Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

The background and theory of integrated risk management

While all good managers have always considered risk in their decision making, only recently have formal programs to do so been introduced. This report covers the logical structure behind the formulation of an integrated risk management plan (IRM). Included in the report are factors forcing the development of a formal plan to consider risk, the basic objective or purpose of an IRM, and desirable traits of such a plan. The report moves on to a discussion of background issues, seeks to formalize some definitions, and then discusses required information on threats. The report concludes with the steps for an IRM.

Hunsucker, John L.↗

Risk Management Overview for Small Business [Slides]

Project Risk Management is a formal process of identifying, analyzing, and responding to negative and positive events that may arise during a project or process lifecycle in order to increase the likelihood that project goals are met on time and on budget.

99 GENERAL AND MISCELLANEOUS↗

A hierarchical-multiobjective framework for risk management

A broad hierarchical-multiobjective framework is established and utilized to methodologically address the management of risk. United into the framework are the hierarchical character of decision-making, the multiple decision-makers at separate levels within the hierarchy, the multiobjective character of large-scale systems, the quantitative/empirical aspects, and the qualitative/normative/judgmental aspects. The methodological components essentially consist of hierarchical-multiobjective coordination, risk of extreme events, and impact analysis. Examples of applications of the framework are presented. It is concluded that complex and interrelated forces require an analysis of trade-offs between engineering analysis and societal preferences, as in the hierarchical-multiobjective framework, to successfully address inherent risk.

Haimes, Yacov Y.↗

A Holistic Approach for Risk Management During Design

In this paper, an approach for the identification, assessment, mitigation and continuous management of risks during the process of designing a space mission is presented. This approach has been developed by observing the risk patterns that occur at the Project Design Center of the Jet Propulsion Laboratory (TeamX) which develops conceptual, concurrent design of Space Missions. TeamX develops an end-to-end conceptual design of a Space Mission in a matter of one or two weeks. As the risk chair in TeamX, the author has had the opportunity to observe the risk patterns that occur during design over the course of many design sessions. This paper introduces an abstraction and generalization of those patterns. Risk is defined as anything that can go wrong, along with its approximate likelihood and consequence. The indicators, and causes, and effects of these risks are cross cutting across the multiple levels of people and processes involved in the design, and the actual design product itself.

reliability analysis↗

Design and Testing of an Approach to Automated In-Flight Safety Risk Management for sUAS Operations

An onboard risk management automation design is presented based on run-time assurance principles, as well as the concept for In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. The automation is designed to operate independently of the autopilot and perform real-time risk assessment spanning multiple classes of hazards, predict constraint violations, and track autopilot states. In the event of elevated risk conditions or predicted constraint violations, the automation will select from a set of available contingencies and trigger autopilot mode changes if necessary to mitigate risk exposure. The onboard automation also informs the remote operator/pilot of what the independent monitor is observing and any contingency decisions or actions that may arise during flight. Details of an implementation of this design and results of verification and validation activities, as required to meet stringent NASA software and system assurance standards, are also presented. This includes simulation and flight testing using small unmanned aircraft systems.

Ersin Ancel↗

System-Level Integration of Modular Language Models for Real-Time Risk Assessment in Third-Party Risk Management Systems

Large enterprises typically rely on dedicated teams to govern and implement security measures throughout their supply chains, ensuring compliance with enterprise security procedures. There is a significant reliance on Third-Party Risk Management (TPRM) platforms, which often require complete, highly structured information from potential vendors. The review and compliance assurance processes are time- and labor intensive, often requiring several rounds of review between the supply chain security risk management teams, business users, and potential vendors, leading to delays in the supply chain processing and consumer experience. Significant challenges in the risk management paradigm include handling unstructured data in various formats and providing real-time feedback to users to reduce the required review time. This paper presents a novel solution to these challenges. A modular multi-step system architecture is proposed using advances in language processing, specifically for unstructured responses and provides real-time feedback (i.e., 3 seconds) so that users can improve their responses before the TPSRM team review. This novel system architecture will increase information accuracy and significantly reduce time and labor during the review process.

99 - GENERAL AND MISCELLANEOUS↗

FY25 Ion Exchange Processing for the West Area Risk Management (WARM) Project

The West Area Risk Management (WARM) Project was established to enable near-term retrieval and pretreatment of tank waste from Hanford’s 200 West Area and to support deployment of an ion exchange (IX) system capable of producing cesium-depleted supernate suitable for offsite treatment and disposal. The WARM experimental campaign was designed to provide key data for design and operational planning of the 200 W IX system, which plans to utilize crystalline silicotitanate (CST) as the active media for cesium removal. This report documents a comprehensive FY25 experimental campaign designed to produce key technical data required for design and operational planning of the WARM IX system. Testing includes assessing Cs and Sr breakthrough performance in a 4-column system, Cs capacity batch contact testing, phosphate precipitation assessments, reduced-hydroxide feed displacement evaluation, and Sr speciation impacts on Sr removal. The experimental results provide detailed trends in Cs and Sr loading behavior, breakthrough performance across a 4-column staged IX system, distribution profiles within CST beds, and projections of operational flowrates relative to Waste Acceptance Criteria (WAC) limits. Batch contact testing established equilibrium partitioning behavior for the S1–S5 simulants and characterized how matrix chemistry influenced Cs sorption onto CST. Additionally, further evaluations on waste matrix as it pertains to precipitation potential were also determined. Collectively, these datasets support engineering design choices for WARM system throughput and pretreatment planning.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Risk management for the Space Exploration Initiative

Probabilistic Risk Assessment (PRA) is a quantitative engineering process that provides the analytic structure and decision-making framework for total programmatic risk management. Ideally, it is initiated in the conceptual design phase and used throughout the program life cycle. Although PRA was developed for assessment of safety, reliability, and availability risk, it has far greater application. Throughout the design phase, PRA can guide trade-off studies among system performance, safety, reliability, cost, and schedule. These studies are based on the assessment of the risk of meeting each parameter goal, with full consideration of the uncertainties. Quantitative trade-off studies are essential, but without full identification, propagation, and display of uncertainties, poor decisions may result. PRA also can focus attention on risk drivers in situations where risk is too high. For example, if safety risk is unacceptable, the PRA prioritizes the risk contributors to guide the use of resources for risk mitigation. PRA is used in the Space Exploration Initiative (SEI) Program. To meet the stringent requirements of the SEI mission, within strict budgetary constraints, the PRA structure supports informed and traceable decision-making. This paper briefly describes the SEI PRA process.

Buchbinder, Ben↗

Risk Management Technique for design and operation of facilities and equipment

The Risk Management System collects information from engineering, operating, and management personnel to identify potentially hazardous conditions. This information is used in risk analysis, problem resolution, and contingency planning. The resulting hazard accountability system enables management to monitor all identified hazards. Data from this system are examined in project reviews so that management can decide to eliminate or accept these risks. This technique is particularly effective in improving the management of risks in large, complex, high-energy facilities. These improvements are needed for increased cooperation among industry, regulatory agencies, and the public.

Fedor, O. H.↗

MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons Learned

As the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multiorganizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other's, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission's leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA's requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.

FISMA↗

Unlocking the benefits of transparent and reusable science for climate-risk management

People around the world seek climate-risk information to guide their decisions. For instance, projections about future flood risk inform where households choose to live, how lenders manage credit risks, and which communities receive federal funding. Yet data limitations and fundamental validation challenges raise important concerns about the reliability of such projections. The principles of transparency and reusability help address these concerns by enabling scrutiny of assumptions and methods, development of foundational data and tools, and consistent application of evaluation standards. While there is ongoing debate about how much transparency commercial climate-risk services should provide, many expect non-commercial actors to lead the way on operationalizing transparency and reusability to fulfill their knowledge-building role in the climate-risk ecosystem. However, despite prominent success stories, we find a substantial gap between principles and practice: only four percent of the most-cited peer-reviewed climate-risk studies in recent years fully share their data and code despite this being a widely accepted minimum standard for transparency. We highlight low-cost measures that non-commercial researchers can take now to improve transparency and reusability. We also emphasize that transformative progress requires substantial investment, cross-sector collaboration, and careful consideration of tradeoffs, data rights, and multiple perspectives on equity. We hope this perspective accelerates both immediate actions and longer-term conversations to improve the ability of science to effectively support timely, evidence-based, and sound climate-risk management.

Open Science↗

National Aeronautics and Space Administration Marshall Space Flight Center Space Transportation Directorate Risk Management Implementation Program

The US civil aerospace program has been a great contributor to the creation and implementation of techniques and methods to identify, analyze, and confront risk. NASA has accomplished mission success in many instances, but also has had many failures. Anomalies have kept the Agency from achieving success on other occasions, as well. While NASA has mastered ways to prevent risks, and to quickly and effectively react and recover from anomalies or failures, it was not until few years ago that a comprehensive Risk Management process started being implemented in some of its programs and projects. A Continuous Risk Management (CRM) cycle process was developed and has been promoted and used successfully in programs and projects across the Agency.

Duarte, Luis Alberto↗

A History of Space Toxicology Mishaps: Lessons Learned and Risk Management

After several decades of human spaceflight, the community of space-faring nations has accumulated a diverse and sometimes harrowing history of toxicological events that have plagued human space endeavors almost from the very beginning. Lessons have been learned in ground-based test beds and others were discovered the hard way - when human lives were at stake in space. From such lessons one can build a risk-management framework for toxicological events to minimize the probability of a harmful exposure, while recognizing that we cannot foresee all events. Space toxicologists have learned that relatively harmless compounds can be converted by air revitalization systems into compounds that cause serious harm to the crew. Our toxic risk management strategy now includes an assessment of the fate of any compound that might be released into the atmosphere. Propellants are highly toxic compounds, yet we have not always been able to thoroughly isolate the crew from exposure to these toxicants. Leakage of fluids from systems has resulted in hazardous conditions at times, and the behavior of such compounds inside a spacecraft has taught us how to manage potentially harmful escapes should they occur. Potential combustion events are an ever-present threat to the wellbeing of the crew. Such events have been sufficiently common that we have learned that one cannot judge the health threat of a given fire by the magnitude of the event. Management of such risks demands monitoring of combustion products. In the category of unpredictable toxic events, if one assumes that fires are predictable, we can place experience with toxic microbial metabolites, upsets during repair operations, and discharges from filters that have accumulated a substantial load of pollutants in their absorption beds. Management of such events requires a broad-spectrum, real-time analytical capability to discern the identity and concentrations of pollutants if they enter the atmosphere. Adverse events are an integral part of any human activity, and the spacefaring community must learn as much as possible from mistakes and near misses.

James, John T.↗