Engineering PapersSearch

SEARCH · Engineering Papers

Results for “supply chain risk management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Obstacles to Practical Digital Supply Chain Risk Management in the Energy Sector

Cyber supply chain risk management (C-SCRM) programs must consider operations that depend on the lifecycles of digital components such as hardware, firmware, software, and services. We integrate academic literature, historical incidents, and existing standards to identify obstacles faced by C-SCRM programs.

Business Process Management & Integration

Cybersecurity Supply Chain Risk Management: Forge Institute Presentation

In this talk, INL will discuss how to develop a cyber supply chain risk management program, to include assessment of vendor risk and applying appropriate mitigations. INL will discuss key risk factors and the challenges of securing supply chain in complex and dynamic vendor environments. Finally, INL will share example language that can be adopted in RFPs and procurement contracts to promote supply chain security.

battery energy storage system

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session Two

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. A comprehensive exploration of BESS cybersecurity supply chain risks, systematic vendor risk assessment through the BESS Procurement Guide, and practical application of the INL SCRM Chatbot for enhanced supply chain resilience. This is Session 2 of 3. (Full Version)

25 - ENERGY STORAGE

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3. (Full Version)

25 - ENERGY STORAGE

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One - Abridged

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3.

25 - ENERGY STORAGE

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE

Interplanetary Supply Chain Risk Management

Emphasis on KSC ground processing operations, reduced spares up-mass lift requirements and campaign-level flexible path perspective for space systems support as Regolith-based ISM is achieved by; Network modeling for sequencing space logistics and in-space logistics nodal positioning to include feedstock. Economic modeling to assess ISM 3D printing adaption and supply chain risk.

Galluzzi, Michael C.

Supply Chain Research and Analysis for Space Systems

The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supply Chain Research and Analysis capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 105 reports since its start-up in early 2015.This presentation addresses the approach, methodology and performance of the Supply Chain Research and Analysiscapability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability.

supply chain risk management

Building Supply Chain Visibility for Risk Management: Illuminating the COVID-19 Pandemic Impact Upon NASA Suppliers

NASA mission projects rely upon global supply chains subject to an array of risks that threaten to disrupt or deny the timely, affordable provision of products and services as required for mission success. Visibility into these supply chains is key to the management of risks, such as those stemming from the coronavirus pandemic and its associated effects upon suppliers. Accordingly, the Supplier Research and Analysis (SRA) Program within Goddard Space Flight Center’s Safety and Mission Assurance (SMA) Directorate produced the COVID-19 pandemic/NASA suppliers dashboard as part of the NASA Meta Information System. The dashboard provides visibility and situational awareness to aid risk assessment, planning and decision-making over the course of the pandemic recovery phase. The approach of integrating data and information into visual dashboard displays has also been employed by the SRA Program to focus on specific risks pertaining to foreign-based suppliers. This webinar is presented by the NASA Office of SMA and its Supply Chain Risk Management Program, in collaboration with the NASA Safety Center and Goddard’s SMA Directorate.

supplier research and analysis, supply chain risk

Supply Chain Research and Analysis: Illuminating Risks in Complex Systems

Framing the strategic challenge posed by the interconnected, multitiered supply chains of mission projects managed by the NASA Goddard Space Flight Center. Discussing conditions and risks which can disrupt or threaten the availability, production and delivery of products and services for complex space systems. Utilizing a holistic analytical framework, business intelligence techniques, an integrated information system platform and analytics to produce insight into suppliers / supply chains and associated risks. Advancing supply chain risk management capabilities to support the successful performance of space missions.

supply chain risk management

Supplier Research & Analysis Approach

"The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supplier Research and Analysis (SRA) capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 95 reports since its start-up in early 2015. This presentation addresses the approach, methodology and performance of the Supplier Research and Analysis (SRA) capability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability."

supplier research and analysis

SCA Tools - SCRM Value Add or Lossy Noise Machines

Software supply chain risk management (SCRM) depends upon accurate information regarding the software components that comprise any given software system. The collection of components included in a software package can be organized within a software bill of materials, or SBOM. SBOMs are ideally generated when the software components are put together, such as at compile time, but for many reasons that has not and is not always possible. For example, legacy or proprietary software packages often do not have SBOMs available to downstream consumers of that software. It’s not just end users that are affected, manufacturers themselves also must deal with this problem. To answer these questions, the market has seen the rise of several commercial software composition analysis (SCA) tools. These tools aim to peer into completed software systems, automatically identifying hidden software dependencies and looking up known vulnerabilities associated with those dependencies to enable end-users to enhance their cyber supply chain risk management processes. These tools are potentially a huge boon to end users of legacy and proprietary software – and a potential bane, depending on how accurate they are. This research asks that question – how accurate are currently available binary SCA tools – and provides answers to several other questions: What does it mean to be “accurate”? What limitations do the tools have in identifying common edge cases that take place in modern software development? Can they help you avoid a devastating supply chain attack, or is it all just noise? After researching SCA tools on the market, we identified three vendors that fit our use case and would provide analysis on compiled binaries. Using these tools, we submitted firmware for critical infrastructure devices for analysis and SBOM generation. The SBOM outputs were then cross referenced with SBOMs generated through manual analysis for comparison. In addition to the firmware samples, we also submitted edge case samples based off a popular open-source library that were specifically crafted to evaluate each tools’ ability to accurately identify components. These samples were customized to be consistent with modifications we have seen in modern software development as well as a couple that are representative of supply chain attacks.

97 MATHEMATICS AND COMPUTING

Modeling Cyber Supply Chain Incidents with Multilayered Graph Motifs

As noted within the literature, supply chain includes people and organizations---manufacturers, integrators, and third-party vendors---that are involved in one or more stages of a product lifecycle. Since supply chains, by definition, include organizations and people, supply chain risk management activities must consider dependencies between an organization's business processes and third-party resources. Just as adversarial tactics can be implemented via techniques implemented via networked computer systems, so can such tactics be expressed via legal business relationships. A cyber incident may have an exponential impact downstream, for example, by leveraging a product's distribution channel (e.g. malicious updates in SolarWinds, buggy updates in CrowdStrike). Similarly, legitimate and legal business relationships also affect the attack surface exposure of systems, enabling long-term persistence and/or unknown impacts to product quality that are hard to detect. This paper catalogs several recent digital supply chain incidents and applies a multilayered network formalism to develop structural indicators (graph motifs) that reflect potentially-adversarial behavior. Finally, we compare and contrast the characteristics of adversarial tactics (e.g. Loss of Availability, Data Collection) that leverage cyber-physical dependencies to those that leverage legal organizational relationships.

97 - MATHEMATICS AND COMPUTING

Securing Digital Energy Infrastructure: BESS Procurement Guidance & Sample Contract Terms

Presentation for Procurement webinar providing technical guidance for entities, procuring Battery Energy Storage Systems (BESS), Inverter Based Resources (IBR), Distributed Energy Resource Management Systems (DERMS) and other energy digital systems and services on how to incorporate cybersecurity requirements into the procurement process to enhance both supply chain security as well as entity-specific supply chain risk management (SCRM) programs.

99 GENERAL AND MISCELLANEOUS

NASA Fastener Procurement, Receiving Inspection, and Storage Practices for NASA Mission Hardware

This document establishes minimum requirements for supply chain risk management, procurement, receiving inspection, testing, traceability management, and storage practices for fasteners used in NASA mission hardware. This document does not contain fastener requirements pertaining to design or design analysis; design and design analysis requirements are contained in NASA-STD-5020, Requirements for Threaded Fastening Systems in Spaceflight Hardware.

Safety and Mission Assurance