Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Risk Management for Human Support Technology Development

NASA requires continuous risk management for all programs and projects. The risk management process identifies risks, analyzes their impact, prioritizes them, develops and carries out plans to mitigate or accept them, tracks risks and mitigation plans, and communicates and documents risk information. Project risk management is driven by the project goal and is performed by the entire team. Risk management begins early in the formulation phase with initial risk identification and development of a risk management plan and continues throughout the project life cycle. This paper describes the risk management approach that is suggested for use in NASA's Human Support Technology Development. The first step in risk management is to identify the detailed technical and programmatic risks specific to a project. Each individual risk should be described in detail. The identified risks are summarized in a complete risk list. Risk analysis provides estimates of the likelihood and the qualitative impact of a risk. The likelihood and impact of the risk are used to define its priority location in the risk matrix. The approaches for responding to risk are either to mitigate it by eliminating or reducing the effect or likelihood of a risk, to accept it with a documented rationale and contingency plan, or to research or monitor the risk, The Human Support Technology Development program includes many projects with independently achievable goals. Each project must do independent risk management, considering all its risks together and trading them against performance, budget, and schedule. Since the program can succeed even if some projects fail, the program risk has a complex dependence on the individual project risks.

jones, Harry↗

Exploration Systems Development (ESD) Approach to Enterprise Risk Management

The National Aeronautics and Space Administration (NASA) Exploration Systems Development (ESD) Division has implemented an innovative approach to Enterprise Risk Management under a unique governance structure and streamlined integration model. ESD's mission is to design and build the capability to extend human existence to deep space. The Enterprise consists of three Programs: Space Launch System (SLS), Orion, and Ground Systems Development and Operations (GSDO). The SLS is a rocket and launch system that will be capable of powering humans, habitats, and support systems to deep space. Orion will be the first spacecraft in history capable of taking humans to multiple destinations within deep space. GSDO is modernizing Kennedy's spaceport to launch spacecraft built and designed by both NASA and private industry. ESD's approach to Enterprise Risk Management is commensurate with affordability and a streamlined management philosophy. ESD Enterprise Risk Management leverages off of the primary mechanisms for integration within the Enterprise. The Enterprise integration approach emphasizes delegation of authority to manage and execute the majority of cross-program activities and products to the individual Programs, while maintaining the overall responsibility for all cross-program activities at the Division. The intent of the ESD Enterprise Risk Management approach is to improve risk communication, to avoid replication and/or contradictory strategies, and to minimize overhead process burden. This is accomplished by the facilitation and integration of risk information within ESD. The ESD Division risks, Orion risks, SLS risks, and GSDO risks are owned and managed by the applicable Program. When the Programs have shared risks with multiple consequences, they are jointly owned and managed. When a risk is associated with the integrated system that involves more than one Program in condition, consequence, or mitigation plan, it is considered an Exploration Systems Integration (ESI) Risk. An ESI risk may require visibility and risk handling by multiple organizations. The Integrated Risk Working Group (IRWG) is a small team of Risk experts that are responsible for collaborating and communicating best practices. In addition, the forum facilitates proper integration of risks across the Enterprise. The IRWG uses a Continuous Risk Management approach for facilitating the identification, analysis, planning, tracking, and controlling of ESI Risks. The ESD Division, Programs, and Integrated Task Teams identify ESI Risks. The IRWG maintains a set of metrics for understanding Enterprise Risk process and the overall Risk Posture. The team is also actively involved in the modeling of risk for Enterprise Performance Management. With the Enterprise being constrained in Schedule and Budget, and with significant technical complexity, the appropriate use of Risk Management techniques is crucial to the success of the Enterprise. The IRWG achieves this through the modified approach, providing a forum for collaboration on risks that cross boundaries between the separate entities.

Bauder, Stephen P.↗

Human System Risk Management for Space Flight

This brief abstract reviews the development of the current day approach to human system risk management for space flight and the development of the critical components of this process over the past few years. The human system risk management process now provides a comprehensive assessment of each human system risk by design reference mission (DRM) and is evaluated not only for mission success but also for long‐term health impacts for the astronauts. The discipline of bioastronautics is the study of the biological and medical effects of space flight on humans. In 1997, the Space Life Sciences Directorate (SLSD) initiated the Bioastronautics Roadmap (Roadmap) as the "Critical Path Roadmap", and in 1998 participation in the roadmap was expanded to include the National Space Biomedical Research Institute (NSBRI) and the external community. A total of 55 risks and 250 questions were identified and prioritized and in 2000, the Roadmap was base-lined and put under configuration control. The Roadmap took into account several major advisory committee reviews including the Institute of Medicine (IOM) "Safe Passage: Astronaut care for Exploration Missions", 2001. Subsequently, three collaborating organizations at NASA HQ (Chief Health and Medical Officer, Office of Space Flight and Office of Biological & Physical Research), published the Bioastronautics Strategy in 2003, that identified the human as a "critical subsystem of space flight" and noted that "tolerance limits and safe operating bands must be established" to enable human space flight. These offices also requested a review by the IOM of the Roadmap and that review was published in October 2005 as "A Risk Reduction Strategy for Human Exploration of Space: A Review of NASA's Bioastronautics Roadmap", that noted several strengths and weaknesses of the Roadmap and made several recommendations. In parallel with the development of the Roadmap, the Office of the Chief Health and Medical Officer (OCHMO) began a process in 2004 of evaluating the tolerance limits and safe operating bands called for in the Bioastronautics Strategy. Over the next several years, the concept of the "operating bands" were turned into Space Flight Human System Standards (SFHSS), developed by the technical resources of the SLSD at the NASA Johnson Space Center (JSC). These standards were developed and reviewed at the SLSD and then presented to the OCHMO for acceptance. The first set of standards was published in 2007 as the NASA‐STD‐3001, Volume 1, Crew Health that elaborated standards for several physiological areas such as cardiovascular, musculoskeletal, radiation exposure and nutrition. Volume 2, Human Factors, Habitability and Human Health was published in 2011, along with development guidance in the Human Integration Design Handbook (HIDH). Taken together, the SFHSS Volumes 1 and 2, and the HIDH replaced the NASA‐STD‐3000 with new standards and revisions of the older document. Three other changes were also taking place that facilitated the development of the human system risk management approach. In 2005, the life sciences research and development portfolio underwent a comprehensive review through the Exploration Systems Architecture Study (ESAS) that resulted in the reformulation of the Bioastronautics Program into Human Research Program (HRP) that was focused on appropriate mitigation results for high priority human health risks. The baseline HRP budget was established in August 2005. In addition, the OCHMO formulated the Health and Medical Technical Authority (HMTA) in 2006 that established the position of the Chief Medical Officer (CMO) at the NASA JSC along with other key technical disciplines, and the OCHMO became the responsible office for the SFHSS as noted above. The final change was the establishment in 2008 of the Human System Risk Board (HSRB), chaired by the CMO with representation from the HRP, SLSD management and technical experts. The HSRB then began to review all human system risks, established a comprehensive risk management and configuration management plan and data sharing policy. These major developments of standards, the HRP, the HMTA and a forum for review of human system risks (HSRB) facilitated the integration of human research, medical operations, systems engineering and many other disciplines in the comprehensive review of human system risks. The HSRB began a comprehensive review of all potential inflight medical conditions and events and over the course of several reviews consolidated the number of human system risks to 30 where the greatest emphasis is placed for investing program dollars for risk mitigation. The HSRB considers all available evidence from human research, medical operations and occupational surveillance in assessing the risks for appropriate mitigation and future work. All applicable DRMs (low earth orbit 6 and 12 months, deep space sortie for 30 days and 1 year, a one year lunar mission, and a planetary mission for 3 years) are considered as human system risks are modified by the hazards associated with space flight such as microgravity, exposure to radiation, distance from the earth, isolation and a closed environment. Each risk has a summary assessment representing the state of knowledge/evidence base for that risk, the available risk mitigations, traceability to the SFHSS and program requirements, and future work required. These data then can drive coordinated budgets across the HRP, the International Space Station, Crew Health and Safety and Advanced Exploration System budgets. These risk assessments were completed for 6 DRMs in December of 2014 and serve as the baseline for which subsequent research and technology development and crew health care portfolios can be assessed. The HSRB will review each risk at least annually and especially when new information is available that must be considered for effective risk mitigation. The current status of each risk can be reported to program management for operations, budget reviews and general oversight of the human system risk management program.

Davis, Jeffrey↗

Managing Risk for Cassini During Mission Operations and Data Analysis (MOandDA)

A Risk Management Process has been tailored for Cassini that not only satisfies the requirements of NASA and JPL, but also allows the Program to proactively identify and assess risks that threaten mission objectives. Cassini Risk Management is a team effort that involves both management and engineering staff. The process is managed and facilitated by the Mission Assurance Manager (MAM), but requires regular interactions with Program Staff and team members to instill the risk management philosophy into the day to day mission operations. While Risk Management is well defined for projects in the development phase, it is a relatively new concept for Mission Operations. The Cassini team has embraced this process and has begun using it in an effective, proactive manner, to ensure mission success. It is hoped that the Cassini Risk Management Process will form the basis by which risk management is conducted during MO&DA on future projects. proactive in identifying, assessing and mitigating risks before they become problems. Cost ehtiveness is achieved by: Comprehensively identifying risks Rapidly assessing which risks require the expenditure of pruject cewums Taking early actions to mitigate these risks Iterating the process frequently, to be responsive to the dynamic internal and external environments The Cassini Program has successfully implemented a Risk Management Process for mission operations, The initial SRL has been developed and input into he online tool. The Risk Management webbased system has been rolled out for use by the flight team and risk owners we working proactive in identifying, assessing and mitigating risks before they become problems. Cost ehtiveness is achieved by: Comprehensively identifying risks Rapidly assessing which risks require the expenditure of pruject cewums Taking early actions to mitigate these risks Iterating the process frequently, to be responsive to the dynamic internal and external environments The Cassini Program has successfully implemented a Risk Management Process for mission operations, The initial SRL has been developed and input into he online tool. The Risk Management webbased system has been rolled out for use by the flight team and risk owners we working put into place will become visible and will be illusmted in future papers.

risk management↗

Method for Tracking and Communicating Aggregate Risk Through the Use of Model-Based Systems Engineering (MBSE) Tools

Large, complex projects can identify a significant number and variety of risks, throughout the project life cycle. These risks are analyzed, mitigated, closed or accepted as independent uncertainties. Once closed or accepted, it is easy for projects to lose awareness of their impact. In reality, each of these risks contributes some amount to the overall risk posture of the project. The ability to track and effectively communicate this aggregate risk has represented a challenge to project management. There have been previous attempts to create a schema to communicate the aggregate effect of risks, without notable success. Most of these attempts have centered on some additive metric derived from the scoring of likelihood and consequence values. This, in and of itself, is a logical approach, but all too often the scores were then aggregated to a level where all context was lost. One weakness has been a lack of attempt to create linkages or logical groups of the risks upon which useful aggregation could then occur. The overall move to model-based (systems) engineering (MBSE) has opened up a vast frontier of opportunities to better integrate all project data. MBSE provides an underlying layer that links data items to each other. Objectives link to requirements, which then link to functions, functions to physical architecture items, and so on, as far down as projects want to model. While it started with a focus on modeling requirements based on things like use cases, efforts are now underway to integrate safety and mission assurance (S&MA) information and analyses, such as risks. This effort, called Model Based Mission Assurance (MBMA), is yielding models that are more useful and are a more accurate representations of the systems. MBSE models, with this ability to link related items, provide a new means of tracking and communicating aggregate risks. In the proposed method, risks are added into the models as distinct items, having attributes that communicate a scoring derived from the likelihood and consequence values as charted on the standard NASA 5x5 risk matrix. Like earlier efforts, each box in the 5x5 has an associated scoring, which may include both a current score and potential post-mitigation/control score. The risk items are then linked to elements of the model, such as system objectives/goals, requirements, functions, or physical architecture items, with "Risk to" relationships. These risks will then be communicated by use of reports generated from the model, detailing all risks and/or hazards linked to model elements. These reports can include aggregate impacts, including a current scoring and potential future state scoring based on the planned mitigations and/or controls. These reports will show all risks, open, accepted, and closed, linked to project objectives or requirements. When run as part of an upcoming risk acceptance discussion, these reports will serve to remind the team of all previous risks that relate to the effected portion of the system. When included as part of periodic program or project reviews, risk reviews, and safety reviews, this method can improve the overall understanding of the system's true risk posture. This proposed method takes full advantage of the advances that modern modeling techniques provide, with a minimal investment of additional time. Utilizing the model environment also enables a near constant access to current state of aggregate risks.

model based mission assurance↗

Managing Research in a Risk World

The Office of Chief Medical Officer (OCHMO) owns all human health and performance risks managed by the Human System Risk Board (HSRB). While the HSRB manages the risks, the Human Research Program (HRP) manages the research portion of the overall risk mitigation strategy for these risks. The HSRB manages risks according to a process that identifies and analyzes risks, plans risk mitigation and tracks and reviews the implementation of these strategies according to its decisions pertaining to the OCHMO risk posture. HRP manages risk research work using an architecture that describes evidence-based risks, gaps in our knowledge about characterizing or mitigating the risk, and the tasks needed to produce deliverables to fill the gaps and reduce the risk. A planning schedule reflecting expected research milestones is developed, and as deliverables and new evidence are generated, research progress is tracked via the Path to Risk Reduction (PRR) that reflects a risk's research plan for a design reference mission. HRP's risk research process closely interfaces with the HSRB risk management process. As research progresses, new deliverables and evidence are used by the HSRB in conjunction with other operational and non-research evidence to inform decisions pertaining to the likelihood and consequence of the risk and risk posture. Those decisions in turn guide forward work for research as it contributes to overall risk mitigation strategies. As HRP tracks its research work, it aligns its priorities by assessing the effectiveness of its contributions and maintaining specific core competencies that would be invaluable for future work for exploration missions.

Anton, W.↗

The Challenger tragedy was caused by an Apollo mistake, terminating risk analysis

NASA’s view of risk changed between early Apollo and the Space Shuttle. Risk was a known serious problem at the beginning of Apollo and the risk estimates were disturbingly high. To avoid public concern, risk analysis was discontinued. Risk analysis was avoided in Shuttle, leading to an unnecessarily risky design. The immediate cause of the Challenger tragedy was the mistaken decision to launch in cold weather. The fundamental cause was the high risk of the Shuttle design. Before Challenger, management thought and testified that the probability of an accident was 1 in 100,000. After Challenger, Probabilistic Risk Analysis (PRA) found a roughly 1 in 100 chance of a Shuttle failure. The recent Orion design uses the safer Apollo approach, with a hardened capsule, launch abort escape, and the crew placed above the rocket tanks and engines. During Apollo it was estimated that, “assuming all elements from propulsion to rendezvous and life support were done as well or better than ever before, that 30 astronauts would be lost before 3 were returned safely to the Earth.” The chance of astronaut survival was only 10%. After the Apollo 1 tragedy, the awareness of risk led to an intense focus on achieving safety. “The only possible explanation for the astonishing success – no losses in space and on time – was that every participant at every level in every area far exceeded the norm of human capabilities.” During Apollo, a NASA PRA found that the chance of success was “less than 5 percent.” The NASA Administrator felt that “the numbers could do irreparable harm,” and discontinued numerical risk assessment. This led to decreasing understanding of risk. The head of Apollo reliability and safety decided, “Statistics don’t count for anything,” and that risk is reduced by “attention taken in design.” The great and initially unexpected success of Apollo appeared to validate the neglect of PRA. Continuing to neglect the mathematical estimation of risk led Shuttle into a high risk design that produced tragic results. The initial design of the Shuttle emphasized increasing capability and reducing cost without analysis or even mention of risk. A retired NASA official stated, “some NASA people began to confuse desire with reality. … One result was to assess risk in terms of what was thought acceptable without regard for verifying the assessment. … Note that under such circumstances real risk management is shut out.” Not computing risk led to removing launch abort, removing crew escape, selecting less reliable Solid Rocket Boosters, placing the crew compartment next to the rocket boosters, and accepting more stressed shielding tile designs. Accepting these specific risks directly caused the shuttle disasters. The Challenger tragedy is frequently taught as a case of management failure. The focus is on the Challenger launch decision hours before, which is a dramatic example of bad management. However, the true cause of the Challenger disaster occurred decades earlier in the Apollo era. When the easily predictable failures occurred, failure investigations focused on how they might have been avoided. The Shuttle was cancelled after the space station was completed because of its high risk. The ultimate cause of the Shuttle tragedies was the choice by the Apollo-era NASA administrator to avoid a negative public reaction to realistic risk analysis.

Harry W. Jones↗

NASA Human System Risk Assessment Process

NASA utilizes an evidence based system to perform risk assessments for the human system for spaceflight missions. The center of this process is the multi-disciplinary Human System Risk Board (HSRB). The HSRB is chartered from the Chief Health and Medical Officer (OCHMO) at NASA Headquarters. The HSRB reviews all human system risks via an established comprehensive risk and configuration management plan based on a project management approach. The HSRB facilitates the integration of human research (terrestrial and spaceflight), medical operations, occupational surveillance, systems engineering and many other disciplines in a comprehensive review of human system risks. The HSRB considers all factors that influence human risk. These factors include pre-mission considerations such as screening criteria, training, age, sex, and physiological condition. In mission factors such as available countermeasures, mission duration and location and post mission factors such as time to return to baseline (reconditioning), post mission health screening, and available treatments. All of the factors influence the total risk assessment for each human risk. The HSRB performed a comprehensive review of all potential inflight medical conditions and events and over the course of several reviews consolidated the number of human system risks to 30, where the greatest emphasis is placed for investing program dollars for risk mitigation. The HSRB considers all available evidence from human research and, medical operations and occupational surveillance in assessing the risks for appropriate mitigation and future work. All applicable DRMs (low earth orbit for 6 and 12 months, deep space for 30 days and 1 year, a lunar mission for 1 year, and a planetary mission for 3 years) are considered as human system risks are modified by the hazards associated with space flight such as microgravity, exposure to radiation, distance from the earth, isolation and a closed environment. Each risk has a summary two-page assessment representing the state of knowledge/evidence of that risk, available risk mitigations, traceability to the Space Flight Human System Standards (SFHSS) and program requirements, and future work required. These data then can drive coordinated budgets across the Human Research Program, the International Space Station, Crew Health and Safety and Advanced Exploration System budgets to provide the most economical and timely mitigations. The risk assessments were completed for the 6 DRMs and serve as the baseline for which subsequent research and technology development and crew health care portfolios can be assessed. The HSRB reviews each risk at least annually or when new evidence/information is available that adds to the body of evidence. The current status of each risk can be reported to program management for operations, budget reviews and general oversight of the human system risk management program.

Francisco, D.↗

Assessing the Risk of Crew Injury Due to Dynamic Loads During Spaceflight

Spaceflight requires tremendous amounts of energy to achieve Earth orbit and to attain escape velocity for interplanetary missions. Although the majority of the energy is managed in such a way as to limit the accelerations on the crew, several mission phases may result in crew exposure to dynamic loads. In the automotive industry, risk of serious injury can be tolerated because the probability of a crash is remote each time a person enters a vehicle, resulting in a low total risk of injury. For spaceflight, the level of acceptable injury risk must be lower to achieve a low total risk of injury because the dynamic loads are expected on each flight. To mitigate the risk of injury due to dynamic loads, the NASA Human Research Program has developed a research plan to inform the knowledge gaps and develop relevant tools for assessing injury risk. The risk of injury due to dynamic loads can be further subdivided into extrinsic and intrinsic risk factors. Extrinsic risk factors include the vehicle dynamic profile, seat and restraint design, and spacesuit design. Human tolerance to loads varies considerably depending on the direction, amplitude, and rise-time of acceleration therefore the orientation of the body to the dynamic vector is critical to determining crew risk of injury. Although a particular vehicle dynamic profile may be safe for a particular design, the seat, restraint, and suit designs can affect the risk of injury due to localized effects. In addition, characteristics intrinsic to the crewmember may also contribute to the risk of injury, such as crewmember sex, age, anthropometry, and deconditioning due to spaceflight, and each astronaut may have a different risk profile because of these factors. The purpose of the research plan is to address any knowledge gaps in the risk factors to mitigate injury risk. Methods for assessing injury risk have been well documented in other analogous industries and include human volunteer testing, human exposure to dynamic environments, post-mortem human subject (PMHS) testing, animal testing, anthropomorphic test devices (ATD), dynamic models of the human, numerical models of ATDs, and numerical models of the human. Each has inherent strengths and limitations. For example, human volunteer testing is advantageous because a population can be selected that is similar to the astronaut corps; however, because of the inherent ethical limitations, only sub-injurious conditions can be tested. PMHSs can be tested in a variety of conditions including injurious levels, but the responses are not completely analogous to living human subjects. In addition, it is exceedingly difficult to select a PMHS population that is similar to the astronaut corps. ATDs are currently widely used in the automotive industry and military because they are highly repeatable and durable. Unfortunately, because they are mechanical models of the human body, the biofidelity of the responses are limited to dynamic conditions used to validate the ATD. Numerical models of the ATD, in addition to the strengths and limitations for ATDs, are easy to use for a variety of designs before a design is fabricated, but also have additional limitations for ATDs, are easy to use for a variety of designs before a design is fabricated, but also have additional uncertainty. Dynamic models are simple and easy to use, but do not account for localized effects of the seat and suit. Finally, numerical models of the human have the potential to have the most advantages; however, the current models are not validated for the conditions expected during spaceflight. To properly assess spaceflight conditions with numerical human models, human data would be needed to optimize the model responses for those conditions. Using the appropriate assessment method with the knowledge gained for each risk factor, an appropriate approach for mitigating the risk of injury due to dynamic loads can be developed ensuring crew safety in future NASA vehicles.

Somers, J. T.↗

An editorial to the Special Issue on “Severe climate Risks”

The history of this Special Issue (https://www.sciencedirect.com/special-issue/10JD7LNJNQ0) indirectly dates back to the early 1990s, when the signature of the United Nations Framework Convention on Climate Change kicked-off an international political process based on one overarching and foundational principle: to avoid “dangerous anthropogenic interference with the climate system” at the global level. More than three decades later, such a principle remains central, though complementary aims made their way through the climate negotiation process, such as the importance of ensuring equity and justice, to give just one example here. Scientific knowledge also considerably progressed and we know more about the range of risks that climate change imposes and will continue to impose to the biosphere and humankind, worldwide and at all territorial levels. It is also clear that societal responses to these risks —“climate adaptation” as we know it— are increasingly happening, but definitely not at the pace of climate risk trends (Berrang-Ford et al., 2021, Erisken et al., 2021, Olazabal and Ruiz De Gopegui, 2021, Magnan et al., 2023a, Reckien et al., 2023, UNEP, 2023). As a result, concerns have emerged over the recent years in both the scientific and policy arenas around the idea that societies may not be able to address all climate risks, and that limits to adaptation and induced residual risks need to be considered more seriously. Such concerns further highlight the continuing importance of the imperative to minimise dangerous anthropogenic interference with the climate system, at any scale. But what does “dangerous interference” mean? How can we decide that we are entering the “dangerous” space, compared to a broader range of climate risks that would qualify as problematic but not necessarily “dangerous”? Who should make such a decision? Which conditions drive risk severity over time, including in the future? And what would be the environmental, economic, social and cultural implications of prioritising some climate risks over others? The Intergovernmental Panel on Climate Change (IPCC) was a pioneer in addressing such questions through the development of the “Key Risks” framing that describes those climate risks having the potential to become dangerous or “severe” over the course of this century (Schellnhuber et al., 2006, Schneider et al., 2007, Oppenheimer et al., 2014, O’Neill et al., 2022). The Fifth and Sixth assessment cycles (AR5 and AR6) went a step further by identifying about 120 Key Risks across regions and sectors, and clustering them into 8 “Representative Key Risks” covering a range of geographical systems (low-lying coasts, and to terrestrial and ocean ecosystems), sectors (critical infrastructure, living standards, human health, food security, and water security) and human dimensions (peace and mobility) (Oppenheimer et al., 2014, O’Neill et al., 2022). This Special Issue was born of the efforts of a range of authors, during the development of the IPCC AR6 main Assessment Report between 2019 and 2022, to characterise Key Risks and Representative Key Risks, and advance knowledge on what shapes “severe climate risks” conceptually as well as in the real-world. The series of papers forming this Special Issue is not intended to cover the topic exhaustively, but rather to give readers an overview through the following narrative: defining “severe climate risks” is highly challenging (Magnan et al., 2023b), but knowledge is expanding on the driving climate hazards (Tebaldi et al., 2023) and their implications on geographical systems, sectors and human dimensions, using here food security (Mirzabaev et al., 2023), human mobility (Gilmore et al., 2024) and peace (Buhaug et al., 2023) as illustrative examples. The overall intention is to support especially decision-makers, whatever the scale or sector considered, in asking severity-driven questions to identify sector- and context-specific “priority” risks from climate change.

54 ENVIRONMENTAL SCIENCES↗

Alternative Perspectives on Risk

The goal of the commercial air transport system is to provide air transportation to the flying public at an acceptable cost with minimal risk. in an ideal situation these three goals would support each other. In fact, it is sometimes the case that the goals conflict: getting passengers to their destinations on time may conflict with fixing a minor mechanical malfunction that may or may not impact safety; flying a route that will avoid turbulence, thereby providing passengers with a more comfortable ride, may consume more fuel; managing traffic density may mean aircraft are delayed or must use an approach that will result in a long taxi to their gates, costing time and fuel. Various players in the system--pilots, dispatchers, controllers, as well as managers in the airline carriers and traffic management system--make decisions every day that involve trade-offs of benefits and costs. The prospect of revisions in the air traffic management system, with shifts in responsibilities from controllers to users, including airline operations center personnel and pilots, means that individuals may be performing either new jobs or old jobs under new guidance. It will be essential to know how the various players (a) perceive the risks and benefits associated with the decisions they will make under the old and new control structures, and (b) how much risk they are willing to accept in making decisions. Risk is here defined as the probability and magnitude of negative events (after Slovic, 1987). Of primary interest are risks associated with traffic, weather, and operational factors such as schedule, fuel consumption, and passenger service. Previous research has documented differences between groups in perceptions of risks associated with both everyday and aviation related situations. Risk perception varies as a function of familiarity with the situation, degree to which one is potentially affected by the risk, the level of control one has over the situation, and one's level of experience and responsibility in the situation. In our presentation we will consider several factors that may influence differences in risk perception, risk tolerance and risk management among the three major categories of participants in the aviation system (pilots, dispatchers, and controllers). Primary factors that may affect risk attitudes (the collective term we will use for the three components of risk) include: expertise or job-specific knowledge or training, personal involvement or vulnerability to consequences, goals, time horizon (imminence of consequences), span of control and type of control, and information or technology support. These will be considered in the context of five different types of risk (physical threat, economic, social, legal, and ethical). A study designed to study differences between pilots and controllers in their perceptions and responses to traffic risks under the present and a user-preferred control situation will be described. Future studies involving dispatchers' risk perceptions regarding various types of risk will be discussed.

Davison, Jeannie↗

Long-Term Health Risk Quantification

Astronauts face hazards during spaceflight, including space radiation exposure, isolation and confinement, traveling far distances from Earth, reduced gravity levels, and closed and hostile environments. These hazards drive the definition of human health and performance risks associated with spaceflight. NASA’s Human System Risk Board maintains the human spaceflight risk posture for in-mission risks, as well as post-flight, Long-Term Health (LTH)risks potentially occurring later in the astronaut’s life. LTH risk encompasses the timeframe from immediately post-flight, through the rest of an astronaut’s career, through retirement, and until death. Possible LTH risk outcomes include the time and interventions needed for the astronaut to return to preflight physiological states after experiencing spaceflight hazards and recovery from any in-mission medical events that persist into the post-flight timeframe. It includes chronic complications that may arise due to experiencing in-flight medical conditions or injuries and medical conditions that occur later in life with a higher probability of occurrence or with more severity because of their spaceflight exposure. Finally, LTH risk outcomes can also include a reduction in life expectancy due to spaceflight exposures. There have been 144 medical conditions identified by NASA’s Lifetime Surveillance of Astronaut Health team to be associated with LTH risk. Epidemiological studies have been performed for some of these conditions to determine if astronauts suffer from an increased prevalence or severity of the condition due to their spaceflight experience compared to a comparable cohort .Differences in astronaut mortality or morbidity due to spaceflight experience were not detected in several of these studies. There were two cases where a modest increase in the incidence rate of astronaut LTH outcomes was detected. The first suggested an increase in the incidence of melanoma cases in astronauts, where the number of cases in astronauts were similar to the elevated number of cases observed in airplane pilots. The second provided some evidence of elevated numbers of cardiovascular disease events in astronauts compared to an appropriate healthy comparator cohort, which may warrant additional investigation. The lack of detection of LTH risk outcomes should not ease concerns about astronaut LTH. The studies highlighted here constitute only a small portion of the potential LTH conditions that could occur. Once epidemiological studies are performed on all conditions, significant findings may be detected. The analysis of astronaut LTH also suffers from limited numbers of data points because of the limited numbers of astronauts overall and the even fewer who have reached an age where LTH outcomes may begin to manifest. As shuttle and ISS astronauts begin to age and increase the feasibility of analysis, LTH outcomes may be detected. An application of risk quantification is the use of risk metrics within trade studies for resource prioritization and decision making. Trade studies regarding countermeasures to LTH risk outcomes would benefit from a quantification of LTH risk. NASA has ground-based processes in place such as astronaut screening and access to continuous medical monitoring and care during and after their astronaut career which are the main methods for mitigating LTH risk. In-mission countermeasures, such as acceptable levels of medical care and available countermeasures to counter spaceflight related physiological decrements, can mitigate a poor health and performance status immediately post-flight. Identifying appropriate risk metrics, obtaining valid quantities for them, and tying them to LTH countermeasures are necessary steps for realizing their use in trade studies. This presentation will highlight the challenges associated with the identification, quantification, and utilization of LTH risk metrics

Beth Lewandowski↗

Risk Management Issues - An Aerospace Perspective

Phased-approach for implementation of risk management is necessary. Risk management system will be simple, accessible and promote communication of information to all relevant stakeholders for optimal resource allocation and risk mitigation. Risk management should be used by all team members to manage risks--risk office personnel. Each group is assigned Risk Integrators who are facilitators for effective risk management. Risks will be managed at the lowest-level feasible, elevate only those risks that require coordination or management from above. Risk reporting and communication is an essential element of risk management and will combine both qualitative and quantitative elements.. Risk informed decision making should be introduced to all levels of management. Provide necessary checks and balances to insure that risks are caught/identified and dealt with in a timely manner, Many supporting tools, processes & training must be deployed for effective risk management implementation. Process improvement must be included in the risk processes.

Perera, Jeevan S.↗

NASA's Risk Management System

Leadership is key to success. Phased-approach for implementation of risk management is necessary. Risk management system will be simple, accessible and promote communication of information to all relevant stakeholders for optimal resource allocation and risk mitigation. Risk management should be used by all team members to manage risks -- risk office personnel. Each group is assigned Risk Integrators who are facilitators for effective risk management. Risks will be managed at the lowest-level feasible, elevate only those risks that require coordination or management from above. Risk reporting and communication is an essential element of risk management and will combine both qualitative and quantitative elements. Risk informed decision making should be introduced to all levels of management. Provide necessary checks and balances to insure that risks are caught/identified and dealt with in a timely manner. Many supporting tools, processes & training must be deployed for effective risk management implementation. Process improvement must be included in the risk processes.

Perera, Jeevan S.↗

Application of quantitative risk assessment to address stakeholder questions in geologic carbon storage

Ambitious international greenhouse gas emissions reduction targets demand a rapid transformation to a low-carbon economy. This transformation includes the accelerated adoption of carbon dioxide (CO2) capture and storage (CCS) technology. However, as with any large-scale engineering enterprise, the widespread commercial-scale deployment of geologic carbon storage (GCS) raises important questions about technology and cost-effectiveness, safety, environmental risk, and long-term liability. Effectively assessing and managing risks and liability associated with GCS projects is a key technical need throughout the project life cycle-from site selection and permitting to monitoring design, operational risk management, and post-operational site closure. This presentation highlights recent advancements in tools for quantitative risk assessment, being developed by the National Risk Assessment Partnership (NRAP). NRAP is a multi-year, multinational laboratory research collaboration sponsored by the U.S. Department of Energy's Office of Fossil Energy and Carbon Management. Our focus will be on these tools' applications in addressing critical stakeholder questions related to supporting permitting to ensure secure and environmentally protective storage; designing effective and efficient monitoring plans; evaluating the effectiveness of remedial actions and risk management alternatives; and informing liability assessment and investment decisions. This paper will detail the key functionality of NRAP’s Open-Source Integrated Assessment Model (NRAP-Open-IAM), a computational framework for assessing leakage risk and containment assurance. This model features streamlined workflows for calculating leakage risk profiles, delineating risk-based area of review, and assessing contingency plans and post-injection site care requirements. ORION is an open-source, observation-based ensemble forecasting toolkit to help operators assess the seismic hazard at a carbon storage site. The State of Stress Analysis Tool (SOSAT), designed to assess subsurface stress conditions and evaluate geomechanical risk resulting from CO2 injection in an area of interest will also be presented. We will also introduce a prototype model to evaluate storage project costs and liability associated with risk management. The Technoeconomic and Liability Evaluation for Storage (TALES) model uses results from forecasts of leakage and induced seismicity risk to estimate the lifecycle cost of managing risk. Finally, a preliminary example of how the NRAP Risk-based Adaptive Monitoring Plan (RAMP) tool can be used to design efficient and effective site monitoring plans and estimate the detectability of fluid leakage will be provided. The relevance of these tools for addressing key stakeholder questions amidst uncertainty will be emphasized.

decision support↗

Lessons Learned With Risk Management: A Systems Engineer's Perspective

Risk management is a communications device that, when executed as an essential task, enables systems engineering to effectively balance risk across the project. Developing and baselining risks is an essential continuous task to ensure top project concerns both from bottom up and top down are being mitigated. Risk management provides the opportunity to avoid the consequence of the risk when mitigation steps start early enough. Just discussing risk with all the project flight elements during development, even if no risks are open, provides an excellent communication opportunity between systems engineering and those elements, ensuring concerns and worries have a platform for discussion. A well-managed risk identification process will identify concerns that are serious but not being clearly communicated, and it will enable mitigation of those potential problems before they cause a failure. Effective risk management requires considerable time and effort, but that effort will save time and money across the development. Risk management must be frequent enough to be useful and in depth enough to bring out emerging issues. It also requires a trusting relationship between the lead systems engineer and element and/or subsystem leads. The discussions need to be with the right number of individuals (typically a handful) and the right duration in time (typically an hour a month). Outside of these risk working groups, there is a formal management process to input, status, and disposition risks, and a monthly Risk Management Board meeting where key project stakeholders are informed. This paper provides good guidance on effective risk management from a systems engineering perspective and provides project lessons learned from the NASA spaceflight missions NICER, Landsat 9, LRO, and OSIRIS-REx to demonstrate the effectiveness of risk management.

Lessons Learned↗

Lessons Learned With Risk Management: A Systems Engineer’s Perspective

Risk management is a communications device that, when executed as an essential task, enables systems engineering to effectively balance risk across the project. Developing and baselining risks is an essential continuous task to ensure top project concerns both from bottom up and top down are being mitigated. Risk management provides the opportunity to avoid the consequence of the risk when mitigation steps start early enough. Just discussing risk with all the project flight elements during development, even if no risks are open, provides an excellent communication opportunity between systems engineering and those elements, ensuring concerns and worries have a platform for discussion. A well-managed risk identification process will identify concerns that are serious but not being clearly communicated, and it will enable mitigation of those potential problems before they cause a failure. Effective risk management requires considerable time and effort, but that effort will save time and money across the development. Risk management must be frequent enough to be useful and in depth enough to bring out emerging issues. It also requires a trusting relationship between the lead systems engineer and element and/or subsystem leads. The discussions need to be with the right number of individuals (typically a handful) and the right duration in time (typically an hour a month). Outside of these risk working groups, there is a formal management process to input, status, and disposition risks, and a monthly Risk Management Board meeting where key project stakeholders are informed. This paper provides good guidance on effective risk management from a systems engineering perspective and provides project lessons learned from the NASA spaceflight missions NICER, Landsat 9, LRO, and OSIRIS-REx to demonstrate the effectiveness of risk management.

Lessons Learned↗

NASA Risk Management Handbook: Version 2.0, Part 1

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0. NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Uncertainty↗