Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Marine Energy Technology Development Risk Management Framework

Over the past decades, the global marine energy industry has suffered a number of serious technological and commercial setbacks. To help reduce the risks of industry failures and advance the development of new technologies, the U.S. Department of Energy (DOE) and the National Renewable Energy Laboratory (NREL) developed a Marine Energy Risk Management Framework in 2015, with this revision published in 2024. This risk management framework shall be utilized on all DOE Water Power Technologies Office (WPTO) projects that require system testing in the open water. By addressing uncertainties, the Marine Energy Risk Management Framework increases the likelihood of successful development of marine energy converter technology. It covers projects of any technology readiness level technology performance level (TPL) and all risk types (e.g. technological risk, regulatory risk, commercial risk) over the development cycle. This risk framework is not a substitute for other risk management procedures that may be required for marine operations, such as installations at sea, hoisting and rigging, safe diver operations, and other safety requirements. This risk framework is intended to meet DOE's risk management expectations for marine energy technology research and development efforts from WPTO. It also provides an overview of other relevant risk management tools and documentation.

16 TIDAL AND WAVE POWER↗

FEMP Cybersecurity Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. The tools are meant to help federal owners and operators to evaluate their overall cybersecurity posture. These tools are developed based on the NIST Cybersecurity framework, risk management framework, and DOE C2M2 architectures. Version 3 provides significant updates and features in ten areas

Ashley, Travis [Pacific Northwest National Laborat↗

A hierarchical-multiobjective framework for risk management

A broad hierarchical-multiobjective framework is established and utilized to methodologically address the management of risk. United into the framework are the hierarchical character of decision-making, the multiple decision-makers at separate levels within the hierarchy, the multiobjective character of large-scale systems, the quantitative/empirical aspects, and the qualitative/normative/judgmental aspects. The methodological components essentially consist of hierarchical-multiobjective coordination, risk of extreme events, and impact analysis. Examples of applications of the framework are presented. It is concluded that complex and interrelated forces require an analysis of trade-offs between engineering analysis and societal preferences, as in the hierarchical-multiobjective framework, to successfully address inherent risk.

Haimes, Yacov Y.↗

NASA Risk Management Handbook: Version 2.0, Part 1

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0. NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Uncertainty↗

NASA Risk Management Handbook: Version 2.0, Part 2

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0 (January 2020). NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Risk Leadership↗

An Integrated Paradigm for the Management of Delivery Risk in Electricity Markets: From Batteries to Insurance and Beyond

If power systems transition to integrate higher amounts of variable renewable energy sources, storage technologies, and distributed energy resources (DERs), new risk management frameworks are necessary to ensure cost-effective and reliable power system operations. Projects funded by the Advanced Research Projects Agency-Energy (ARPA-E) Performance-based Energy Resource Feedback, Optimization, and Risk Management (PERFORM) program aim to contribute new risk management frameworks by developing methods to quantify and manage risk at grid asset and system levels. The National Renewable Energy Laboratory (NREL) led a PERFORM project in collaboration with the Johns Hopkins University, the Electric Power Research Institute (EPRI), kWh Analytics, Packetized Energy, and Imperial Consultants (ICON). The project addressed two challenges related to risk management in electricity markets: managing net load imbalances and flexibility from DERs. This final technical report presents a list of project accomplishments, activities, and outputs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Artificial Intelligence in Nuclear Safeguards; Evaluating Safeguards and Security Risks and Benefits for Advanced and Small Modular Reactor Deployments

Rapidly growing interest in advanced and small modular reactor (A/SMR) technologies presents challenges as well as opportunities for implementing international safeguards and security. A/SMR deployments are expected to be more numerous, more geographically dispersed, and more varied in their designs, placing new demands on the data systems and analytical tools used to support oversight (Alberti et al., 2023; Canadian Nuclear Safety Commission et al., 2024). Because of this variability, the importance and reliance on data systems for A/SMR deployments is expected to be higher than for previous reactor generations. Artificial Intelligence and Machine Learning (AI/ML) offer potential capabilities to address the high variability inherent in A/SMR technology. The beneficiaries of AI-assisted tools include facility operators, government regulators, IAEA inspectors, and A/SMR vendors. This report analyzes how AI/ML-assisted technologies can strengthen the implementation of IAEA safeguards and security measures. It also identifies AI-assisted tools to strengthen operator, facility, and regulator knowledge management practices and examines the potential risks AI/ML-based tools may introduce to IAEA safeguards and security efforts. It concludes with a set of hypothetical, standards-style requirements for AI/ML systems used in safeguards contexts, grounded in an inspector-centric view of system verification. Despite the potential benefits of AI/ML systems, understanding potential intentional and unintentional failure modes is critical for ensuring adequate protection of nuclear materials and facilities. Unique features of A/SMRs including sealed cores, remote and novel paradigms of operation, off-site reactor fabrication, novel fuel forms, and varied refueling requirements, introduce challenges for traditional safeguards technological approaches (Pensado et al., 2024; Federation of American Scientists, 2025). AI/ML systems deployed to address these challenges may introduce new risks requiring systematic evaluation rooted in both AI-specific risk frameworks, such as the NIST AI Risk Management Framework (NIST AI RMF), and established cyber risk management standards such as NIST SP 800-30 (National Institute of Standards and Technology [NIST], 2023; NIST, 2012).

97 MATHEMATICS AND COMPUTING↗

Accelerated Materials Deployment in Advanced Nuclear Power Plants

The purpose of this report is to begin the development of a maximally efficient process for licensing and deploying new materials in Advanced Non-Light-Water Reactors (ANLWRs). Some new materials that are to be used in some new plants are seen as possibly introducing risks, because our understanding of those new materials’ behavior in the conditions generated by some novel plant designs is less complete than our understanding of the behavior of materials with long use histories in existing designs. In these cases, an approved code/standard or a code case to support the use of these materials in the novel design’s safety case may not exist for the regulator to utilize as part of the licensing determination. This circumstance creates the potential for an extremely long licensing process for new designs using new materials. The present strategy is to show how to manage these risks proactively, in such a way as to permit licensing decisions to be made in a timely manner, based on this risk management process. The present report outlines the gaps in the current codes to support deployment and use of novel materials and begins the development of the necessary risk management framework that is focused on the subject materials issues; it is based on risk-informed in-service surveillance practices, carried out in such a way as to compensate for current limitations in our state of knowledge. This development will enable licensing and deployment of the subject materials, conditional on the proactive surveillance process to be established. While this report is occasioned by limitations in our knowledge of certain materials issues that may arise in advanced designs, in-service surveillance is always done in order to compensate for a lack of knowledge: if we knew that components were not already failed and not trending toward failure, we would not perform surveillance, even in current-generation plants (except that prescriptive requirements would force us to do so). What is different about the surveillance program discussed here is that the issues are newer and the relevant experience base is less complete, so the surveillance presently contemplated may need to measure new things and/or measure them more often than has been traditional for surveillance coupons. The present report is devoted to the risk management framework and applies American Society of Mechanical Engineers Boiler and Pressure Vessel Code Section XI, Division [1] to establish the structure of a protocol for carrying out the necessary surveillance. These documents are generic: they do not tell us how often to surveille, or what to surveille, or what to measure, but rather how to determine those things, given certain technical inputs. The Regulatory Development R&D Program [2] is currently developing the companion supporting technical basis for the materials surveillance technology that, when completed and validated, can be used by owner/operator and NRC to implement a materials degradation management program for ANLWRs. This report also outlines salient points of discussion, positive potential outcomes, and potential concerns from industry and the USNRC. These aspects of the report intend to inform future work to develop a proposed technical process for adoption by the industry and endorsement by the USNRC to allow developers to propose a risk informed and conservative approach for the use of materials where operating experience/data and codes and standards may not exist for use of a novel material in an operating reactor environment. Additionally, such a technology could be leveraged to potentially reduce part of the upfront materials data requirements from ongoing long-term materials testing so that early action on license application could be undertaken by NRC, in parallel with the continuation of long-term data collection. This could accelerate the schedule for a first-of-a-kind ANLWR deployment or a nth-of-a-kind new materials insertion for established ANLWR designs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Managing Marine Energy Risks for Project Success

This presentation reviews recommended practices for marine energy risk management based on NLR's recent risk management framework publication (https://www.nrel.gov/docs/fy24osti/90212.pdf). This presentation will include a demonstration of risk management processes and techniques that everyone in the marine energy industry can use to successfully meet their project objectives. This presentation will include a description of methods to identify and manage risks that are specific to marine energy, while demonstrating this through tools such as risk registers, failure modes effects and criticality analysis (FMECA), and more tools that are currently being developed. The goal of this presentation is for the participants to have knowledge and access to tools to help them manage the risks specific to their marine energy projects.

13 HYDRO ENERGY↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper

data links↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper.

Iannicca, Dennis C.↗

Integrating Spaceflight Human System Risk Research

NASA is working to increase the likelihoods of human health and performance success during exploration missions, and subsequent crew long-term health. To manage the risks in achieving these goals, a system modeled after a Continuous Risk Management framework is in place. "Human System Risks" (Risks) have been identified, and approximately 30 are being actively addressed by NASA's Human Research Program (HRP). Research plans for each of HRP's Risks have been developed and are being executed. Ties between the research efforts supporting each Risk have been identified, however, this has been in an ad hoc fashion. There is growing recognition that solutions developed to address the full set of Risks covering medical, physiological, behavioral, vehicle, and organizational aspects of the exploration missions must be integrated across Risks and disciplines. We will discuss how a framework of factors influencing human health and performance in space is being applied as the backbone for bringing together sometimes disparate information relevant to the individual Risks. The resulting interrelated information is allowing us to identify and visualize connections between Risks and research efforts in a systematic and standardized way. We will discuss the applications of the visualizations and insights to research planning, solicitation, and decision-making processes.

Mindock, J.↗

Integrating Spaceflight Human System Risk Research

NASA is working to increase the likelihood of human health and performance success during exploration missions as well as to maintain the subsequent long-term health of the crew. To manage the risks in achieving these goals, a system modelled after a Continuous Risk Management framework is in place. "Human System Risks" (Risks) have been identified, and approximately 30 are being actively addressed by NASA's Human Research Program (HRP). Research plans for each of HRP's Risks have been developed and are being executed. Inter-disciplinary ties between the research efforts supporting each Risk have been identified; however, efforts to identify and benefit from these connections have been mostly ad hoc. There is growing recognition that solutions developed to address the full set of Risks covering medical, physiological, behavioural, vehicle, and organizational aspects of exploration missions must be integrated across Risks and disciplines. This paper discusses how a framework of factors influencing human health and performance in space is being applied as the backbone for bringing together sometimes disparate information relevant to the individual Risks. The resulting interrelated information enables identification and visualization of connections between Risks and research efforts in a systematic and standardized manner. This paper also discusses the applications of the visualizations and insights into research planning, solicitation, and decision-making processes.

Mindock, Jennifer↗

Integrated Issues and Risk Management: A Theoretical Framework Overview

The contractor requirements document for DOE O 226.1B, Implementation of Department of Energy Oversight Policy, requires DOE/NNSA contractors to establish an assurance system that includes, among other things, “Rigorous, risk-informed, and credible self-assessment and feedback and improvement activities. Assessment programs must be risk-informed, formally described and documented, and appropriately cover potentially high consequence activities” and “Contains an issues management process that is capable of categorizing the significance of findings based on risk and priority and other appropriate factors….” However, the term “risk-informed” is not defined in this or any other DOE order, and no formal guidance on how to integrate the two concepts currently exists. The Risk Management Guide for Defense Programs released by NA-18, Office of Systems Engineering and Integration (SE&I), states it is “a framework and general guidance to program office personnel on the effective management of program risks and issues”, however it then defines issues as “events with 100% likelihood of affecting program objectives” and states “unless specified otherwise, the term “risk” will also serve to represent issues for the remainder of this plan,” severally limiting its ability to provide adequate guidance on this topic. Outside of DOE scope, the U.S. Nuclear Regulatory Commission (U.S. NRC) imposes similar requirements. ASME NQA-1-2015 Requirement 16 states “Conditions adverse to quality shall be identified promptly and corrected as soon as practicable. In the case of a significant condition adverse to quality, the cause of the condition shall be determined, and corrective action taken to preclude recurrence. The identification, cause, and corrective action for significant conditions adverse to quality shall be documented and reported to appropriate levels of management. Completion of corrective actions shall be verified”. The purpose of this document is to provide a best-in-class framework for an integrated risk and issues management process. This process would provide a robust feedback loop between risk management and issues management to: Enhance risk identification and characterization, use risk handling principles to improve corrective action planning, and ensure regulatory compliance.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Cost-benefit based assurance planning

We have extended an existing risk management framework with a refined cost-benefit model. Benefits are measured in terms of reduction of risk.

risk requirements tradeoffs design quality assuran↗