Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A hierarchical-multiobjective framework for risk management

A broad hierarchical-multiobjective framework is established and utilized to methodologically address the management of risk. United into the framework are the hierarchical character of decision-making, the multiple decision-makers at separate levels within the hierarchy, the multiobjective character of large-scale systems, the quantitative/empirical aspects, and the qualitative/normative/judgmental aspects. The methodological components essentially consist of hierarchical-multiobjective coordination, risk of extreme events, and impact analysis. Examples of applications of the framework are presented. It is concluded that complex and interrelated forces require an analysis of trade-offs between engineering analysis and societal preferences, as in the hierarchical-multiobjective framework, to successfully address inherent risk.

Haimes, Yacov Y.↗

NASA Risk Management Handbook: Version 2.0, Part 1

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0. NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Uncertainty↗

NASA Risk Management Handbook: Version 2.0, Part 2

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0 (January 2020). NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Risk Leadership↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper

data links↗

Security Risk Assessment Process for UAS in the NAS CNPC Architecture

This informational paper discusses the risk assessment process conducted to analyze Control and Non-Payload Communications (CNPC) architectures for integrating civil Unmanned Aircraft Systems (UAS) into the National Airspace System (NAS). The assessment employs the National Institute of Standards and Technology (NIST) Risk Management framework to identify threats, vulnerabilities, and risks to these architectures and recommends corresponding mitigating security controls. This process builds upon earlier work performed by RTCA Special Committee (SC) 203 and the Federal Aviation Administration (FAA) to roadmap the risk assessment methodology and to identify categories of information security risks that pose a significant impact to aeronautical communications systems. A description of the deviations from the typical process is described in regards to this aeronautical communications system. Due to the sensitive nature of the information, data resulting from the risk assessment pertaining to threats, vulnerabilities, and risks is beyond the scope of this paper.

Iannicca, Dennis C.↗

Integrating Spaceflight Human System Risk Research

NASA is working to increase the likelihoods of human health and performance success during exploration missions, and subsequent crew long-term health. To manage the risks in achieving these goals, a system modeled after a Continuous Risk Management framework is in place. "Human System Risks" (Risks) have been identified, and approximately 30 are being actively addressed by NASA's Human Research Program (HRP). Research plans for each of HRP's Risks have been developed and are being executed. Ties between the research efforts supporting each Risk have been identified, however, this has been in an ad hoc fashion. There is growing recognition that solutions developed to address the full set of Risks covering medical, physiological, behavioral, vehicle, and organizational aspects of the exploration missions must be integrated across Risks and disciplines. We will discuss how a framework of factors influencing human health and performance in space is being applied as the backbone for bringing together sometimes disparate information relevant to the individual Risks. The resulting interrelated information is allowing us to identify and visualize connections between Risks and research efforts in a systematic and standardized way. We will discuss the applications of the visualizations and insights to research planning, solicitation, and decision-making processes.

Mindock, J.↗

Integrating Spaceflight Human System Risk Research

NASA is working to increase the likelihood of human health and performance success during exploration missions as well as to maintain the subsequent long-term health of the crew. To manage the risks in achieving these goals, a system modelled after a Continuous Risk Management framework is in place. "Human System Risks" (Risks) have been identified, and approximately 30 are being actively addressed by NASA's Human Research Program (HRP). Research plans for each of HRP's Risks have been developed and are being executed. Inter-disciplinary ties between the research efforts supporting each Risk have been identified; however, efforts to identify and benefit from these connections have been mostly ad hoc. There is growing recognition that solutions developed to address the full set of Risks covering medical, physiological, behavioural, vehicle, and organizational aspects of exploration missions must be integrated across Risks and disciplines. This paper discusses how a framework of factors influencing human health and performance in space is being applied as the backbone for bringing together sometimes disparate information relevant to the individual Risks. The resulting interrelated information enables identification and visualization of connections between Risks and research efforts in a systematic and standardized manner. This paper also discusses the applications of the visualizations and insights into research planning, solicitation, and decision-making processes.

Mindock, Jennifer↗

Cost-benefit based assurance planning

We have extended an existing risk management framework with a refined cost-benefit model. Benefits are measured in terms of reduction of risk.

risk requirements tradeoffs design quality assuran↗

Incorporating cost-benefit analyses into software assurance planning

The objective is to use cost-benefit analyses to identify, for a given project, optimal sets of software assurance activities. Towards this end we have incorporated cost-benefit calculations into a risk management framework.

investment software quality software process impro↗

A History of Space Toxicology Mishaps: Lessons Learned and Risk Management

After several decades of human spaceflight, the community of space-faring nations has accumulated a diverse and sometimes harrowing history of toxicological events that have plagued human space endeavors almost from the very beginning. Lessons have been learned in ground-based test beds and others were discovered the hard way - when human lives were at stake in space. From such lessons one can build a risk-management framework for toxicological events to minimize the probability of a harmful exposure, while recognizing that we cannot foresee all events. Space toxicologists have learned that relatively harmless compounds can be converted by air revitalization systems into compounds that cause serious harm to the crew. Our toxic risk management strategy now includes an assessment of the fate of any compound that might be released into the atmosphere. Propellants are highly toxic compounds, yet we have not always been able to thoroughly isolate the crew from exposure to these toxicants. Leakage of fluids from systems has resulted in hazardous conditions at times, and the behavior of such compounds inside a spacecraft has taught us how to manage potentially harmful escapes should they occur. Potential combustion events are an ever-present threat to the wellbeing of the crew. Such events have been sufficiently common that we have learned that one cannot judge the health threat of a given fire by the magnitude of the event. Management of such risks demands monitoring of combustion products. In the category of unpredictable toxic events, if one assumes that fires are predictable, we can place experience with toxic microbial metabolites, upsets during repair operations, and discharges from filters that have accumulated a substantial load of pollutants in their absorption beds. Management of such events requires a broad-spectrum, real-time analytical capability to discern the identity and concentrations of pollutants if they enter the atmosphere. Adverse events are an integral part of any human activity, and the spacefaring community must learn as much as possible from mistakes and near misses.

James, John T.↗

MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons Learned

As the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multiorganizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other's, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission's leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA's requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.

FISMA↗

Cross-Cutting Risk Framework: Mining Data for Common Risks Across the Portfolio

The National Aeronautics and Space Administration (NASA) defines risk management as an integrated framework, combining risk-informed decision making and continuous risk management to foster forward-thinking and decision making from an integrated risk perspective. Therefore, decision makers must have access to risks outside of their own project to gain the knowledge that provides the integrated risk perspective. Through the Goddard Space Flight Center (GSFC) Flight Projects Directorate (FPD) Business Change Initiative (BCI), risks were integrated into one repository to facilitate access to risk data between projects. With the centralized repository, communications between the FPD, project managers, and risk managers improved and GSFC created the cross-cutting risk framework (CCRF) team. The creation of the consolidated risk repository, in parallel with the initiation of monthly FPD risk managers and risk governance board meetings, are now providing a complete risk management picture spanning the entire directorate. This paper will describe the challenges, methodologies, tools, and techniques used to develop the CCRF, and the lessons learned as the team collectively worked to identify risks that FPD programs projects had in common, both past and present.

risk-informed decision making↗

ePORT, NASA's Computer Database Program for System Safety Risk Management Oversight (Electronic Project Online Risk Tool)

ePORT (electronic Project Online Risk Tool) provides a systematic approach to using an electronic database program to manage a program/project risk management processes. This presentation will briefly cover the standard risk management procedures, then thoroughly cover NASA's Risk Management tool called ePORT. This electronic Project Online Risk Tool (ePORT) is a web-based risk management program that provides a common framework to capture and manage risks, independent of a programs/projects size and budget. It is used to thoroughly cover the risk management paradigm providing standardized evaluation criterion for common management reporting, ePORT improves Product Line, Center and Corporate Management insight, simplifies program/project manager reporting, and maintains an archive of data for historical reference.

Johnson, Paul W.↗

Real-Time Risk Assessment Framework for Unmanned Aircraft System (UAS) Traffic Management (UTM)

The new Federal Aviation Administration (FAA) Small Unmanned Aircraft rule (Part 107) marks the first national regulations for commercial operation of small unmanned aircraft systems (sUAS) under 55 pounds within the National Airspace System (NAS). Although sUAS flights may not be performed beyond visual line-of-sight or over non- participant structures and people, safety of sUAS operations must still be maintained and tracked at all times. Moreover, future safety-critical operation of sUAS (e.g., for package delivery) are already being conceived and tested. NASA's Unmanned Aircraft System Trac Management (UTM) concept aims to facilitate the safe use of low-altitude airspace for sUAS operations. This paper introduces the UTM Risk Assessment Framework (URAF) which was developed to provide real-time safety evaluation and tracking capability within the UTM concept. The URAF uses Bayesian Belief Networks (BBNs) to propagate off -nominal condition probabilities based on real-time component failure indicators. This information is then used to assess the risk to people on the ground by calculating the potential impact area and the effects of the impact. The visual representation of the expected area of impact and the nominal risk level can assist operators and controllers with dynamic trajectory planning and execution. The URAF was applied to a case study to illustrate the concept.

Ancel, Ersin↗

Gateway Implementation of Cybersecurity Requirements

Cyber threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is one of the critical subsystems that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfill and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Svetlana Hanson↗

Gateway Implementation of Cybersecurity Requirements

Cybersecurity threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is a critical discipline that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfil and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Cybersecurity↗