Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “performance based security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Identification of Security related Bug Reports via Text Mining using Supervised and Unsupervised Classification

This paper is focused on automated classification of software bug reports to security and non-security related, using both supervised and unsupervised approaches. For both approaches, three types of feature vectors are used. For supervised learning, we experiment with multiple learning algorithms and training sets with different sizes. Furthermore, we propose a novel unsupervised approach based on anomaly detection. The evaluated is based on three NASA datasets. The results show that supervised classification is affected more by the learning algorithms than by feature vectors and using only 25% of the data for training provides as good results as if 90% of data are used for training. Both supervised and unsupervised learning can be used for identification of security bug reports; the former slightly outperforms the latter at the expense of labeling the testing set. In general, the performance differs across datasets, mainly due to the different amounts of security related information.

Goseva-Popstojanova, Katerina↗

Entry, Descent, and Landing Analysis for the OSIRIS-REx Sample Return Capsule

The Origins, Spectral Interpretation, Resource Identification, and Security – Regolith Explorer (OSIRIS-REx) sample return capsule (SRC) returned to Earth on September 24, 2023, safely landing in the Utah Test and Training Range (UTTR). To ensure a safe and successful landing, a pair of high-fidelity EDL simulations, based on the Program to Optimize Simulated Trajectories (POST) architecture, were used to regularly assess the latest orbit determination (OD) solution from the navigation team, making predictions on Entry, Descent, and Landing (EDL) performance and SRC landing location. The results from these analyses fed into the decision processes for the final trajectory correction maneuvers (TCM’s) and SRC release. The models and methods of analysis will be discussed and a comparison of the final pre-entry landing prediction against the observed landing location will be presented along with an assessment of the best estimates of day-of-entry environmental conditions.

Scott R Francis↗

Evaluating Process Effectiveness to Reduce Risk

It is well documented that government agencies do not have the same incentive as the private sector to focus on process effectiveness and continual improvement of those processes. It is also well documented whenever government agencies fail to deliver efficient, effective, consistent, and fair services to the citizens. In spite of the various "reinventing government" and "effectiveness initiatives" of the past decades, and in spite of the efforts on the part of many agencies to improve, government in general still lags behind industry in creating a culture of effective processes and systems. While the tragic events that unfolded recently in Flint, Michigan, teach us that running government "like a business" does not always take the needs of the citizenry into account, there are many lessons and techniques from the private sector that government agencies can use to improve. The incentive to improve, while mandated by various administrations1, needs to come from within the workforce, in order to effectively take root. The best, most effective incentive is to reduce, control or eliminate risk. Government agencies face some of the same risks as the private sector, while some are unique. While ISO 310002 has been around since 2009, risk has taken on increased visibility within the private sector with the advent of the emphasis on risk-based thinking in ISO 9001:20153. The relationship between risk-based thinking and effective processes is simple and direct. Those processes that are well thought out and standardized (i.e. Plan-Do-Check-Act), will have taken into account the applicable policy, statutory, regulatory, safety, quality and technical parameters, which may not occur to someone performing the process with minimal experience or training; and thus protect the employees, the public and the agency from statutory and regulatory violations; delay in providing services; non-delivery of services; harm to public or employee safety and health; cost overruns; breaches in security; loss of confidence in government; failure of publicly funded projects; damage to the environment; ethics violations, and the list goes on; with local, national and even international consequences. The Plan-Do-Check-Act process, also known as the "process approach" can be used at any time to establish and standardize a process, and it can also be used to check periodically for "process creep" (i.e., informal, unauthorized changes that have occurred over time), any necessary updates and improvements. While ISO 9001 compliance is not mandated for all government agencies, if interpreted correctly, it can be useful in establishing a framework and implementing effective management systems and processes.4 Another method that can be used to evaluate effectiveness is the scorecard definitions in Mallory's Process Management Standard5 as a basis for evaluating work on the process level on effective, and continuously improved and improving processes. With processes on the lower end of the scale, agencies are vulnerable to a great many risks, with employees and managers making up many of the rules as they go, leading to the above listed negative results. Without clear guidance for nominal operations, off-nominal situations can, and do, increase the likelihood of chaos. In an increasingly technical environment, with inter-agency communication and collaboration becoming the norm, agencies need to come to grips with the fact that processes can become rapidly outdated, and that the technical community should take on an increased role in the maturation of the agency's processes. Industry has long known that effective processes are also efficient, and process improvement methods such as Kaizen, Lean, Six Sigma, 5S, and mistake proofing lead to increased productivity, improved quality, and decreased cost. Again, government agencies have different concerns, but inefficiencies and mistakes can have dire and wide reaching consequences for the public that they serve. While no one goes to work planning to cause harm, it is up to agencies to establish upper level systems, which make establishment and compliance with processes possible. Again, Mallory provides us with a Systems Management Standard6, similar to the Process Management Standard, with a scale of 0-5 for systems effectiveness and maturity. Deming determined that "eighty-five percent of the reasons for failure are deficiencies in the systems and process rather than the employee. The role of management is to change the process rather than badgering individual employees to do better." 7 It is not just the working level employees who need effective processes, but the mid-and upper level managers as well. A disciplined management culture sets the tone for the employees, aids both routine and off-nominal decision-making, and incorporates risk -based thinking into the systems and processes as a matter of normal activity. Figure 1, illustrates the relationship between ineffective and effective processes and risk, through the use of the "stoplight" colors that are commonly used to show serious situations (red), situations which may be improving or deteriorating depending on trends (yellow), and situations that are under control and continuously improved (green).

Shepherd, Christena C.↗

Bayesian batch optimization for molybdenum versus tungsten inertial confinement fusion double shell target design

Access to reliable, clean energy sources is a major concern for national security. Much research is focused on the “grand challenge” of producing energy via controlled fusion reactions in a laboratory setting. For fusion experiments, specifically inertial confinement fusion (ICF), to produce sufficient energy, the fusion reactions in the ICF fuel need to become self-sustaining and burn deuterium-tritium (DT) fuel efficiently. The recent record-breaking NIF ignition shot was able to achieve this goal as well as produce more energy than used to drive the experiment. This achievement brings self-sustaining fusion-based power systems closer than ever before, capable of providing humans with access to secure, renewable energy. In order to further progress toward the actualization of such power systems, more ICF experiments need to be conducted at large laser facilities such as the United States's National Ignition Facility (NIF) or France's Laser Mega-Joule. The high cost per shot and limited number of shots that are possible per year make it prohibitive to perform large numbers of experiments. As such, experimental design relies heavily on complex predictive physics simulations for high-fidelity “preshot” analysis. These multidimensional, multi-physics, high-fidelity simulations have to account for a variety of input parameters as well as modeling the extreme conditions (pressures and densities) present at ignition. Such simulations (especially in 3D) can become computationally prohibitive to turn around for each ICF experiment. In this work, we explore using Bayesian optimization with Gaussian processes (GPs) to find optimal designs for ICF double shell targets, while keeping computational costs to manageable levels. These double shell targets have an inner shell that grades from beryllium on the outer surface to the higher Z material molybdenum, as opposed to the nominally used tungsten, on the inside in order to trade off between the high performance associated with high density inner shells and capsule stability. We describe our results for “capsule-only” xRAGE simulations to study the physics between different capsule designs, inner shell materials, and potential for future experiments.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

The Database Query Support Processor (QSP)

The number and diversity of databases available to users continues to increase dramatically. Currently, the trend is towards decentralized, client server architectures that (on the surface) are less expensive to acquire, operate, and maintain than information architectures based on centralized, monolithic mainframes. The database query support processor (QSP) effort evaluates the performance of a network level, heterogeneous database access capability. Air Force Material Command's Rome Laboratory has developed an approach, based on ANSI standard X3.138 - 1988, 'The Information Resource Dictionary System (IRDS)' to seamless access to heterogeneous databases based on extensions to data dictionary technology. To successfully query a decentralized information system, users must know what data are available from which source, or have the knowledge and system privileges necessary to find out this information. Privacy and security considerations prohibit free and open access to every information system in every network. Even in completely open systems, time required to locate relevant data (in systems of any appreciable size) would be better spent analyzing the data, assuming the original question was not forgotten. Extensions to data dictionary technology have the potential to more fully automate the search and retrieval for relevant data in a decentralized environment. Substantial amounts of time and money could be saved by not having to teach users what data resides in which systems and how to access each of those systems. Information describing data and how to get it could be removed from the application and placed in a dedicated repository where it belongs. The result simplified applications that are less brittle and less expensive to build and maintain. Software technology providing the required functionality is off the shelf. The key difficulty is in defining the metadata required to support the process. The database query support processor effort will provide quantitative data on the amount of effort required to implement an extended data dictionary at the network level, add new systems, adapt to changing user needs, and provide sound estimates on operations and maintenance costs and savings.

Source record↗

Runway Safety Monitor Algorithm for Single and Crossing Runway Incursion Detection and Alerting

The Runway Safety Monitor (RSM) is an aircraft based algorithm for runway incursion detection and alerting that was developed in support of NASA's Runway Incursion Prevention System (RIPS) research conducted under the NASA Aviation Safety and Security Program's Synthetic Vision System project. The RSM algorithm provides warnings of runway incursions in sufficient time for pilots to take evasive action and avoid accidents during landings, takeoffs or when taxiing on the runway. The report documents the RSM software and describes in detail how RSM performs runway incursion detection and alerting functions for NASA RIPS. The report also describes the RIPS flight tests conducted at the Reno/Tahoe International Airport (RNO) and the Wallops Flight Facility (WAL) during July and August of 2004, and the RSM performance results and lessons learned from those flight tests.

Green, David F., Jr.↗

Classifying Aircraft using Velocity Data with Support Vector Machines and Likelihood Ratio Tests

Timely classification of aircraft is important for small unmanned aerial system (sUAS) technologies, such as onboard collision avoidance systems, and aerial perimeter security for prisons and sports venues. This work uses velocity-based metrics to classify multi-rotor sUAS, fixed wings UAS, and general aviation planes using two classification methods: Support Vector Machines (SVM), and Likelihood Ratio (LR) tests. We found that a 96% classification accuracy is achieved when either classifier is trained using average speed derived from flight controller data or radar data and tested with one second of radar data. Further, we show that LR tests perform similarly to SVM for single metric classification. In addition, we present two novel metrics for classifying aircraft: log variance of absolute change in speed, and log variance of relative change in speed. Finally, we discuss challenges associated with training classifiers with flight controller data but testing on radar data.

Logan T Dihel↗

Scale up production of carbon fibers from petroleum mesophase pitch

This work investigates the scale-up of pitch precursors for the carbon fiber market using mesophase pitch formulated and produced by Advanced Carbon Products Technologies’ (ACPT’s) patented mesophase pitch processing technology. Through use of its patented process, ACPT developed strategic materials by converting petroleum-based pitch into a high-value, low-cost, carbon-rich feedstock for carbon fiber and other materials critical to our national security. The team successfully developed processing criteria for the tailored mesophase pitch material that can be processed further into precursor and carbon fiber. Processability of the mesophase pitch into precursor and carbon fiber was demonstrated at scale. The resulting materials sequester the carbon that would otherwise be burned and released into the atmosphere, making this an environmentally friendly way to produce these materials in the United States.Pitch-based carbon fibers offer a promising pathway toward cost-effective, high-performance materials for structural and high-modulus composite applications; however, adoption has been limited by challenges in precursor processability and scale-up. In this work, tailored isotropic and mesophase petroleum-derived pitch materials were developed and evaluated for precursor and carbon fiber production through a collaborative effort between Oak Ridge National Laboratory (ORNL) and ACPT. Processing conditions were established at ORNL’s Carbon Fiber Technology Facility to enable stable melt-blowing of pitch-based precursors under continuous operation. Mesophase pitch precursor fibers were produced following oxidation and carbonization, corresponding to a diameter shrinkage of approximately 12%–13% and an estimated mass yield of about 75%–80%. Continuous melt-blowing steady-state operation was demonstrated over time, indicating robust process stability. Melt-blowing was achieved at throughput rates of approximately 20 lb/h⁻¹, validating the commercial viability of petroleum-derived pitch feedstocks for fiber production. Further studies are required to tailor carbon fiber microstructure and properties for specific composite applications.

99 GENERAL AND MISCELLANEOUS↗

Electrically Heated Testing of the Kilowatt Reactor Using Stirling Technology (KRUSTY) Experiment Using a Depleted Uranium Core

The Kilopower project aims to develop and demonstrate scalable fission-based power technology for systems capable of delivering 110 kW of electric power with a specific power ranging from 2.5 - 6.5 Wkg. This technology could enable high power science missions or could be used to provide surface power for manned missions to the Moon or Mars. NASA has partnered with the Department of Energys National Nuclear Security Administration, Los Alamos National Labs, and Y-12 National Security Complex to develop and test a prototypic reactor and power system using existing facilities and infrastructure. This technology demonstration, referred to as the Kilowatt Reactor Using Stirling TechnologY (KRUSTY), will undergo nuclear ground testing in the summer of 2017 at the Nevada Test Site. The 1 kWe variation of the Kilopower system was chosen for the KRUSTY demonstration. The concept for the 1 kWe flight system consist of a 4 kWt highly enriched Uranium-Molybdenum reactor operating at 800 degrees Celsius coupled to sodium heat pipes. The heat pipes deliver heat to the hot ends of eight 125 W Stirling convertors producing a net electrical output of 1 kW. Waste heat is rejected using titanium-water heat pipes coupled to carbon composite radiator panels. The KRUSTY test, based on this design, uses a prototypic highly enriched uranium-molybdenum core coupled to prototypic sodium heat pipes. The heat pipes transfer heat to two Advanced Stirling Convertors (ASC-E2s) and six thermal simulators, which simulate the thermal draw of full scale power conversion units. Thermal simulators and Stirling engines are gas cooled. The most recent project milestone was the completion of non-nuclear system level testing using an electrically heated depleted uranium (non-fissioning) reactor core simulator. System level testing at the Glenn Research Center (GRC) has validated performance predictions and has demonstrated system level operation and control in a test configuration that replicates the one to be used at the Device Assembly Facility (DAF) at the Nevada National Security Site. Fabrication, assembly, and testing of the depleted uranium core has allowed for higher fidelity system level testing at GRC, and has validated the fabrication methods to be used on the highly enriched uranium core that will supply heat for the DAF KRUSTY demonstration.

Briggs, Maxwell H.↗

Modal Test of the NASA Mobile Launcher at Kennedy Space Center

The NASA Mobile Launcher (ML), located at Kennedy Space Center (KSC), has recently been modified to support the launch of the new NASA Space Launch System (SLS). The ML is a massive structure—consisting of a 345-foot tall tower attached to a two-story base, weighing approximately 10.5 million pounds—that will secure the SLS vehicle as it rolls to the launch pad on a Crawler Transporter, as well as provide a launch platform at the pad. The ML will also provide the boundary condition for an upcoming SLS Integrated Modal Test (IMT). To help correlate the ML math models prior to this modal test, and allow focus to remain on updating SLS vehicle models during the IMT, a ML-only experimental modal test was performed in June 2019. Excitation of the tower and platform was provided by five uniquely-designed test fixtures, each enclosing a hydraulic shaker, capable of exerting thousands of pounds of force into the structure. For modes not that were not sufficiently excited by the test fixture shakers, a specially-designed mobile drop tower provided impact excitation at additional locations of interest. The response of the ML was measured with a total of 361 accelerometers. Following the random vibration, sine sweep vibration, and modal impact testing, frequency response functions were calculated and modes were extracted for three different configurations of the ML in 0 Hz to 12 Hz frequency range. This paper will provide a case study in performing modal tests on large structures by discussing the Mobile Launcher, the test strategy, an overview of the test results, and recommendations for meeting a tight test schedule for a large-scale modal test.

Hydraulic shakers↗

FiberFlex: Real-time FPGA-based Intelligent and Distributed Fiber Sensor System for Pedestrian Recognition

In recent years, security monitoring of public places and critical infrastructure has heavily relied on the widespread use of cameras, raising concerns about personal privacy violations. To balance the need for effective security monitoring with the protection of personal privacy, we explore the potential of optical fiber sensors for this application. This article proposes FiberFlex, an intelligent and distributed fiber sensor system. Ultizing Field Programmable Gate Arrays (FPGA) high-level synthesis (HLS) acceleration, FiberFlex offers real-time pedestrian detection by co-designing the entire pipeline of optical signal acquisition, processing, and recognition networks based on the principles of optical fiber sensing. As a promising alternative to traditional camera-based monitoring systems, FiberFlex achieves pedestrian detection by analyzing the vibration patterns caused by pedestrian footsteps, enabling security monitoring while preserving individual privacy. FiberFlex comprises three modules: First , fiber-optic sensing system: A fiber-optic distributed acoustic sensing (DAS) system is built and used to measure the ground vibration waves generated by people walking. Second , algorithms: We first collect the training data by measuring the ground vibration waves, label the data, and use the data to train the neural network models to perform pedestrian recognition. Third , hardware accelerators: We use HLS tools to design hardware modules on FPGA for data collection and pre-processing and integrate them with the downstream neural network accelerators to perform in-line real-time pedestrian detection. The final detection results are sent back from FPGA to the host CPU. We implement our system FiberFlex with the in-house built DAS system and AMD/Xilinx Kintex7 FPGA KC705 board and verify the whole system using the real-world collected data. We conduct recognition tests on five test subjects of varying ages, heights, and weights in a fixed sensing area. Each subject experienced 20 real-time recognition tests using their daily walking habits, and the subjects were given adequate rest between tests. After 100 tests on five test subjects, the overall real-time recognition accuracy exceeded \(88.0\%\) . The whole system uses 55 W of power, 33 W in the optical DAS system and 22 W in the FPGA. Relying on its end-to-end interdisciplinary design, FiberFlex seamlessly combines fiber-optic sensors with FPGA accelerators to enable low-power real-time security monitoring without compromising privacy, making it a valuable addition to the existing security monitoring network. According to FiberFlex, more valuable research can be conducted in the future, such as fall monitoring for the elderly, migration of identification networks between different application scenarios, and improvement of anti-interference performance in more complex environments. In future perception networks, where the “eyes” are not feasible, let’s use fiber optic touch instead.

Distributed↗

Estimating Tropical Cyclone Threats to Floating Rigs in the Gulf of Mexico

Offshore drilling operations in the Gulf of Mexico are particularly vulnerable during hurricane season. When a weather threat arises, a decision to evacuate the rig and/or move to a safe location may need to be made. Securing the well, evacuating, and/or moving to a safe location can take a considerable amount of time. This transition time is called T-time. T-time is not only rig dependent, but also depends on the activity being performed at the time of the threat. For these reasons, it is important to assess tropical cyclone threats and the estimated time it will take the storm to reach the rig location from the time it is first detected. The objective of this study is to use 50 years of cyclone history from a National Oceanic and Atmospheric Administration’s (NOAA) database, the International Best Track Archive for Climate Stewardship (IBTrACS) to estimate cyclone threats at any location in the Gulf of Mexico. The cyclone threat is estimated based on the rig location as well as the start date and duration of the offshore activity. By threat, it is meant the likelihood that a specific location with an associated offshore activity lies within the forecasted track cone and storm size of the upcoming cyclone. Three representative rig locations in the Gulf of Mexico were selected as assessment sites to evaluate the threat of incoming cyclones for different T-times. To conduct this tropical cyclone study, an Excel spreadsheet tool was developed to automate the analysis of the tropical cyclone data. The spreadsheet tool allows the user to input any location (i.e., longitude and latitude) in the Gulf of Mexico and displays a list of historical cyclones that have passed within 150 nautical miles of that location during the activity period selected by the user. In addition, the tool allows the user to input any T-time to assess the threat of cyclones that would not provide adequate time to secure the well, evacuate, and/or move to a safe location.

Offshore Oil Drilling↗

BeyondFingerprinting: AI-guided discovery of robust materials & processes

BeyondFingerprinting was a 2021-2024 Sandia Grand Challenge LDRD exploring the potential to develop new resilient materials and manufacturing processes by taking an artificial-intelligence (AI)-guided approach that integrates human-subject-matter expertise with algorithms enriched with physics-based constraints to unearth process-structure-property correlations. Such algorithms, trained on high-throughput experiments and simulations, are shown to serve as surrogate models that efficiently detect key “fingerprints” in materials data, prognose material performance, and guide effective process improvements. To accelerate broader adoption across mission areas, this AI-guided approach was demonstrated with three complex process-centric exemplars: electroplating, physical vapor deposition, and laser powder bed fusion. Together, these exemplars impact nearly every hardware component relevant to DOE and NNSA national security missions.

36 MATERIALS SCIENCE↗

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE↗

Development Status of the Advanced Life Support On-Line Project Information System

The Advanced Life Support Program has recently accelerated an effort to develop an On-line Project Information System (OPIS) for research project and technology development data centralization and sharing. The core functionality of OPIS will launch in October of 2005. This paper presents the current OPIS development status. OPIS core functionality involves a Web-based annual solicitation of project and technology data directly from ALS Principal Investigators (PIS) through customized data collection forms. Data provided by PIs will be reviewed by a Technical Task Monitor (TTM) before posting the information to OPIS for ALS Community viewing via the Web. The data will be stored in an object-oriented relational database (created in MySQL(R)) located on a secure server at NASA ARC. Upon launch, OPIS can be utilized by Managers to identify research and technology development gaps and to assess task performance. Analysts can employ OPIS to obtain.

Levri, Julie A.↗

Blockchain Application Within a Multi-Sensor Satellite Architecture

With the thrust towards multi-sensor satellite architectures for earth and space exploration, such as constellations and swarms, new technologies are required to enable the transition to this future capability. One of the areas of interest is establishing secure, efficient and prioritized data and command communication pathways among ground and space-based sources for such systems. This paper presents early research results on the potential role, capabilities and value of blockchain usage within constellation and swarm satellite architectures. It demonstrates the use of blockchain's smart contract and distributed ledger capabilities for secure and prioritized multi-sensor satellite collaborative data exchanges, as well as the logging and tracking of command and control events. Adapting and utilizing this emerging technology will aid in addressing technology gaps expected from future constellation flight architectures, such as managing collective computational operations (correlation), dynamic and autonomous observation planning, time-critical events, and provenance tied to ground and space-based autonomous operations and control recordkeeping. In this scenario blockchain is applied in encrypted command transmittal to multiple, yet specific, entities enabling acknowledgement transmittals, performance scalability, and automatic event-based triggering.

Mital, Rohit↗

Capability Building Progression of an Insider Threat Mitigation Program at an International Research Reactor

The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Fostering Nuclear Security Culture through Effective Leadership: An Operational Perspective

Security culture plays a critical role in determining the effectiveness of an organization's security performance, making its significance impossible to overemphasize. It encompasses the collective values, shared perceptions, and habitual actions embraced by all individuals within a nuclear organization—from leadership to frontline staff. When the entire workforce recognizes the reality of potential threats, accepts that security is a shared duty, and integrates security-minded behavior into everyday routines, it fosters an environment where strong security practices are the norm. In such a setting, everyone can take pride and feel reassured in being part of an organization where a strong security culture is deeply embedded. Security culture is based on the broader concept of organizational culture. All organizations—whether families, social clubs, religious institutions, businesses, non-governmental organizations, or governments—possess an underlying culture shaped by core values and beliefs. These values and beliefs influence attitudes and drive behavior throughout the organization. While multiple factors contribute to the development of a strong security culture, leadership plays a particularly pivotal role. In organizations where security culture is well-established, leaders go beyond rhetoric; they demonstrate a genuine commitment to security through their actions. They implement policies and procedures that actively engage all employees, foster open dialogue around security concerns, and encourage teamwork in resolving issues. Furthermore, they reward proactive behavior and ensure that corrective actions are taken promptly. Regular assessments of the organization's security culture allow such leaders to gauge its effectiveness and take strategic steps to strengthen it when necessary. This paper leverages practical, real-world experience to guide leadership and senior management within nuclear organizations through the foundational steps of cultivating a robust, organization-wide culture of nuclear security. It emphasizes the critical importance of early leadership engagement in shaping this culture and outlines a comprehensive approach that includes strategic, tactical, and operational measures. Additionally, it explores methods for fostering a unified vision across all levels of the organization to ensure alignment, commitment, and continuous improvement in nuclear security practices.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗