Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk-Informed Approach”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

An Integrated Reliability and Physics-Based Risk Modeling Approach for Assessing Human Spaceflight Systems

This paper presents an integrated reliability and physics-based risk modeling approach for assessing human spaceflight systems. The approach is demonstrated using an example, end-to-end risk assessment of a generic-crewed space transportation system during a reference mission to the International Space Station. The behavior of the system is modeled using analysis techniques from multiple disciplines in order to properly capture the dynamic time- and state- dependent consequences of failures encountered in different mission phases. We discuss how to combine traditional reliability analyses with Monte Carlo simulation methods and physics-based engineering models to produce loss-of- mission and loss-of-crew risk estimates supporting risk-based decision-making and requirement verification. This approach facilitates risk-informed design by providing more realistic representation of system failures and interactions; identifying key risk-driving sensitivities, dependencies, and assumptions; and tracking multiple figures of merit within a single, responsive assessment framework that can readily incorporate evolving design information throughout system development.

Risk assessment↗

Risk Assessment of Obstacle Collision for UAVs under off-nominal conditions

Enabling operations of unmanned aerial vehicles (UAVs) in low-altitude airspace, demands the need of robust risk monitoring framework for assessing the safety of airspace, ground-structures and people. As widespread applications emerge, the need of risk assessment becomes increasingly important for UAV flights beyond visual line-of-sight, especially subjected to off-nominal conditions introduced by component failures, degraded controllability or environmental disturbances such as wind gusts in an urban canyon. From a safety perspective, collision with obstacles can be detrimental not only to the vehicle and payload, but also to the structure and people on ground. Although it is safe to assume that approved UAVs would be equipped with collision avoidance systems, risk of collision which can be predicted for a flight trajectory even before the UAV encounters any obstacle is beneficial to resolve contingencies in its decision-making under off-nominal conditions. In this paper, a framework is presented for computing the risk of collision with obstacle based on a UAV's predicted trajectory, proximity to static and dynamic obstacles, sub-system state-of-health and external wind conditions. The conditional probability of trajectory deviation is generated using a Bayesian Belief Network (BBN) based on on-board sensor measurements. Further, a kinematic 3-DOF model is implemented to compute deviation in UAV's trajectory subjected to one case study of off-nominal condition i.e. wind gusts. Finally, the integrated risk factor is demonstrated on real data from experimental flights of an octocopter at NASA Langley Research Center, in presence of simulated obstacles and wind conditions. The proposed approach would enable risk-informed decision making process for timely mitigation of current and future unsafe events.

Portia Banerjee↗

Risk Assessment of Obstacle Collision for UAVs under Off-nominal Conditions

Enabling operations of unmanned aerial vehicles (UAVs) in low-altitude airspace demands the need of robust risk monitoring framework for assessing the safety of airspace, ground structures and people. As widespread applications emerge, the need of risk assessment becomes increasingly important for UAV flights beyond visual line-of-sight, especially subjected to off-nominal conditions introduced by component failures, degraded controllability or environmental disturbances such as wind gusts in an urban canyon. From a safety perspective, collision with obstacles can be detrimental not only to the vehicle and payload, but also to the structure and people on ground. Although it is safe to assume that approved UAVs would be equipped with collision avoidance systems, risk of collision which can be predicted for a flight trajectory even before the UAV encounters any obstacle is beneficial to resolve contingencies in its decision-making under off-nominal conditions. In this paper, a framework is presented for computing the risk of collision with obstacle based on a UAV’s predicted trajectory, proximity to static and dynamic obstacles, sub-system state-of-health and external wind conditions. The conditional probability of trajectory deviation is generated using a Bayesian Belief Network (BBN) based on on-board sensor measurements. Further, a kinematic 3-DOF model is implemented to compute deviation in UAV’s trajectory subjected to one case study of off-nominal condition i.e. wind gusts. Finally, the integrated risk factor is demonstrated on real data from experimental flights of an octocopter at NASA Langley Research Center, in presence of simulated obstacles and wind conditions. The proposed approach would enable risk-informed decision making process for timely mitigation of current and future unsafe events.

Bayesian network↗

An Altair Overview: Designing a Lunar Lander for 21st Century Human Space Exploration

Altair, the lunar lander element of NASA's Constellation program, was conducted in a different design environment than many other NASA projects of similar scope. Because of this relatively unique approach, there are a number of significant success stories that should be considered during the development of any future lunar landers or human spacecraft. This paper is divided into two separate themes; the first is the approach used during the conceptual design studies, including the systematic analysis cycles and the decision making process associated with each: and the second is a summary of the resulting lessons learned that were compiled after looking back at the lifetime of the Project. Altair was terminated before entering Phase B of its design, and was often criticized for being a very heavy and very large vehicle. While there was specific rationale for all of the decisions that led up to that configuration, future design cycles were specifically planned to re-address the mass challenge. Had the project continued, the deliberate, stepwise design process would have converged on an optimized lander design that balanced mass, risk, cost and capabilities. Some of the specific items that will be addressed in this paper include project development strategy, organizational approach and team dynamics, risk-informed design process, mission architecture constraints, mission key driving requirements, model-based systems engineering process, configuration studies, contingency considerations, subsystem overviews and key trade studies. The paper will conclude with a summary of the lessons identified during the Altair project and make suggestions for application to future studies.

Brown, Kendall K.↗

The Evolution of System Safety at NASA

The NASA system safety framework is in the process of change, motivated by the desire to promote an objectives-driven approach to system safety that explicitly focuses system safety efforts on system-level safety performance, and serves to unify, in a purposeful manner, safety-related activities that otherwise might be done in a way that results in gaps, redundancies, or unnecessary work. An objectives-driven approach to system safety affords more flexibility to determine, on a system-specific basis, the means by which adequate safety is achieved and verified. Such flexibility and efficiency is becoming increasingly important in the face of evolving engineering modalities and acquisition models, where, for example, NASA will increasingly rely on commercial providers for transportation services to low-earth orbit. A key element of this objectives-driven approach is the use of the risk-informed safety case (RISC): a structured argument, supported by a body of evidence, that provides a compelling, comprehensible and valid case that a system is or will be adequately safe for a given application in a given environment. The RISC addresses each of the objectives defined for the system, providing a rational basis for making informed risk acceptance decisions at relevant decision points in the system life cycle.

Dezfuli, Homayoon↗

Statistical Engineering in Air Traffic Management Research

NASA is working to develop an integrated set of advanced technologies to enable efficient arrival operations in high-density terminal airspace for the Next Generation Air Transportation System. This integrated arrival solution is being validated and verified in laboratories and transitioned to a field prototype for an operational demonstration at a major U.S. airport. Within NASA, this is a collaborative effort between Ames and Langley Research Centers involving a multi-year iterative experimentation process. Designing and analyzing a series of sequential batch computer simulations and human-in-the-loop experiments across multiple facilities and simulation environments involves a number of statistical challenges. Experiments conducted in separate laboratories typically have different limitations and constraints, and can take different approaches with respect to the fundamental principles of statistical design of experiments. This often makes it difficult to compare results from multiple experiments and incorporate findings into the next experiment in the series. A statistical engineering approach is being employed within this project to support risk-informed decision making and maximize the knowledge gained within the available resources. This presentation describes a statistical engineering case study from NASA, highlights statistical challenges, and discusses areas where existing statistical methodology is adapted and extended.

Wilson, Sara R.↗

Altair Lunar Lander Development Status: Enabling Human Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a minimum functionality approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicles safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to begin Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. A blended NASA-industry team will continue to refine the lander configuration and mature the vehicle design over the next few years. This paper will update the international community on the status of the Altair Project as it addresses the challenges of project formulation, including optimizing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

Altair Lunar Lander Development Status: Enabling Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a "minimum functionality" approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicle's safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to began Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. NASA intends to continue to seek industry involvement in project formulation activities. This paper will update the international coimmunity on the status of the Altair Project as it addresses the challenges of project formulation, including optinuzing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

Promoting a Culture of Tailoring for Systems Engineering Policy Expectations

NASA's Marshall Space Flight Center (MSFC) has developed an integrated systems engineering approach to promote a culture of tailoring for program and project policy requirements. MSFC's culture encourages and supports tailoring, with an emphasis on risk-based decision making, for enhanced affordability and efficiency. MSFC's policy structure integrates the various Agency requirements into a single, streamlined implementation approach which serves as a "one-stop-shop" for our programs and projects to follow. The engineers gain an enhanced understanding of policy and technical expectations, as well as lesson's learned from MSFC's history of spaceflight and science missions, to enable them to make appropriate, risk-based tailoring recommendations. The tailoring approach utilizes a standard methodology to classify projects into predefined levels using selected mission and programmatic scaling factors related to risk tolerance. Policy requirements are then selectively applied and tailored, with appropriate rationale, and approved by the governing authorities, to support risk-informed decisions to achieve the desired cost and schedule efficiencies. The policy is further augmented by implementation tools and lifecycle planning aids which help promote and support the cultural shift toward more tailoring. The MSFC Customization Tool is an integrated spreadsheet that ties together everything that projects need to understand, navigate, and tailor the policy. It helps them classify their project, understand the intent of the requirements, determine their tailoring approach, and document the necessary governance approvals. It also helps them plan for and conduct technical reviews throughout the lifecycle. Policy tailoring is thus established as a normal part of project execution, with the tools provided to facilitate and enable the tailoring process. MSFC's approach to changing the culture emphasizes risk-based tailoring of policy to achieve increased flexibility, efficiency, and effectiveness in project execution, while maintaining appropriate rigor to ensure mission success.

Blankenship, Van A.↗

Enabling Space Exploration Medical System Development Using a Tool Ecosystem

The NASA Human Research Program’s (HRP) Exploration Medical Capability (ExMC) Element is utilizing a Model Based Systems Engineering (MBSE) approach to enhance the development of systems engineering products that will be used to advance medical system designs for exploration missions beyond Low Earth Orbit. In support of future missions, the team is capturing content such as system behaviors, functional decompositions, architecture, system requirements and interfaces, and recommendations for clinical capabilities and resources in Systems Modeling Language (SysML) models. As these products mature, SysML models provide a way for ExMC to capture relationships among the various products, which includes supporting more integrated and multi-faceted views of future medical systems. In addition to using SysML models, HRP and ExMC are developing supplementary tools to support two key functions: 1) prioritizing current and future research activities for exploration missions in an objective manner; and 2) enabling risk-informed and evidence-based trade space analysis for future space vehicles, missions, and systems. This paper will discuss the long-term HRP and ExMC vision for the larger ecosystem of tools, which include dynamic Probabilistic Risk Assessment (PRA) capabilities, additional SysML models, a database of system component options, and data visualizations. It also includes a review of an initial Pilot Project focused on enabling medical system trade studies utilizing data that is coordinated across tools for consistent outputs (e.g., mission risk metrics that are associated with medical system mass values and medical conditions addressed). This first Pilot Project demonstrated successful operating procedures and integration across tools. Finally, the paper will also cover a second Pilot Project that utilizes tool enhancements such as medical system optimization capabilities, post-processing, and visualization of generated data for subject matter expert review, and increased integration amongst the tools themselves.

Amador, Jennifer R.↗

Enabling Space Exploration Medical System Development Using a Tool Ecosystem

The NASA Human Research Program's (HRP) Exploration Medical Capability (ExMC) Element is utilizing a Model Based Systems Engineering (MBSE) approach to enhance the development of systems engineering products that will be used to advance medical system designs for exploration missions beyond Low Earth Orbit. In support of future missions, the team is capturing content such as system behaviors, functional decompositions, architecture, system requirements and interfaces, and recommendations for clinical capabilities and resources in Systems Modeling Language (SysML) models. As these products mature, SysML models provide a way for ExMC to capture relationships among the various products, which includes supporting more integrated and multi-faceted views of future medical systems. In addition to using SysML models, HRP and ExMC are developing supplementary tools to support two key functions: 1) prioritizing current and future research activities for exploration missions in an objective manner; and 2) enabling risk-informed and evidence-based trade space analysis for future space vehicles, missions, and systems. This paper will discuss the long-term HRP and ExMC vision for the larger ecosystem of tools, which include dynamic Probabilistic Risk Assessment (PRA) capabilities, additional SysML models, a database of system component options, and data visualizations. It also includes a review of an initial Pilot Project focused on enabling medical system trade studies utilizing data that is coordinated across tools for consistent outputs (e.g., mission risk metrics that are associated with medical system mass values and medical conditions addressed). This first Pilot Project demonstrated successful operating procedures and integration across tools. Finally, the paper will also cover a second Pilot Project that utilizes tool enhancements such as medical system optimization capabilities, post-processing, and visualization of generated data for subject matter expert review, and increased integration amongst the tools themselves.

Amador, Jennifer R.↗

An Integrated Approach to Life Cycle Analysis

Life Cycle Analysis (LCA) is the evaluation of the impacts that design decisions have on a system and provides a framework for identifying and evaluating design benefits and burdens associated with the life cycles of space transportation systems from a "cradle-to-grave" approach. Sometimes called life cycle assessment, life cycle approach, or "cradle to grave analysis", it represents a rapidly emerging family of tools and techniques designed to be a decision support methodology and aid in the development of sustainable systems. The implementation of a Life Cycle Analysis can vary and may take many forms; from global system-level uncertainty-centered analysis to the assessment of individualized discriminatory metrics. This paper will focus on a proven LCA methodology developed by the Systems Analysis and Concepts Directorate (SACD) at NASA Langley Research Center to quantify and assess key LCA discriminatory metrics, in particular affordability, reliability, maintainability, and operability. This paper will address issues inherent in Life Cycle Analysis including direct impacts, such as system development cost and crew safety, as well as indirect impacts, which often take the form of coupled metrics (i.e., the cost of system unreliability). Since LCA deals with the analysis of space vehicle system conceptual designs, it is imperative to stress that the goal of LCA is not to arrive at the answer but, rather, to provide important inputs to a broader strategic planning process, allowing the managers to make risk-informed decisions, and increase the likelihood of meeting mission success criteria.

Chytka, T. M.↗

Achieving a Risk-Informed Decision-Making Environment at NASA: The Emphasis of NASA's Risk Management Policy

This slide presentation reviews the evolution of risk management (RM) at NASA. The aim of the RM approach at NASA is to promote an approach that is heuristic, proactive, and coherent across all of NASA. Risk Informed Decision Making (RIDM) is a decision making process that uses a diverse set of performance measures along with other considerations within a deliberative process to inform decision making. RIDM is invoked for key decisions such as architecture and design decisions, make-buy decisions, and budget reallocation. The RIDM process and how it relates to the continuous Risk Management (CRM) process is reviewed.

Dezfuli, Homayoon↗

A Proactive and Top-Down Approach to Managing Risk at NASA

Our ultimate goal is to manage risk in a holistic and coherent fashion across the Agency: a) The RIDM process is intended to risk-inform direction-setting decisions. c) The CRM process is intended to manage risk associated with the implementation of baseline performance requirements. Currently we are working on: a) Enhancements to the CRM process. b) Better integration of the RIDM and CRM processes. c) Better integration of institutional risk considerations into RM framework.

Dezfuli, Homayoon↗

NASA Accident Precursor Analysis Handbook, Version 1.0

Catastrophic accidents are usually preceded by precursory events that, although observable, are not recognized as harbingers of a tragedy until after the fact. In the nuclear industry, the Three Mile Island accident was preceded by at least two events portending the potential for severe consequences from an underappreciated causal mechanism. Anomalies whose failure mechanisms were integral to the losses of Space Transportation Systems (STS) Challenger and Columbia had been occurring within the STS fleet prior to those accidents. Both the Rogers Commission Report and the Columbia Accident Investigation Board report found that processes in place at the time did not respond to the prior anomalies in a way that shed light on their true risk implications. This includes the concern that, in the words of the NASA Aerospace Safety Advisory Panel (ASAP), "no process addresses the need to update a hazard analysis when anomalies occur" At a broader level, the ASAP noted in 2007 that NASA "could better gauge the likelihood of losses by developing leading indicators, rather than continue to depend on lagging indicators". These observations suggest a need to revalidate prior assumptions and conclusions of existing safety (and reliability) analyses, as well as to consider the potential for previously unrecognized accident scenarios, when unexpected or otherwise undesired behaviors of the system are observed. This need is also discussed in NASA's system safety handbook, which advocates a view of safety assurance as driving a program to take steps that are necessary to establish and maintain a valid and credible argument for the safety of its missions. It is the premise of this handbook that making cases for safety more experience-based allows NASA to be better informed about the safety performance of its systems, and will ultimately help it to manage safety in a more effective manner. The APA process described in this handbook provides a systematic means of analyzing candidate accident precursors by evaluating anomaly occurrences for their system safety implications and, through both analytical and deliberative methods used to project to other circumstances, identifying those that portend more serious consequences to come if effective corrective action is not taken. APA builds upon existing safety analysis processes currently in practice within NASA, leveraging their results to provide an improved understanding of overall system risk. As such, APA represents an important dimension of safety evaluation; as operational experience is acquired, precursor information is generated such that it can be fed back into system safety analyses to risk-inform safety improvements. Importantly, APA utilizes anomaly data to predict risk whereas standard reliability and PRA approaches utilize failure data which often is limited and rare.

Groen, Frank↗

Sustaining a Mature Risk Management Process: Ensuring the International Space Station for a Vibrant Future

The International Space Station (ISS) risk management methodology is an example of a mature and sustainable process. Risk management is a systematic approach used to proactively identify, analyze, plan, track, control, communicate, and document risks to help management make risk-informed decisions that increase the likelihood of achieving program objectives. The ISS has been operating in space for over 14 years and permanently crewed for over 12 years. It is the longest surviving habitable vehicle in low Earth orbit history. Without a mature and proven risk management plan, it would be increasingly difficult to achieve mission success throughout the life of the ISS Program. A successful risk management process must be able to adapt to a dynamic program. As ISS program-level decision processes have evolved, so too has the ISS risk management process continued to innovate, improve, and adapt. Constant adaptation of risk management tools and an ever-improving process is essential to the continued success of the ISS Program. Above all, sustained support from program management is vital to risk management continued effectiveness. Risk management is valued and stressed as an important process by the ISS Program.

Raftery, Michael↗

Considering Risk and Resilience in Decision-Making

This paper examines the concepts of decision-making, risk analysis, uncertainty and resilience analysis. The relation between risk, vulnerability, and resilience is analyzed. The paper describes how complexity, uncertainty, and ambiguity are the most critical factors in the definition of the approach and criteria for decision-making. Uncertainty in its various forms is what limits our ability to offer definitive answers to questions about the outcomes of alternatives in a decision-making process. It is shown that, although resilience-informed decision-making would seem fundamentally different from risk-informed decision-making, this is not the case as resilience-analysis can be easily incorporated within existing analytic-deliberative decision-making frameworks.

Torres-Pomales, Wilfredo↗