Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Engineering Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Lessons Learned With Risk Management: A Systems Engineer’s Perspective

Risk management is a communications device that, when executed as an essential task, enables systems engineering to effectively balance risk across the project. Developing and baselining risks is an essential continuous task to ensure top project concerns both from bottom up and top down are being mitigated. Risk management provides the opportunity to avoid the consequence of the risk when mitigation steps start early enough. Just discussing risk with all the project flight elements during development, even if no risks are open, provides an excellent communication opportunity between systems engineering and those elements, ensuring concerns and worries have a platform for discussion. A well-managed risk identification process will identify concerns that are serious but not being clearly communicated, and it will enable mitigation of those potential problems before they cause a failure. Effective risk management requires considerable time and effort, but that effort will save time and money across the development. Risk management must be frequent enough to be useful and in depth enough to bring out emerging issues. It also requires a trusting relationship between the lead systems engineer and element and/or subsystem leads. The discussions need to be with the right number of individuals (typically a handful) and the right duration in time (typically an hour a month). Outside of these risk working groups, there is a formal management process to input, status, and disposition risks, and a monthly Risk Management Board meeting where key project stakeholders are informed. This paper provides good guidance on effective risk management from a systems engineering perspective and provides project lessons learned from the NASA spaceflight missions NICER, Landsat 9, LRO, and OSIRIS-REx to demonstrate the effectiveness of risk management.

Lessons Learned

Lessons Learned With Risk Management: A Systems Engineer's Perspective

Risk management is a communications device that, when executed as an essential task, enables systems engineering to effectively balance risk across the project. Developing and baselining risks is an essential continuous task to ensure top project concerns both from bottom up and top down are being mitigated. Risk management provides the opportunity to avoid the consequence of the risk when mitigation steps start early enough. Just discussing risk with all the project flight elements during development, even if no risks are open, provides an excellent communication opportunity between systems engineering and those elements, ensuring concerns and worries have a platform for discussion. A well-managed risk identification process will identify concerns that are serious but not being clearly communicated, and it will enable mitigation of those potential problems before they cause a failure. Effective risk management requires considerable time and effort, but that effort will save time and money across the development. Risk management must be frequent enough to be useful and in depth enough to bring out emerging issues. It also requires a trusting relationship between the lead systems engineer and element and/or subsystem leads. The discussions need to be with the right number of individuals (typically a handful) and the right duration in time (typically an hour a month). Outside of these risk working groups, there is a formal management process to input, status, and disposition risks, and a monthly Risk Management Board meeting where key project stakeholders are informed. This paper provides good guidance on effective risk management from a systems engineering perspective and provides project lessons learned from the NASA spaceflight missions NICER, Landsat 9, LRO, and OSIRIS-REx to demonstrate the effectiveness of risk management.

Lessons Learned

How Systems Engineering and Risk Management Defend Against Murphy's Law and Human Error

Systems Engineering and Risk Management processes can work synergistically to defend against the causes of many mission ending failures. Defending against mission ending failures is facilitated by fostering a team that has a healthy respect for Murphy's Law and a team with a of curiosity for how things work, how they can fail, and what they need to know. This curiosity is channeled into making the unknowns known or what is uncertain more certain. Efforts to assure mission success require the expenditure of energy in the following areas: 1. Understanding what defines Mission Success as guided by the customer's needs, objectives and constraints. 2. Understanding how the system is supposed to work and how the system is to be produced, fueled by the curiosity of how the system should work and how it should be produced. 3. Understanding how the system can fail and how the system might not be produced on time and within cost, fueled by the curiosity of how the system might fail and how production might be difficult. 4. Understanding what we need to know and what we need learn for proper completion of the above three items, fueled by the curiosity of what we might not know in order to make the best decisions.

Bay, Michael

ESMD Risk Management Workshop: Systems Engineering and Integration Risks

This report has been developed by the National Aeronautics and Space Administration (NASA) Exploration Systems Mission Directorate (ESMD) Risk Management team in close coordination with the Systems Engineering Team. This document provides a point-in-time, cumulative, summary of key lessons learned derived from the SE RFP Development process. Lessons learned invariably address challenges and risks and the way in which these areas have been addressed. Accordingly the risk management thread is woven throughout the document.

Systems Engineering

Space systems engineering and risk management - joined at the hip

This paper explores the separate skills and capabilities practiced until now, and the powerful coupling to be achieved, practically and effectively, in implementing a space mission, from inception (pre-phase A) to the end of Operations (phase E). The use of risk assessment techniques in balancing cost risk against performance risk, and the application of the systems engineering team in these trades, is the key to achieving this new implementation paradigm.

systems engineering

Forward for the new edition of: “What Every Engineer Should Know About Risk Engineering and Management"

In aerospace and engineering in general, the major metrics are capability, cost, and safety/risk. With the increasingly rapid emergence and utilization of new technologies and systems of increasing complexity, ensuring safety becomes more difficult. The technology and practice/applications of safety/risk technologies require updating in concert with capability and systems technology changes. Hence the new, updated edition of this risk engineering book. Major changes in technology and applications, now and going forward, increasingly involve artificial intelligence (AI)/autonomy and complex systems, which are rapidly developing and moving targets when it comes to risk/safety analysis. These introduce both new risks and safety issues, and they alter more usual ones. The current reality is that often the best AI is when it is “Black Boxed”, developed “independently”, without detailed human understanding of how and by what processes decisions and results are produced. There are ongoing efforts to make the AI processes more understandable by humans, with results to be determined. Also, trusted and true autonomy is free of human intervention, which would require machines to ideate to solve in real time issues that arise due to unknown unknowns and even known unknowns. Machines using generative adversarial network (GANs) and other approaches are beginning to ideate. Overall, the capabilities and practice of AI/autonomy utilization is a work in progress with the rate of progress substantial and the impacts upon system risk/safety major.

Dennis M. Bushnell

Risk Reduction on X-33/RLV Engines

Risk management has received considerable attention in the X-33 and Reusable Launch Vehicle (RLV) program due to aggressive schedules, limited funding. and planned private investment to develop the commercial VentureStar vehicle. As an X-33 and RLV team member and main propulsion supplier, Boeing Rocketdyn Propulsion and Power has addressed risk through a methodical application of systems engineering in identifying, assessing, and mitigating risks. The methods employed involve rigorous risk mitigation planning early in development, continuous risk monitoring and assessment during the course of development, and the systematic verification of compliance with technical requirements prior to delivery. In addition, an engine system reliability analysis was conducted to reduce risk. In July 1996, NASA selected Lockheed Martin's "Skunk Works" (LMSW) as the lead contractor for the X-33 and RLV program. The X-33 vehicle is a half-scale pathfinder for the full-scale RLV. The LMSW RLV design is a lifting body shaped vehicle employing linear aerospike engine provided propulsion. The initial X-33 flight is planned for the summer of 2000, and the initial VentureStar flight is planned for between 2005 and 2007.

Crowley, Tim

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

Risk Posture

Portable Electron Microscopy for ISS and Beyond

Advances in space exploration have evolved in lockstep with key technology advances in diverse fields such as materials science, biological science, and engineering risk management. Research in these areas, where structure and physical processes come together, can proceed rapidly in part due to sophisticated ground-based analytical tools that help re-searchers develop technologies and engineering processes that push frontiers of human space exploration. Electron microscopes (EM) are an example of such a workhorse tool, lending a unique blend of strong optical scattering, high native resolution, large depth of focus, and spectroscopy via characteristic X-ray emission, providing exquisite high-magnification structural imaging and chemical analysis. Ground-based EM’s have been essential in NASA research for many years. In particular, in mineralogy and petrology, EM is used to understand the origin and evolution of the solar system, particularly rocky bodies. In microbiology, EM has helped visualize the architecture of tissues and cells. In engineering/materials science, EM has been used to characterize particulate debris in air and water samples, determine pore sizes in ceramics/catalysts, understand the nature of fibers, determine composition and morphology of new and existing materials, and characterize micro-textures of vapor deposited films. EM is highly effective at investigating a wide variety of nanoscale materials/biomaterials at the core of many of NASA’s inquiries. Despite exquisite optical performance and versatility, EM’s are traditionally large, heavy, and have high power consumption. They are also expensive so they tend to be housed at universities and large research institutions, or at major industrial laboratory sites with support staff, supplies, and skilled operators. Since most organizations cannot support their own EM, samples are often sent to these large institutions and service centers to be imaged, at great expense and of-ten with delay of weeks to months for complex analyses. Complexity, high cost, and maintenance associated with collecting EM image data has until now severely limited fields in which EM is used. Making EM accessible outside constrained terrestrial laboratory environments will bring EM’s performance and versatility to a much broader range of scientific and engineering endeavors, including in space.

Own, C. S.

Integrated Systems Engineering, Safety, Reliability and Risk Management – Minimizing Black Swan Events

This paper examines key barriers that can possibly inhibit safe and reliable mission execution and, in the worst case, result in loss of human life due to many unknown contributory factors that can lead to Black Swan events. Some of the representative contributory factors include decision errors, overconfidence and a host of common causes including cultural and human factors. Decisions are always easy to criticize in hindsight when more information is available after a major accident. Depending on the type and complexity of the project and/or mission, the catastrophic risks of drifting into failure can be alleviated by implementing uniquely and strategically tailored Integrated-System-of-Systems, dynamic, risk-informed decision management processes. This paper presents some of the lessons learned from James Webb Space Telescope (JWST), NASA’s Human Space Flight program, and industry that provide motivation to organizations working on mega-complex missions to prudently accomplish targeted mission success. These lessons are important for future human Lunar, Mars and Beyond missions planned to be pursued by NASA through a public-private partnership using nimble but effective safety-conscious, proven sound engineering practices including implementation of integrated risk mitigation practices.

SLS

NASA System Safety Handbook. Volume 2: System Safety Concepts, Guidelines, and Implementation Examples

This is the second of two volumes that collectively comprise the NASA System Safety Handbook. Volume 1 (NASASP-210-580) was prepared for the purpose of presenting the overall framework for System Safety and for providing the general concepts needed to implement the framework. Volume 2 provides guidance for implementing these concepts as an integral part of systems engineering and risk management. This guidance addresses the following functional areas: 1.The development of objectives that collectively define adequate safety for a system, and the safety requirements derived from these objectives that are levied on the system. 2.The conduct of system safety activities, performed to meet the safety requirements, with specific emphasis on the conduct of integrated safety analysis (ISA) as a fundamental means by which systems engineering and risk management decisions are risk-informed. 3.The development of a risk-informed safety case (RISC) at major milestone reviews to argue that the systems safety objectives are satisfied (and therefore that the system is adequately safe). 4.The evaluation of the RISC (including supporting evidence) using a defined set of evaluation criteria, to assess the veracity of the claims made therein in order to support risk acceptance decisions.

Safety Case

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon

NASA Crew and Cargo Launch Vehicle Development Approach Builds on Lessons from Past and Present Missions

The United States (US) Vision for Space Exploration, announced in January 2004, outlines the National Aeronautics and Space Administration's (NASA) strategic goals and objectives, including retiring the Space Shuttle and replacing it with new space transportation systems for missions to the Moon, Mars, and beyond. The Crew Exploration Vehicle (CEV) that the new human-rated Crew Launch Vehicle (CLV) lofts into space early next decade will initially ferry astronauts to the International Space Station (ISS) Toward the end of the next decade, a heavy-lift Cargo Launch Vehicle (CaLV) will deliver the Earth Departure Stage (EDS) carrying the Lunar Surface Access Module (LSAM) to low-Earth orbit (LEO), where it will rendezvous with the CEV launched on the CLV and return astronauts to the Moon for the first time in over 30 years. This paper outlines how NASA is building these new space transportation systems on a foundation of legacy technical and management knowledge, using extensive experience gained from past and ongoing launch vehicle programs to maximize its design and development approach, with the objective of reducing total life cycle costs through operational efficiencies such as hardware commonality. For example, the CLV in-line configuration is composed of a 5-segment Reusable Solid Rocket Booster (RSRB), which is an upgrade of the current Space Shuttle 4- segment RSRB, and a new upper stage powered by the liquid oxygen/liquid hydrogen (LOX/LH2) J-2X engine, which is an evolution of the J-2 engine that powered the Apollo Program s Saturn V second and third stages in the 1960s and 1970s. The CaLV configuration consists of a propulsion system composed of two 5-segment RSRBs and a 33- foot core stage that will provide the LOX/LED needed for five commercially available RS-68 main engines. The J-2X also will power the EDS. The Exploration Launch Projects, managed by the Exploration Launch Office located at NASA's Marshall Space Flight Center, is leading the design, development, testing, and operations planning for these new space transportation systems. Utilizing a foundation of heritage hardware and management lessons learned mitigates both technical and programmatic risk. Project engineers and managers work closely with the Space Shuttle Program to transition hardware, infrastructure, and workforce assets to the new launch systems, leveraging a wealth of knowledge from Shuffle operations. In addition, NASA and its industry partners have tapped into valuable Apollo databases and are applying corporate wisdom conveyed firsthand by Apollo-era veterans of America s original Moon missions. Learning from its successes and failures, NASA employs rigorous systems engineering and systems management processes and principles in a disciplined, integrated fashion to further improve the probability of mission success.

Dumbacher, Daniel L.

Engineering Management Capstone Project EM 697: Compare and Contrast Risk Management Implementation at NASA and the US Army

NASA at Marshall Space Flight Center (MSFC) and the U.S. Army at Redstone Arsenal were analyzed to determine whether they were successful in implementing their risk management program. Risk management implementation surveys were distributed to aid in this analysis. The scope is limited to NASA S&MA (Safety and Mission Assurance) at MSFC, including applicable support contractors, and the US Army Engineering Directorate, including applicable contractors, located at Redstone Arsenal. NASA has moderately higher risk management implementation survey scores than the Army. Accordingly, the implementation of the risk management program at NASA is considered good while only two of five of the survey categories indicated that the risk management implementation is good at the Army.

Brothers, Mary Ann