using collaboration as the primary tool. The goal is to create a system with efficiencies while minimizing risk to the operators, maintainers, and support personnel, as well as any collateral personnel and systems. To accomplish this, HSI should be implemented as part of preemptive measures to minimize potential human error and mishaps during the operation phase. Investigative and assessment tools exist that consider events, issues, and other outside influences of a system that may not fall under the current construct of the HSI domains, leaving gaps in early HSI implementation and affecting the prevention of human errors and mishaps. This presentation will outline what NASA HSI is doing to support Early HSI implementation and Operational Performance shifts that affect human performance.

Anthony T Thomas↗

FRESCO: A Framework for Spacecraft Systems Autonomy

Achieving the science exploration and defense goals of the following decades will require flight systems capable of operations with limited operator contact, system mode changes and retasking based on sensor data, and complex robotic operations. To support these capabilities, increasingly autonomous flight systems are required that can perform dedicated mission functions, e.g. payload targeting and communications, and system-level functions, e.g. planning and goal monitoring. Architecting an autonomous system requires a well-reasoned, self-consistent framework to avoid \textit{ad hoc} design choices that will introduce complexity and risk. The Framework for Robust Execution and Scheduling of Commands On-Board, FRESCO, is the result of lessons learned in developing a software architecture to enable autonomous solar system exploration. FRESCO generalizes this work to offer a modular, software-agnostic approach to developing verifiable architecture for autonomous space systems. FRESCO specifies guiding principles, functions, interfaces, and interactions from which mission-specific autonomous control architectures can be derived. FRESCO is a principled framework relying on explicit, state-based goal definitions, centralized management of state knowledge, clearly separated control boundaries, and hierarchical reasoning. Using components from FRESCO reference architecture, an autonomous decision-making architecture can be designed for spacecraft which can then be mapped to flight software architecture. FRESCO is flexibly defined to enable autonomous control of flight systems built using extensive software and hardware heritage. Finally, FRESCO-derived architectures support a spectrum of operator/spacecraft interactions, ranging from traditional commanding to goal-driven commanding with the ability to change mission goals autonomously. FRESCO has been used in defining the autonomy architectures for the ASTERIA mission and have been demonstrated in laboratory and software simulation for small body rendezvous and in-space servicing missions.

Kolcio, Ksenia↗