Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

Risk Posture↗

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

42 ENGINEERING↗

Autonomous Tools for Attack Surface Reduction (Final Report)

The electric power grid is a complex critical infrastructure that forms the lifeline of modern society, and its secure and reliable operation is of paramount importance to national security and economic wellbeing. However, recent findings documented in authoritative sources indicate the threat of cyber-based attacks growing in numbers and sophistication. However, securing the grid against stealthy cyberattacks is a challenging task due to legacy nature of the infrastructure coupled with dynamic nature of threat landscape and ever-growing sophistication of the adversaries. Additionally, the grid’s attack surface continues to grow with the increased dependence on digital communications and control that now extends to each consumer through smart meters and distributed energy resources. Unfortunately, this expansive surface increases the grid’s vulnerability and further exposes critical control systems in both substations and control centers. To respond to this emerging need, we had successfully assembled an interdisciplinary team with academic- industry partnership to successfully conduct research, development, evaluation, demonstration, and commercialization of attack surface reduction tools, whose goal was to significantly reduce the cyber attack surface in the North American power grid. Our proposed project was a synergistic collaborative effort leveraging the synergistic expertise of the team members across power systems, cyber security and CPS security, testbeds, field deployments and demonstration, and successful commercialization. The following are the specific tasks that have been successfully completed two phases (2016-2020). Phase I: Task 1: Developed and implemented a robust Project Management and Data Management Plan, coupled with a well thought out Risk Mitigation Plan. Task 2.1: Developed a comprehensive framework that continually assesses and autonomously reduces the attack surface for the power grid control environment spanning across substations, control center and the SCADA network to significantly reduce the risks of cyber attacks. Task 2.2: Developed attack surface analysis techniques, metrics, and tools that assess the attack surface at multiple levels including the control center, substations, and the SCADA network. Task 2.3: Developed attack surface reduction techniques and tools that dynamically reduce attack surface and hence increase attacker’s cost without interfering in the critical functions of the system. Task 2.4: Prototyped, implemented, and quantitatively evaluated/validated the techniques and tools on a realistic industrial CPS security testbed environment by leveraging the unique resources of the team. Task 3: Developed Commercialization plan to transition the developed tools into power system industry stakeholders for a broader adoption by leveraging the expertise of our industrial members. Phase II: Task 4: Successfully completed field demonstration, verification, and evaluation of the effectiveness of the attack surface analysis and reduction techniques on a realistic utility testbed environment. This also involved the development of realistic scenarios, sound metrics, data sets, evaluation criteria, and documentation. Technology integration & Field demonstration: The project had significantly advanced the state-of-the-art research and practice in improving the cybersecurity of our nation’s power grid infrastructure against cyber threats. In particular, the proposed, designed, and deployed attack surface analysis and reduction algorithms and tools have contributed to significantly reducing the exposure and risk of the devices, substations, and the integrated SCADA/EMS/ DMS grid environment to cyber threat. Strong demonstration and evaluation techniques have verified the feasibility of the developed techniques on realistic cyber-physical testbeds and utility partner's real grid environment, and collaborative research and evaluation of attack surface reduction techniques (for wide-are monitoring and control) within a vendor (GE) EMS platform. The Attack Host Analyzer (AHA) tool that was developed through this project was made available through GitHub.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Characterizing manufacturing sector disruptions with targeted mitigation strategies

It has become clear in recent decades that manufacturing supply chains are increasingly vulnerable to disruptions of varying geographical scales and intensities. These disruptions—whether intentional, accidental, or resulting from natural disasters—cause failures and capacity reductions to manufacturing infrastructure, with lasting effects that can cascade throughout the manufacturing network. An overall lack of understanding of solutions to mitigate disturbances has rendered the challenge of reducing manufacturing supply chain vulnerability even more difficult. Additionally, the variability of disruptions and their impacts complicates policy maker and stakeholder efforts to plan for specific disruptive scenarios. It is necessary to comprehend different kinds of disturbances and group them based on stakeholder-provided metrics to support planning processes and modeling efforts that promote adaptable, resilient manufacturing supply chains. This paper reviews existing methods for risk management in manufacturing supply chains and the economic and environmental impacts of disruptions. In addition, we develop a framework using agglomerative hierarchical clustering to classify disruptions using U.S. manufacturing network data between 2000 and 2021 and characteristic metrics defined in the literature. Our review identifies five groups of disruptions and discusses both general mitigation methods and strategies targeting each identified group. Further, we highlight gaps in the literature related to estimating and including environmental costs in disaster preparedness and mitigation planning. We also discuss the lack of easily available metrics to quantify environmental impacts of disruptions and how such metrics could be included into our methodology.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Multiple aspects maintenance ontology-based intelligent maintenance optimization framework for safety-critical systems

Abstract Maintenance optimization is a process for improving the efficiency of maintenance strategies and activities, considering various aspects of the target system and components, such as the probabilities of system failures and the cost of repair and replacement of a failed component. The improvement of maintenance optimization algorithms generally requires information from various data sources. For example, it may require the system risk information derived from risk analysis tools or the residual lifetime of a component from fault prognosis tools. The requirements of data acquisition (DAQ) and aggregation pose new challenges for maintenance management systems (MMSs) that implement and use these maintenance optimization algorithms. This paper proposes a multiple aspects maintenance ontology-based framework to facilitate DAQ from MMSs, online monitoring systems, fault detection and discrimination tools, risk assessment tools, decision-making tools, and component identification tools, and accelerate the implementation and verification of contemporary maintenance optimization models and algorithms. The proposed framework consists of a multi-aspect maintenance ontology with critical information for maintenance optimization and application interfaces for collecting information from various data sources, such as fault prognosis tools, online monitoring tools, risk assessment tools, and decision-making algorithms. In addition, this paper proposes a heuristic method for integrating concepts and properties from other existing ontologies into the proposed framework when the existing ontology is not fully compatible with the ontology under construction. Finally, the paper verifies the proposed ontology framework using a feedwater system designed for nuclear power plants with valves and filters as the components under maintenance.

Diao, Xiaoxu (ORCID:0000000346726352)↗

Transforming Cyber Education thru Open to All Accessible Pathways

Boise State University’s (BSU) Cyber Operations and Resilience CORe program was intentionally designed so that any student, especially non-traditional and non-technical students, with an interest in cybersecurity could have an education and training pathway to enter the cyber workforce. The CORe curriculum focuses on teaching students how to design, apply, and improve cybersecurity through the interaction of people, processes, and technology. CORe is a stackable curriculum with elective credit hours and options for various academic and industry certificates and certifications that enable students to customize their unique career pathway. The CORe program guides students to think about the system being managed, the risks presented, and the dynamic intersection of system elements when considering how to incorporate resilience frameworks in achieving a resilient system. By developing systems thinking, the students gain an understanding of the interdependencies interacting with the operational system. Further, the CORe program encourages students to integrate cybersecurity knowledge with models and frameworks found in other academic disciplines through a unifying systems approach. CORe is designed around the realities of today’s broad cyber landscape: that breaches will occur in any system over time and proactive design of resilience into systems to detect, respond, and recover in a timely and orderly manner is critical. Students are taught to think holistically about cybersecurity focusing on all system elements. CORe is not a traditional cybersecurity degree. CORe is distinguished by the non-traditional engineering, computer science approach to cybersecurity education with the singular focus on infusing resilience operations and transdisciplinary systems thinking principles throughout the curriculum.

99 GENERAL AND MISCELLANEOUS↗

NASA System Safety Handbook. Volume 2: System Safety Concepts, Guidelines, and Implementation Examples

This is the second of two volumes that collectively comprise the NASA System Safety Handbook. Volume 1 (NASASP-210-580) was prepared for the purpose of presenting the overall framework for System Safety and for providing the general concepts needed to implement the framework. Volume 2 provides guidance for implementing these concepts as an integral part of systems engineering and risk management. This guidance addresses the following functional areas: 1.The development of objectives that collectively define adequate safety for a system, and the safety requirements derived from these objectives that are levied on the system. 2.The conduct of system safety activities, performed to meet the safety requirements, with specific emphasis on the conduct of integrated safety analysis (ISA) as a fundamental means by which systems engineering and risk management decisions are risk-informed. 3.The development of a risk-informed safety case (RISC) at major milestone reviews to argue that the systems safety objectives are satisfied (and therefore that the system is adequately safe). 4.The evaluation of the RISC (including supporting evidence) using a defined set of evaluation criteria, to assess the veracity of the claims made therein in order to support risk acceptance decisions.

Safety Case↗

Resilience Assessment Framework For Electric Distribution Systems Performance Under Extreme Conditions

The devastating impact of extreme weather-related events is increasingly evident on power grids, especially on distribution grids. The severity of their potential impact calls for 1) developing a suitable resilience assessment framework to capture the system performance and 2) assessing relevant mitigative strategies to lessen the impact of such events. This paper proposes a framework to identify grid vulnerabilities using the energy-at-risk concept to select, disconnect and isolate grid portions due to a resilience event. The proposed framework mainly consists of two steps; i) processing the utility's available infrastructure, i.e., a network model, possible switching combinations, and outage information for those combinations, as a graph-based database, and ii) implementing a novel optimal switching algorithm leveraging database and grid simulated metrics. These switching actions are generated to implement load curtailment in a rolling manner during anticipated grid scarcity conditions. In this study, a test case is created using two taxonomy feeders and is simulated against an extreme temperature event, e.g., a long, relatively cold, and prolonged freeze peak, thereby creating stress on the grid. It is demonstrated that the proposed framework allows utilities to predict the energy-at-risk during such resilience events and design suitable outage management strategies.

Poudel, Shiva↗

Hurricane-induced power outage risk under climate change is primarily driven by the uncertainty in projections of future hurricane frequency

Nine in ten major outages in the US have been caused by hurricanes. Long-term outage risk is a function of climate change-triggered shifts in hurricane frequency and intensity; yet projections of both remain highly uncertain. However, outage risk models do not account for the epistemic uncertainties in physics-based hurricane projections under climate change, largely due to the extreme computational complexity. Instead they use simple probabilistic assumptions to model such uncertainties. Here, we propose a transparent and efficient framework to, for the first time, bridge the physics-based hurricane projections and intricate outage risk models. We find that uncertainty in projections of the frequency of weaker storms explains over 95% of the uncertainty in outage projections; thus, reducing this uncertainty will greatly improve outage risk management. We also show that the expected annual fraction of affected customers exhibits large variances, warranting the adoption of robust resilience investment strategies and climate-informed regulatory frameworks.

54 ENVIRONMENTAL SCIENCES↗

A Field Guide to Corralling the Chaos: A Conceptual Framework for Using Models to Guide Opportunistic Field Studies of Natural Disturbances

Watersheds regulate biogeochemical processes and provide ecosystem services to human societies, but disturbances can fundamentally alter these processes across space and time. Determining when and where to sample to capture disturbance impacts in watersheds remains a central challenge. Manipulation studies and long-term monitoring are often constrained by scope, and opportunistic studies often lack pre-disturbance data needed to statistically determine disturbance impacts. We identify a persistent knowledge gap: the absence of a clear, transferable framework to guide opportunistic disturbance research where pre-disturbance data collection is not a feasible option. To address this gap, we present a conceptual framework that intentionally integrates modeling and empirical observation in an iterative, stepwise model–experiment workflow. We demonstrate its application through two contrasting case studies: wildfire impacts on headwater streams using a pre-disturbance preparedness approach, and saltwater flooding impacts on coastal forests using an ‘ex-post-facto’ approach. From these applications, we assess strengths, limitations, and the critical role of team science for transferability across disturbance types and study designs. Broadly, this framework offers a scalable path towards more rigorous, timely, and actionable disturbance science that can inform watershed management, hazard risk reduction, and ecosystem resilience.

Coastal Biogeochemistry↗

Europa Clipper Payload Verification and Validation: Early Architecture and Implementation

NASA’s Europa Clipper mission will investigate the Jovian icy moon Europa with a sophisticated payload consisting of a suite of nine instruments. Clipper’s observations will help provide answers to a broad range of scientific objectives related to Europa’s habitability. As the project proceeds through Phase C, we are building confidence in the system’s ability to achieve these science goals by implementing a rigorous payload verification and validation (V&V) program. This paper details the planned structure and implementation of the Europa Clipper payload V&V program as it exists leading up to the project critical design review (CDR), before the bulk of instrument- or payload- level V&V activities have begun. We first explain the context for payload V&V on Europa Clipper, including its interfaces with other parts of the project system. We then describe the taxonomy of V&V concepts and their interrelationships, followed by a discussion on how this framework allows us to codify interfaces, processes, and ideas that are key to a successful V&V program. We focus on key aspects of the planning phases of V&V, especially establishing a complete set of verification items and accurately mapping them into appropriate verification activities. The second half of the paper describes the logistics of implementing this framework onto our actual payload system, including the processes and tools we use to manage and communicate agreements, changes, and risks across the project. We conclude with a reflection on the unique drivers and challenges of the V&V program concept development so far and the work that is planned for phase D implementation.

Srivastava, Priyanka↗

Enhanced Iodine Capture Using a Postsynthetically Modified Thione–Silver Zeolitic Imidazole Framework

Efficient management of radionuclides that are released from various processes in the nuclear fuel cycle is of significant importance. Among these nuclides, radioactive iodine (mainly 129 I and 131 I) is a major concern due to the risk it poses to the environment and to human health; thus, the development of materials that can capture and safely store radioactive iodine is crucial. Herein, a novel silver-thione-functionalized zeolitic imidazole framework (ZIF) was synthesized via post-synthetic modification and assessed for its iodine uptake capabilities alongside the parent ZIF-8 and intermediate materials. A solvent-assisted ligand exchange procedure was used to replace the 2-methylimidazole linkers in ZIF-8 with 2-mercaptoimidazole, forming the intermediate compound ZIF-8=S, which was reacted with AgNO 3 to yield the ZIF-8=S-Ag + composite for iodine uptake. Despite possessing the lowest BET surface area of the derivatives, the Ag-functionalized material demonstrated superior I 2 adsorption in terms of both maximum capacity (550 g I 2 /mol) and rapid kinetics (50% loading achieved in 5 hrs, saturation in 50 hrs) compared to our pristine ZIF-8, which reached 450 g I 2 /mol after 150 hours and 50% loading in 25 hours. This improvement is attributed to the presence of the Ag + ions, which provide a strong chemical driving force to form stable Ag-I species. In conclusion, the results of this study contribute to a broader understanding of the strategies that can be employed to engineer adsorbents with robust iodine uptake behavior.

36 MATERIALS SCIENCE↗

1.3.3.402 - Cybersecurity Value-at-Risk Framework

The Cybersecurity Value-at-Risk Framework tool will guide users through an assessment and detailed analysis of a hydropower plant's operations. The tool will then provide results and data to inform effective cybersecurity investment decision-making and planning. The results will help managers understand the risk probability of cyberattacks on their facilities and how best to use resources to mitigate those risks.

cybersecurity↗

Georgetown University – SYSM 5630 Systems Integration Verification and Validation : Todd Noste

At Lawrence Livermore National Laboratory in the National Ignition Facility Optics Group, we use the systems engineering approach for project management and as a design tool. Systems engineering is used in a graded approach to design and project management that is based on risk, informing how much rigor to apply. The tools and techniques from systems engineering offer a framework to organize projects with everyone speaking the same language to provide consistent and repeatable project success that satisfies the stakeholders’ needs and meets the mission. The classes have provided a framework with tools for communicating system design, requirements, verification and validation, and an operational context.

42 ENGINEERING↗

Aggregation and Grid Security Workshop Report

The Aggregation and Grid Security Workshop - held on June 17-18, 2025, National Laboratory of the Rockies (NLR) in Golden, Colorado - brought together approximately 40 external stakeholders from the energy sector, including VPP owner/operators, aggregators, OEMs, utilities, testing & certification labs, trade associations, and cybersecurity vendors. Led by key facilitators, the workshop focused on addressing cybersecurity challenges and enhancing grid resilience for aggregated Distributed Energy Resources (DERs) and Virtual Power Plants (VPPs). The workshop was catalyzed by recognition that traditional, rearward-looking regulatory frameworks are insufficient to keep pace with technological change. There is a "missing understanding" of risk, an "absent security basis" for managing it, and an "untenable responsibility" due to unclear ownership and requirements. The workshop aimed to shift the mindset from reacting to past crises to proactively preparing for emerging threats, fostering forward resilience through risk simulation and collaborative action. This report summarizes the outcomes of the workshop, marking it a significant step toward a secure, reliable and affordable energy future.

14 SOLAR ENERGY↗

Expected occurrence of wildlife in US Atlantic offshore wind areas

Offshore wind energy has entered a pivotal phase of development for the U.S. Atlantic Outer Continental Shelf (OCS), a region that supports critical habitats, migratory corridors and flyways for many marine species. Assessing where and when marine wildlife occurs is a crucial first step in developing a risk assessment framework to evaluate potential risks and impacts of offshore wind development. In this study, we perform this initial assessment by evaluating the expected occurrence of marine mammal, seabird and sea turtle taxa in areas of interest to identify patterns and potential areas of concern. Specifically, this work depicts the expected monthly density of 84 marine species and taxa within each of the 29 active wind energy lease areas plus a 10 km buffer to account for nearby activity. We then compare these densities to subregional thresholds, evaluated as the 90th percentile of the subregion’s monthly density, to provide comparisons across the shelf region. This analysis synthesizes the most recent spatial distribution models of 31 marine mammal taxa (26 species and 5 guilds), 49 seabird species and 4 sea turtle species to provide a unified evaluation of the major marine wildlife in the region. Out of the 84 species and taxa analyzed, 56 exhibit levels of expected density in wind energy areas that exceed the corresponding 90th percentile subregional threshold at some point throughout the year. These results represent an initial assessment in the broader Occurrence, Exposure, Response, and Consequence (OERC) framework, originally developed by the U.S. Navy for marine species risk assessments. These results offer valuable guidance to marine spatial planners, management agencies and offshore wind developers on the expected locations and timing of interaction risk to wildlife species in or near wind energy areas across the region.

17 WIND ENERGY↗

A template of information needs for decision-making about delaying remediation on contaminated lands to protect human health

The contamination legacy of industrialization, militarization, and nuclear arms race poses current or future risks to populations and the environment. Responsible parties and regulators make decisions regarding which sites to clean up, how, how much, and when. This study aimed to provide an information needs template to evaluate and reduce risks to human health when considering whether to initiate or delay remediation. This investigation focused on four aspects of timing and prioritization: 1) management, planning and implementation, 2) source terms, pathways, and exposures, 3) risks and receptors, and 4) external drivers. Within each type, issues were identified and described. Management class included personnel, health and safety data, funding, equipment, and structural integrity. Source term included contaminant sources, pathways, initiating events, and barriers to exposure. Risk included types and exposures to workers and general public. External drivers included regulatory framework, stakeholders, Congressional mandates, and economic and social contexts. Risk may increase over time as contamination spreads, enters aquifers, and reaches receptors, and may decline as radionuclides decay, and plumes dissipate. The overall objective was to provide a template of information that is useful to managers and regulators, and might be used by the public to understand the risks and benefits of re-prioritization cleanup.

Environmental Sciences & Ecology↗

Supplier Research & Analysis Approach

"The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supplier Research and Analysis (SRA) capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 95 reports since its start-up in early 2015. This presentation addresses the approach, methodology and performance of the Supplier Research and Analysis (SRA) capability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability."

supplier research and analysis↗