SSP_30234-RevH.docx
DOCX document 287 KB Posted
- Attached to
- Human Space Flight Technical Integration Contract (HSFTIC) Federal contract opportunity
- Solicitation number
- 80JSC019R0023
About this file
This document provides details for a forthcoming solicitation for the Human Space Flight Technical Integration Contract (HSFTIC). Key information includes that NASA/JSC plans to issue a Request for Proposal (RFP) on or about November 1, 2019 with an anticipated offer due date of December 11, 2019. The procurement is a total small business set-aside under NAICS code 541715 with a size standard of 1,250 employees. The solicitation and related documents will be available at the listed websites. Prospective offerors shall notify the office of their intent to submit an offer and are responsible for monitoring the website for solicitation releases and amendments. All contractual technical questions must be submitted in writing. The RFP is anticipated to require technical integration services in support of human space flight programs at the Johnson Space Center.
SSP 30234 Rev H
View the file
Other files for this federal contract opportunity
Show all 50
Human Space Flight Technical Integration Contract (HSFTIC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Failure Modes and Effects Analysis and Critical Items List Requirements for Space Station
International Space Station Program
Revision H
September 2015
National Aeronautics and Space Administration International Space Station Program Johnson Space Center Houston, Texas Contract #NNJ12GA46C
SSP 30234
Revision H
REVISION AND HISTORY PAGE
| REV. |
| DESCRIPTION |
| PUB. DATE |
| Baseline Issue (Reference SSCBD BB000250 EFF. 01-15-87) |
| 01-15-87 |
| A |
| Revision A (Reference the Electronic Baseline Reformatted Version) |
| 06-30-88 |
| B |
| Revision B (Reference SSCBD BB000658B EFF. 09-09-02) |
| 09-92 |
| Change B1 (Reference SSCBD BB003528 EFFF. 05-03-93) |
| 05-93 |
| C |
| Revision C (Reference SSCBDs BB003666 EFF. 09-29-93, BB003681 EFF. 05-28-93, and BB003684 EFF. 09-29-93) |
| 10-93 |
| D |
| Revision D (Per BSCR 1.7.1) |
| 03-08-96 |
| E |
| Revision E (Reference CR 000977) |
| 04-13-99 |
| F |
| Revision F (Reference per SSCD 006169, EFF. 09-10-02) |
| Early Release |
| 10-15-02 |
| Program Release |
| 06-26-03 |
| DCN 001 (Reference per SSCD 010518, EFF. 05-29-07) |
| 10-17-07 |
| DCN 002 (Reference per SSCD 011287, EFF. 11-03-08) |
| 01-06-09 |
| G |
| Revision G (Reference per SSCD 013122, EFF. 08-07-12) |
| 08-14-12 |
| H |
| Revision H (Reference SSCD 15026, EFF. 09-27-15) |
| 09-28-15 |
SSP 30234
Revision H
1-1
PREFACE
failure modes and effects analysis and critical items list requirements for space station
SSP 30234, Failure Modes and Effects Analysis and Critical Items List Requirements for Space Station, requirements provide consistent methods for the preparation, storage, transmission, publication, and distribution of the Failure Modes Effects Analysis (FMEA) and Critical Items List (CIL). This document is to be identified in the Statement of Work (SOW), similar contractual/programmatic documents, or in Bilateral Data Exchange Agreements (BDEA).
This document contains an introduction and subsections on organizational relationships and responsibilities; FMEA/CIL process; FMEA requirements, ground rules, and reporting requirements; CIL requirements, rules, and reporting requirements; and CIL approval, database, and maintenance requirements.
This document is under the control of the Space Station Program Control Board (SSPCB), and any changes or revisions will be approved by the Manager of the International Space Station (ISS) Program.
INTERNATIONAL SPACE STATION PROGRAM
failure modes and effects analysis and critical items list requirements for space station
CONCURRENCE
September 2015 vi
TABLE OF CONTENTS
| PARAGRAPH | PAGE | ||
| 1.0 | introduction | 1-1 | |
| 1.1 | objective | 1-1 | |
| 1.2 | REQUIREMENT TRACEABILITY | 1-1 | |
| 1.3 | PURPOSE | 1-1 | |
| 1.4 | scope | 1-2 | |
| 1.5 | iss fmea/Critical ITEMS LIST (cil) database | 1-2 | |
| 1.6 | precedence | 1-2 | |
| 2.0 | documents | 2-1 | |
| 2.1 | applicable documents | 2-1 | |
| 2.2 | reference documents | 2-2 | |
| 3.0 | ORGANIZATIONAL RELATIONSHIPS AND RESPONSIBILITIES | 3-1 | |
| 3.1 | NASA/Headquarters | 3-1 | |
| 3.1.1 | associate administrator for Human Exploration and Operation | 3-1 | |
| 3.1.2 | Chief FOR Office of SAFETY AND MISSION assurance | 3-1 | |
| 3.2 | ISS PROGRAM OFFICE | 3-1 | |
| 3.2.1 | MANAGER OF the iss PROGRAM | 3-1 | |
| 3.2.2 | ISS PROGRAM OFFICE ORGANIZATIONAL RESPONSIBILITIES | 3-1 | |
| 3.2.2.1 | safety and mission assurance control board responsibilities | 3-1 | |
| 3.2.2.1.1 | NASA reliability and maintainability RESPONSIBILITIES | 3-2 | |
| 3.2.2.1.2 | HARDWARE PROVIDER/OWNER AND ISS INTEGRATOR RELIABILITY AND MAINTAINABILITY RESPONSIBILITIES | 3-2 | |
| 3.3 | INTERNATIONAL PARTNER | 3-4 | |
| 4.0 | FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEMS PROCESS | 4-1 | |
| 4.1 | FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEMS PROCESS OVERVIEW | 4-1 | |
| 4.2 | FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEMS ACTIVITIES THROUGH PRELIMINARY DESIGN Phase | 4-2 | |
| 4.3 | FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM ACTIVITIES | ||
| FROM PRELIMINARY DESIGN REVIEW THROUGH CRITICAL DESIGN REVIEW | 4-2 | ||
| 4.4 | FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM ACTIVITIES SUBSEQUENT TO CRITICAL DESIGN REVIEW | 4-2 | |
| 4.5 | FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM INTEGRATION ACTIVITIES | 4-3 | |
| 4.6 | RELATION OF THE FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL | ||
| ITEM TO LOGISTICS SUPPORT ANALYSIS | 4-4 | ||
| 5.0 | FLIGHT HARDWARE failure modes and effects analysis REQUIREMENTS, GROUND RULES, AND REPORTING REQUIREMENTS | 5-1 | |
| 5.1 | requirement applicability | 5-1 | |
| 5.2 | LEVEL OF ANALYSIS | 5-2 | |
| 5.3 | MISSION PHASES | 5-2 | |
| 5.4 | FAILURE MODE CONSIDERATION | 5-2 | |
| 5.5 | FAILURE CAUSES | 5-3 | |
| 5.6 | FAILURE EFFECTS | 5-3 | |
| 5.7 | INTERFACES | 5-3 | |
| 5.8 | tIMELINES | 5-4 | |
| 5.9 | Initial assessment of criticality | 5-4 | |
| 5.10 | UNIQUE failure modes and effects analysis REQUIREMENTS | 5-5 | |
| 5.10.1 | CABLES/HARNESSES/CONNECTORS | 5-5 | |
| 5.10.2 | FLUID SYSTEMS | 5-5 | |
| 5.10.3 | ContiNgency equipment | 5-5 | |
| 5.10.4 | items with hazardous effects <moved to paragraph 6.6.1> | 5-5 | |
| 5.10.5 | pressure vessels | 5-5 | |
| 5.10.6 | Habitable Single string elements | 5-6 | |
| 5.10.7 | Assessment of Commercial off- the-shelf hardware | 5-6 | |
| 5.10.8 | non-disabling injury and damage to hardware | 5-6 | |
| 5.11 | INPUTS AND OUTPUTS | 5-6 | |
| 5.12 | IDENTICAL ITEMS | 5-6 | |
| 5.13 | CRITICALITY DETERMINATIONS | 5-6 | |
| 5.13.1 | CRITICALITY ASSIGNMENTS | 5-6 | |
| 5.13.2 | CREW PROCEDURES and ACTIONS | 5-9 | |
| 5.13.3 | UNIQUE CRITICALITY CATEGORIZATION REQUIREMENTS | 5-9 | |
| 5.13.3.1 | maintenance items and spares | 5-9 | |
| 5.13.3.2 | SAFETY items | 5-10 | |
| 5.13.3.3 | exercise equipment | 5-10 | |
| 5.13.3.4 | visiting vehicles | 5-11 | |
| 5.13.3.5 | quick disconnects | 5-11 | |
| 5.13.3.6 | protective items | 5-11 | |
| 5.13.4 | prelaunch | 5-12 | |
| 5.13.5 | REDUNDANCY SCREENS | 5-12 | |
| 5.13.5.1 | screen a | 5-12 | |
| 5.13.5.2 | screen b | 5-13 | |
| 5.13.5.3 | screen c | 5-13 | |
| 5.14 | failure modes and effectS analysis reporting requirements | 5-14 | |
| 5.14.1 | failure modes and effectS analysis worksheets | 5-14 | |
| 5.14.2 | failure modes and effectS analysis report | 5-14 | |
| 6.0 | flight hardware critical item identification, acceptance rationale, and ISS program approval requirements | 6-1 | |
| 6.1 | critical items criteria | 6-1 | |
| 6.2 | retention rationale | 6-1 | |
| 6.2.1 | design | 6-1 | |
| 6.2.2 | test | 6-1 | |
| 6.2.3 | inspection | 6-1 | |
| 6.2.4 | failure history | 6-1 | |
| 6.2.5 | operational use | 6-2 | |
| 6.2.6 | maintainability | 6-2 | |
| 6.3 | critical items reporting requirements | 6-2 | |
| 6.3.1 | critical items (fmea/cil worksheets) | 6-2 | |
| 6.3.2 | critical items list report | 6-2 | |
| 6.4 | united states on-orbit segment critical item approval process | 6-3 | |
| 6.4.1 | critical item baselining and approval | 6-3 | |
| 6.4.2 | critical item retention rationale implementation | 6-4 | |
| 6.5 | international partner critical item process | 6-5 | |
| 6.6 | unique critical item requirements | 6-5 | |
| 6.6.1 | items with catastrophic/safety related effects | 6-5 | |
| 6.6.2 | off-the-shelf medical equipment | 6-6 | |
| 7.0 | GROUND SUPPORT EQUIPMENT FAILURE MODES AND EFFECTS ANALYSIS REQUIREMENTS, Ground RULES, AND REPORTING REQUIREMENTS | 7-1 | |
| 7.1 | requirement applicability | 7-1 | |
| 7.2 | ground support equipment failure modes and effects analysis requirements and ground rules | 7-1 | |
| 7.2.1 | General | 7-1 | |
| 7.2.2 | electrical | 7-3 | |
| 7.2.3 | fluids | 7-4 | |
| 7.3 | end-to-end analysis | 7-4 | |
| 7.4 | Ground Support Equipment criticality Assignments | 7-5 | |
| 7.5 | Ground Support Equipment failure modes and effects analysis | ||
| and critical item report | 7-5 | ||
| 7.5.1 | Ground Support Equipment failure modes and effects analysis | ||
| and critical item worksheets | 7-5 | ||
| 7.5.2 | ground support equipment failure modes and effects analysis/critical items report | 7-5 | |
| 8.0 | ground support equipment critical items criteria | 8-1 | |
| 8.1 | critical line replaceable unit list | 8-1 | |
| 8.2 | critical items list sheet | 8-1 | |
| 8.3 | analysis results | 8-1 | |
| 8.4 | retention rationale | 8-1 | |
| 8.5 | ground support equipment critical item process | 8-1 | |
| 9.0 | Payload FAILURE MODES AND EFFECTS ANALYSIS REQUIREMENTS, ground RULES, AND REPORTING REQUIREMENTS | 9-1 | |
| 9.1 | requirement applicability | 9-1 | |
| 9.2 | payload failure modes and effects analysis requirements and | ||
| ground rules | 9-1 | ||
| 9.3 | payload failure modes and effects analysis | 9-1 | |
| 9.3.1 | payload failure modes and effects analysis worksheets | 9-1 | |
| 9.3.2 | payload failure modes and effects analysis report | 9-1 | |
| 9.3.3 | payload criticality Assignments | 9-2 | |
| 10.0 | ISS program critical items list approval and maintenance requirements | 10-1 | |
| 10.1 | critical items list approval requirements | 10-1 | |
| 10.2 | critical items list maintenance requirements | 10-1 |
APPENDIX
| a | acronyms and abbreviations | a-1 |
| b | glossary | b-1 |
| c | data elements for flight hardware failure modes and effects analysis and critical item worksheet | c-1 |
| d | data elements for ground support equipment failure modes and effects analysis and critical item worksheet | d-1 |
| e | data elements for payload FAILURE MODES AND EFFECTS ANALYsIS | e-1 |
| f | standard list of failure modes | f-1 |
| g | JSC Form 1380, initial assessment of criticality (IAC) | g-1 |
| h | FMEA AND CRITICAL ITEM UPDATE PROCESS | h-1 |
| i | ISS LETTER 0B-07-019, SUBJECT “ISS REVIEW PROCESs FOR ‘OFF-THE-SHELF’ MEDICAL EQUIPMENT” | i-1 |
| j | CRITICAL ITEM SUMMARY SHEET | j-1 |
| k | failure propagation white paper | k-1 |
| l | open work | l-1 |
TABLE
| 5.13.1-1 | Criticality Definitions | 5-7 |
| 7.4-1 | GSE criticality definitions | 7-5 |
| 9.3.3-1 | Payload criticality definitions | 9-2 |
| L-1 | to be determined items | l-1 |
| L-2 | TO BE RESOLVED ISSUES | l-1 |
FIGURE
| 6.4.1-1 | Critical Item Baselining and Approval Process | 6-4 |
| H-1 | ISS FMEA/Critical Item Update Process | h-3 |
introduction A Failure Modes and Effects Analysis (FMEA) or critical item initiated prior to this revision may be completed in accordance with the previous version of this document and does not require updating to meet the requirements of this revision.
objective The objective of this document is to establish a consistent framework for uniform implementation of the FMEA and critical item tasks. In order to fulfill this objective, this document defines basic requirements and responsibilities, ground rules and assumptions, data elements, and terminology for performance of FMEA and critical item tasks.
REQUIREMENT TRACEABILITY
The International Space Station (ISS) Program Office has levied this document to define the FMEA and critical item requirements and outline the methodology to be used by the ISS hardware providers/owners and integrator.
General roles and responsibilities of International Partners (IPs) to meet this document are outlined in SSP 50019, NASA/ESA Joint Management Plan; SSP 50022, NASA/CSA Joint Management Plan; SSP 50030, NASA/NASDA Joint Management Plan; SSP 50076, NASA/ASI Joint Management Plan; and SSP 50107, NASA/RSA Joint Management Plan. Detailed responsibilities from this document for each IP are specified in SSP 50124, NASA/CSA Bilateral Data Exchange Agreements, Lists and Schedules; SSP 50126, NASA/JAXA Bilateral Data Exchange Agreements, Lists and Schedules for the Japanese Experiment Module (JEM); SSP 50127 NASA/ESA Bilateral Data Exchange Agreements, Lists, and Schedules for Columbus; SSP 50146, NASA/RSA Bilateral S&MA Process Requirements for International Space Station; SSP 50182, NASA/ASI Bilateral Safety and Product Assurance Requirements; and SSP 50614, NASA/JAXA Bilateral Data Exchange Agreements, Lists and Schedules for H-II Transfer Vehicle (HTV). As ISS has achieved assembly complete, submittal dates for FMEA and critical item information will be defined in the protocol documentation between National Aeronautics and Space Administration (NASA) and the IP responsible for the hardware. For all others, the details will be called out in the SOW or similar contractual/programmatic document.
PURPOSE
During the preliminary and detailed design phases, the purpose of the FMEA is to drive iteration of the hardware and software design to address potential effects of credible failure modes.
This is accomplished, in part, by assessing compliance of the design with the failure tolerance, failure propagation, redundancy status, and separation redundant paths requirements. After the design is baselined, the purpose of the FMEA is to serve as official documentation that captures credible failures and the corresponding effects on system functionality, mission, visiting vehicles, space station, ground personnel and crew. The critical item serves to document requirements needed to control causes of critical failures and mitigate failure effects. Requirements are commonly identified in the areas of manufacturing, assembly, test, maintenance, and operational workarounds. The critical item review and approval process serves as an aid to ISS Program Management in understanding and managing the risks inherent in the design.
For Ground Support Equipment (GSE) and Payloads, the design philosophy is fail-safe. The FMEA is used as a tool to determine the extent of compliance with this design philosophy.
scope The requirements of this document apply, to the extent specified herein, to all ISS Program hardware, including Flight Support Equipment (FSE), GSE, Government Furnished Equipment (GFE), IP Furnished Equipment, Payloads, and Commercial Orbital Transportation Services where SSP 30234 is levied as the document to develop and approve FMEAs and critical items. These requirements shall apply throughout the entire life cycle of the aforementioned items, including Design, Development, Test and Evaluation, and Operations. This document does not apply to software; however, it does reflect how software operates within the integrated system.
iss fmea/Critical ITEMS LIST (cil) database The ISS FMEA/Critical Items List (CIL) database houses worksheets dispositioned on the ISS Program. The database serves as the ISS Program tool to update, generate, review, and approve FMEA/CIL worksheets. For access to the ISS FMEA/CIL database, contact the ISS Program Safety and Mission Assurance/Program Risk Office.
precedence In the event of conflict between this document and NASA ISS Program Contracts, the contract shall take precedence.
5-1 documents applicable documents The following documents include specifications, models, standards, guidelines, handbooks, and other special publications. The documents listed in this paragraph are applicable to the extent specified herein. Inclusion of applicable documents herein does not in any way supersede the order of precedence identified in Paragraph 1.6 of this document.
| SSP 30309 |
| Safety Analysis and Risk Assessment Requirements Document |
| SSP 50019 |
| NASA/ESA Joint Management Plan |
| SSP 50022 |
| NASA/CSA Joint Management Plan |
| SSP 50030 |
| NASA/NASDA Joint Management Plan |
| SSP 50076 |
| NASA/ASI Joint Management Plan |
| SSP 50107 |
| NASA/RSA Joint Management Plan |
| SSP 50124 |
| NASA/CSA Bilateral Data Exchange Agreements, Lists and Schedules |
| SSP 50126 |
| NASA/JAXA Bilateral Data Exchange Agreements, Lists and Schedules for the Japanese Experiment Module (JEM) |
| SSP 50127 |
| NASA/ESA Bilateral Data Exchange Agreements, Lists, and Schedules for Columbus |
| SSP 50146 |
| NASA/RSA Bilateral S&MA Process Requirements for International Space Station |
| SSP 50182 |
| NASA/ASI Bilateral Safety and Product Assurance Requirements |
| SSP 50614 |
| NASA/JAXA Bilateral Data Exchange Agreements, Lists and Schedules for H-II Transfer Vehicle (HTV) |
reference documents The following documents contain supplemental information to guide the user in the application of this document. These reference documents may or may not be specifically cited within the text of this document.
| JSC Form 1380 |
| Initial Assessment of Criticality (IAC) |
SSP 30482
Volume 1 Electric Power Specifications and Standards Volume 1:
Electrical Performance Specifications
| SSP 41000 |
| System Specification for the International Space Station |
| SSP 41162 |
| Segment Specification for United States On-Orbit |
| SSP 50021 |
| Safety Requirements Document |
| SSP 50431 |
| Space Station Program Requirements for Payloads |
| SSP 50808 |
| International Space Station (ISS) to Commercial Orbital Transportation Services (COTS) Interface Control Document (IRD) |
ORGANIZATIONAL RELATIONSHIPS AND RESPONSIBILITIES
NASA/Headquarters associate administrator for Human Exploration and Operation The Associate Administrator for Human Exploration and Operation (HEO) is the policy-level interface and ensures that the ISS Program meets the requirements of external organizations and policy requirements of the IPs. The Associate Administrator for HEO flows down authority for top-level objectives and resource availability to the ISS Program Manager.
Chief FOR Office of SAFETY AND MISSION assurance The Chief for Office of Safety and Mission Assurance (S&MA) provides agency level policies in the areas of Safety, Reliability, Maintainability, and Quality Assurance. The Chief for S&MA performs an oversight function, as a check and balance, of all NASA operations, including the ISS.
ISS PROGRAM OFFICE
MANAGER OF the iss PROGRAM The Manager of the ISS Program has overall ISS responsibility, with approval authority over all ISS Program documents, including this document. The Manager of the ISS Program is the chairman of the Space Station Program Control Board (SSPCB), which has overall responsibility for ISS technical integration. With respect to the FMEA and critical item program, the SSPCB is responsible for reviewing and approving all ISS critical items. SSPCB delegations for review and approval of critical items are documented herein.
ISS PROGRAM OFFICE ORGANIZATIONAL RESPONSIBILITIES
The ISS Program Manager delegated responsibility for FMEAs and critical items to the Safety and Mission Assurance Control Board (S&MACB). The Vehicle Control Board (VCB) and Avionics and Software Control Board (ASCB) have ownership responsibility for FMEA worksheets and critical items addressing their assigned hardware. System engineers assigned to support the VCB and ASCB are required to participate during review of FMEAs and critical items to ensure technical accuracy and completeness of the products.
safety and mission assurance control board responsibilities The S&MACB delegated responsibility for management of the FMEA and critical item process to the ISS Reliability and Maintainability Working Group (RMWG). The S&MACB reviews critical item presentations after the RMWG. For those critical items where an operational workaround is selected in lieu of hardware redesign, ISS Program approval authority is delegated to the S&MACB from the SSPCB. Prior to approval by the S&MACB, representatives from Johnson Space Center (JSC) Engineering, ISS Logistics and Maintenance, JSC Extravehicular Activity (EVA) Management Office, Systems Engineering and Integration, and JSC Flight Operations shall approve the operational workaround procedure. Operational workaround procedures include contingency procedures, EVA, and, if specifically approved on a case by case basis, maintenance. Critical items without operational workarounds are forwarded from the S&MACB to the SSPCB for ISS Program review and, if warranted, approval.
NASA reliability and maintainability RESPONSIBILITIES NASA Reliability and Maintainability (R&M) FMEA and critical item responsibilities, as delegated from the S&MACB, are described below.
3.2.2.1.1.1 Recommend FMEA and critical item programmatic requirements.
3.2.2.1.1.2 Provide interpretation and establish ground rules, when needed, to clarify intent of requirements.
3.2.2.1.1.3 Integrate NASA ISS S&MA functions as they relate to development, review and approval of the FMEA worksheets and critical items.
3.2.2.1.1.4 Perform oversight of the FMEA and critical item process throughout ISS life cycle to assure that all credible failure modes have been considered and addressed; that the CIL properly lists critical items as defined in this document; and that listed actions which mitigate effects, justify retention of critical items, and/or reduce risk of failure are properly implemented. In addition, ensure that logistical and operational considerations surrounding retention rationale are implemented.
3.2.2.1.1.5 Assess and address the adequacy of FMEA/CIL worksheets.
3.2.2.1.1.6 Ensure all hardware are traceable to the FMEA worksheets per Paragraph 5.1.
3.2.2.1.1.7 Ensure operational workaround procedures are developed and fully implemented by Flight Operations Directorate (FOD).
3.2.2.1.1.8 Recommend updates to this document.
3.2.2.1.1.9 Ensure FMEA/CIL worksheets are maintained current per Appendix H.
3.2.2.1.1.10 Serve as a focal point for the ISS FMEA/CIL database, which includes overseeing updates to the database software.
HARDWARE PROVIDER/OWNER AND ISS INTEGRATOR RELIABILITY AND MAINTAINABILITY RESPONSIBILITIES
3.2.2.1.2.1 Implement a FMEA and critical item program for their respective deliverable equipment and integrate S&MA functions as they relate to development of FMEA worksheets and critical items.
3.2.2.1.2.2 Consolidate, maintain current, and manage the integrated FMEA/CIL worksheets throughout ISS life cycle. (Only applicable to ISS integrator)
3.2.2.1.2.3 Perform oversight of the FMEA and critical item process to assure that all credible failure modes have been considered and addressed; that the CIL properly lists critical items as defined in this document; and that listed actions which mitigate effects, justify retention of critical items, and/or reduce risk of failure are properly implemented. In addition, ensure that logistical and operational considerations related to retention rationale are implemented.
3.2.2.1.2.4 Ensure a process that will facilitate the following:
| 1. | Availability of technical data to support FMEA development. |
| 2. | Use of the ISS FMEA/CIL database to generate and request approval of FMEA/CIL worksheets. |
3.2.2.1.2.5 Describe the end-to-end architecture of the system capability and provide hardware descriptions, including a list of functions and the associated system/subsystem hardware which perform the functions, and analyze the allocation of failure tolerance requirements.
3.2.2.1.2.6 Update the FMEAs provided by the hardware providers into an integrated FMEA for the assembly complete configuration that identifies both functional failure effects and the resulting failure effect on Station-level (capabilities)/ISS operations (i.e., crew/Space Station/mission success/visiting vehicle). (Only applicable to ISS integrator)
3.2.2.1.2.7 Conduct a FMEA for each mission phase for their respective deliverable hardware, and ensure all hardware are traceable to FMEA worksheets per Paragraph 5.1.
3.2.2.1.2.8 Verify that output failure mode effects adequately describe the manifestation of out-of-specification outputs on the inputs of interfacing hardware in order to verify that failures will not propagate.
3.2.2.1.2.9 Assess and document failure effects.
3.2.2.1.2.10 Provide critical item retention rationale to support risk acceptance of critical item. When an item is assessed a critical item by the ISS integrator, the hardware provider shall provide (as a minimum) design, test, and inspection retention rationale needed to establish controls for the failure causes.
3.2.2.1.2.11 Ensure operational workarounds documented in the critical item retention rationale are approved by FOD for implementation. Review status of implementation and reopen any approved critical item in the event the procedures deviate from the requirements established in the critical item retention rationale.
3.2.2.1.2.12 Recommend updates to this document.
3.2.2.1.2.13 Maintain FMEA/CIL worksheets current by updating them in accordance with Appendix H.
INTERNATIONAL PARTNER
IP FMEA and critical item responsibilities are to do the following.
3.3.1 Implement a FMEA and critical item program for their respective deliverable equipment. When negotiated and agreed to with NASA, the ISS FMEA/CIL database will be used to generate and request approval of FMEA/CIL worksheets.
3.3.2 Conduct a FMEA for each mission phase considering each applicable stage for their respective deliverable equipment and ensure all hardware are traceable to FMEA worksheets.
3.3.3 When requested, provide NASA with assistance in the preparation of the integrated FMEA/CIL worksheets. When critical items are developed as a result of integration, provide (as a minimum) design, test and inspection retention rationale needed to establish controls for the failure causes.
3.3.4 Provide for oversight of the FMEA and critical item process within their jurisdiction to assure that their FMEA/CIL documentation meets the ISS Program requirements.
3.3.5. Verify that output failure mode effects adequately describe the manifestation of out-of-specification outputs on the inputs of interfacing hardware and at the End Item interfaces in order to verify that failures will not propagate.
FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEMS PROCESS The FMEA and critical item process is described in the following paragraphs.
FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEMS PROCESS OVERVIEW The ISS hardware progress through Design, Development, Test and Evaluation, and Operations will be measured at specific milestone reviews that separate the maturation process into distinct phases. The typical phases are as follows: preliminary design (summarized at the Preliminary Design Review [PDR]), detailed design (summarized at the Critical Design Review [CDR]), development, operational preparation (summarized at the Flight Readiness Reviews [FRRs]), and operations (activities subsequent to launch, including assembly, man-tended operations, and permanent manned operations). The preparation and review of the FMEA and critical item is an integral part of the summary assessment made at each of the noted milestones. While ISS hardware may be designed to different milestones, the intent of the FMEA and critical item remains the same.
During design, the information generated as a result of the FMEA and critical item activities also serves as input to other design activities such as software development; Built-In Test (BIT) equipment design; and ORU packaging design to assure that items with critical failure effects receive special consideration in these varied areas. This information is utilized by other analyses such as hazards analyses, risk assessments, reliability analyses, and maintainability analyses.
After the design is baselined, the FMEA and critical item supports other activities. The FMEA provides documentation of the failure modes present in the system, the effects of failure mode occurrence, the methods of detecting the failure, and corrective action taken to prevent effects of failure (including restoration of function). For critical failure modes, and when required to be submitted for risk acceptance, the retention rationale justifies use of the critical item in the system. The retention rationale drives the inspection, process control, and test/verification requirements for the critical items; influences operations planning (including mission planning, procedure development, and logistical and maintenance support requirements); and reports failure history. Logistical and maintenance support requirements could be impacted by acceptance of a critical item; therefore, consideration of the following should precede formal acceptance of each critical item: total crew maintenance time allocations, logistical capabilities of the system, and microgravity (probability of success) requirements.
In order to be effective in fulfilling its purpose, it is essential that the FMEA be kept current with the ISS design and operational use. Items permanently disabled or removed from on-orbit operation do not require updates. The FMEA shall also be consulted in the review of design changes.
FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEMS ACTIVITIES THROUGH PRELIMINARY DESIGN Phase During the preliminary design phase, the purpose of the FMEA is to assess technical risk from hardware failure and determine the degree of equipment design compliance with the reliability design requirements (other design requirements may depend on the FMEA for verification) by formally documenting the effects and causes of all failure modes of the equipment being analyzed. Where technical risk and requirement noncompliance are indicated, the FMEA shall be used as a tool to drive iteration of the design (where practical) to eliminate risk and bring the design into compliance with the requirements. In order to minimize the impacts of design changes, it is essential that identification of technical risk and design nonconformance be accomplished as early in the design process as possible. At PDR, the FMEA shall address each system/subsystem at the functional level, as a minimum. If redesign is not practical, those functions that meet the criteria specified in Paragraph 6.1 (Section 8.0) shall be suitably documented in the preliminary CIL. Additionally, the preliminary CIL shall include a list of recommendations for elimination of design deficiencies through redesign during the detailed design phase, if possible. At PDR, the preliminary CIL is the medium through which technical risk items and nonconforming designs are presented to ISS Program Management at all levels for initial determination of actions.
FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM ACTIVITIES FROM PRELIMINARY DESIGN REVIEW THROUGH CRITICAL DESIGN REVIEW Based on the decisions made during the PDR, the ISS Program enters the detailed design phase. During this phase, the FMEA continues to be used to assess technical risk and determine the degree of equipment design compliance with the reliability design requirements. In preparation for CDR, the FMEA is developed to a greater level of detail (to the component level). As in the PDR, those functions that meet the criteria specified in Paragraph 6.1 (Section 8.0) shall be suitably documented in the CIL. The CIL at this point is the medium through which technical risk items and nonconforming designs are presented to ISS Program management for formal action (i.e., acceptance or redesign).
At the CDR, the CIL shall be evaluated. This evaluation will result in a preliminary indication of which items will be considered for ISS Program acceptance (accepted risks), and which critical items must be redesigned. Design options shall be presented early during the design phase to minimize any cost or schedule impact to redesign hardware and/or software. The CIL shall be retained until each critical item is either baselined via ISS Program approval or removed from the CIL based on a design change.
FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM ACTIVITIES SUBSEQUENT TO CRITICAL DESIGN REVIEW As a result of the CDR, actions will take place to implement design changes or to prepare ISS Program acceptance documentation for critical items. In the cases where design changes are not required, but where critical items would still remain on the CIL, appropriate ISS Program acceptance documentation shall be developed using the retention rationale previously identified in the CDR CIL. Any required updates to the retention rationale shall be made. If a subsequent design change eliminates a critical item, the FMEA shall be updated and forwarded for approval. In addition, action shall be taken to remove the item from the interim ISS Program CIL developed at CDR. If the design change does not eliminate the critical item, then the retention rationale shall be revised, as necessary, and ISS Program acceptance documentation developed.
At this time, the critical items are baselined and approved. The flight hardware baselining and approval process is defined in Section 6.0, Flight Hardware Critical Item Identification, Acceptance Rationale, and ISS Program Approval Requirements. The GSE baselining and approval process is defined in Section 8.0, Government Support Equipment Critical Items Criteria. After the design is baselined, the purpose of the FMEA is fundamentally changed. Formerly a tool for influencing design, it now becomes a tool for documenting controls needed to eliminate or mitigate risk. The status of items on the open CIL (critical items where requests for ISS Program acceptance have not been approved) shall be presented to management at subsequent milestone reviews to aid in assessment of the readiness of the system and the associated risks. The open CIL information presented at these reviews shall contain updates to the data that have occurred since the previous milestone. This data shall be presented during the Certification of Flight Readiness (CoFR) reviews in terms of the integrated open CIL. If changes to the design or functional use of the hardware alter the results of the FMEA and a current critical item is affected or a new critical item is created, then new ISS Program acceptance documentation shall be submitted.
FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM INTEGRATION ACTIVITIES The ISS integrator is responsible for the preparation of an integrated FMEA. The integrated FMEA shall be assembled from the FMEA information provided by the hardware providers. The ISS integrator shall examine all of the interfaces between hardware provider FMEAs to ensure that the endto-end functional failure effects and criticality determinations are correctly documented. This shall be accomplished for each of the mission phases of Paragraph 5.3. As problems are identified, the appropriate hardware providers shall be required to make appropriate corrections. In addition, and if applicable, the ISS integrator shall analyze each of the assembly stages where configuration changes occur (i.e., those flights not devoted solely to logistics or crew transfer). The ISS integrator shall integrate at all of the interfaces between hardware provider FMEAs to ensure that the functional failure effects and criticality determinations are correctly documented. When required, the hardware providers shall assist the ISS integrator in the preparation of the integrated FMEA. When critical items are involved, the hardware provider shall provide, as a minimum, design, test, and inspection retention rationale needed to establish controls for the failure causes. If warranted based on continued ISS assembly of modules or elements, the ISS integrator shall identify stage single failure points to the ISS Program. A stage single failure point is an item with a failure mode that can lead to loss of space station or life if the failure occurs during an assembly mission. For an item to be a stage critical item, the same failure mode is not assessed a critical item during the operations phase. Stage critical items are processed in accordance with Paragraph 6.4.1.
RELATION OF THE FAILURE MODES AND EFFECTS ANALYSIS and CRITICAL ITEM TO LOGISTICS SUPPORT ANALYSIS The ISS has adopted the Logistics Support Analysis (LSA) process as a means through which operations and logistics considerations that impact hardware design and long term logistics needs are identified and quantified. Maintainability analysis uses the results of FMEA to identify and document corrective and preventive maintenance actions (tasks) on ISS hardware. The LSA Control Number structure provides traceability from specific maintenance tasks to documented FMEA results, and follows a strict hardware breakdown. ISS Program Management uses LSA data, sorted by LSA Control Number, to conduct supportability assessments of hardware designs and logistics capabilities being developed for the operations phase of the ISS Program.
FLIGHT HARDWARE failure modes and effects analysis REQUIREMENTS, GROUND RULES, AND REPORTING REQUIREMENTS requirement applicability
5.1.1 A FMEA is required for the following items. These items are examples intended to generically reflect the types of items that require a FMEA. The RMWG will provided needed guidance concerning the requirement applicability to specific items, and may grant exceptions to these items if justified based on technical rationale.
5.1.1.1 All Orbital Replacement Units (ORUs).
5.1.1.2 Hardware with pivoting, sliding, or expansion joints.
5.1.1.3 Mechanical linkages (e.g., power bolts, gears, cranks, and other mechanisms with moving parts).
5.1.1.4 Capture/release devices such as capture latches.
5.1.1.5 Single mechanical barriers between oxidizer and fuel/combustible gas.
5.1.1.6 Pressure containers (vessels/tanks, hoses, couplers, and quick disconnects).
5.1.1.7 Filters.
5.1.2 A FMEA is not required for the following items. The FMEA will add no value as the failure characteristics are understood and causes of the failure are addressed through baselined design and test requirements, or the items are simple in design. These items are examples intended to generically reflect the types of items that do not require a FMEA. The RMWG will provide needed guidance concerning specific items.
5.1.2.1 Static mounting brackets and bolts, screws, or fasteners that are not part of a mechanical linkage.
5.1.2.2 Window glass.
5.1.2.3 Static primary and secondary structure such as truss structure and platform structure.
5.1.2.4 Consumable and non-reusable items (e.g., food, drugs, wipes, drug dispensers [syringes], sampling device containers, crew hygiene items).
5.1.2.5 Clothing, cushions, decals, and stowage containers (bags, nets, soft containers, fluid stowage containers).
5.1.2.6 Non-powered tools.
5.1.2.7 ORU mounting devices that are operated only for maintenance.
5.1.2.8 Handheld cameras and lenses.
5.1.2.9 Fittings.
LEVEL OF ANALYSIS
At PDR, the FMEA shall be documented for each system/subsystem at the functional level, as a minimum. The analysis shall identify failure causes (for those failure modes required by Paragraph 5.4 to a level sufficient to allow elimination of the cause by design action.
For CDR and subsequent updates, the FMEA shall be prepared to the component/ORU level as a minimum. For Criticality 1, 1S, and 2 single failure points, the analysis shall be performed within the component/ORU/assembly to the level necessary to identify all applicable Criticality 1, 1S, or 2 failure modes and their causes (reference Paragraph 5.13.1). In the event a higher level of integration creates a critical item, the associated organization is responsible for the analysis level. In addition, the failure causes must be defined at a level that will permit inspections/tests to be devised and will serve to assure that the cause is not built into the hardware or is not present before use of the item. The FMEA must always be updated as the design changes. Appendix H includes the process for performing FMEA updates.
MISSION PHASES
The FMEA shall consider effects of failure modes during the ISS mission phases specified below. The mission phases will be assessed for each failure effect level, as identified in Paragraph 5.6.
Prelaunch - Commences at installation in launch vehicle in the configuration to be launched.
Transportation - Begins at launch, and includes ascent, and launch abort return.
Assembly - Begins with on-orbit checkout and includes assembly operations.
Operations - Begins at completion of assembly and includes on-orbit operations.
Return - Begins with disassembly/demate, and includes return to earth, post-landing operations, and safing.
FAILURE MODE CONSIDERATION
All credible hardware failure modes shall be considered. Failure modes should be postulated after consideration of the following four basic failure conditions:
| 1. | Premature operation. |
| 2. | Failure to operate within specification or failure to operate at a prescribed time. |
| 3. | Failure during operation, including failure to contain or store energy or fluids. |
| 4. | Failure to cease operation at a prescribed time. |
Failure modes may be ruled as non-credible if sufficient technical rationale is established to show the failure will not occur during the defined operational mission of the item under consideration. The RMWG shall have final authority to determine credibility of failure modes.
FAILURE CAUSES
The FMEA shall identify all potential causes for the failure mode under analysis. Failure modes assessed Criticality 3 are exempt from this requirement. Failure modes assessed criticality 2N/2NR are exempt, but only for those cases when the item under analysis is “off the shelf.” If a criticality 2N/2NR item is “off the shelf” with minimum modification, the requirement is exempt if there is no change in functionality. If needed, the RMWG will provide guidance for applicability.
FAILURE EFFECTS
The analysis shall document the worst case failure effects and identify those functions and mission phases for which the specified effects apply. The assessment shall only address failure effects of the item under analysis. The assessment shall assume no redundancy exists for the item under analysis and that the crew operates in accordance with established procedures (see Paragraph 5.13.2). Except for safety and protective items, the assessment shall assume no other failures have occurred.
Safety and protective items are unique and require a different approach to capture the worst case effect. When assessing these items, the analyst shall assume the event (may be failure or non-failure related) warranting functionality of the item has occurred. Without this assumption, safety and protective items would have no failure effect and be assessed “Criticality 3.”
Failure effects shall be documented at the following levels, where applicable, for each mission phase identified in Paragraph 5.3:
· ORU/Assembly - Identify the worst case local failure effects on the particular item under analysis and its interfaces.
· Subsystem/Next assembly - Identify the worst case failure effects at this level, and document any failure propagation effects (see Appendix K).
· End-item/Segment - Identify the worst case failure effects on the various allocated EndItem functions/capabilities performed or supported by the item under analysis.
· Crew/Space Station/Visiting Vehicle - Identify the worst case high level effects at this level (as applicable) resulting from the degradation and/or loss of the End-Item functions and capabilities.
INTERFACES
The ISS integrated FMEA shall consider hardware interfaces. All failures must be analyzed across its interfacing End Item/Segment to determine worst case effect. Failure modes that could propagate, causing failure and damage to interfacing hardware, including visiting vehicles, shall be identified. The ISS integrated FMEA performed by the ISS integrator will examine the effects of failures across all interfaces.
tIMELINES The FMEA shall include estimates of “time to effect” and “time to detect” (reference Appendix C, Items 42A and 34A, respectively). “Time to effect” is defined as the estimated time from failure mode occurrence to manifestation of the worst case failure effect, assuming no redundancy. “Time to detect” is the estimated time from failure occurrence to detection of the failure by the flight or ground crew. Timeline data which is available from the safety, maintainability, or logistics disciplines shall be utilized whenever possible to avoid duplication of effort. Dormant failures detectable upon attempted operation by a crew member or ground personnel may use the term “immediate” to communicate “time to detect.” The following are exempt from this requirement:
| 1. | Failure modes assessed Criticality 3. |
| 2. | Failure modes assessed Criticality 2N/2NR where the item under analysis is a maintenance item, “off the shelf”, or “off the shelf” with minimum modifications that do not affect functionality. (Applies to FMEA updates performed during sustaining as these are items that would qualify for an Initial Assessment of Criticality (IAC) if the analyses were performed today.) |
| 3. | Failure modes for Criticality 2N/2NR items authorized to use the IAC. |
| 4. | Failure modes for Criticality 2/2R items where FMEAs were approved prior to Revision E of this document. The exemption does not apply if the FMEA is updated during sustaining or as a result of a design change. |
Initial assessment of criticality JSC Form 1380, Initial Assessment of Criticality (IAC), captures a “short version” of a FMEA and can be used for a couple of reasons. It can be used to provide early identification of criticality as “criticality” of hardware is often needed to baseline requirements for “Electrical, Electronic, and Electromechanical Parts” and “Test and Verification.” The IAC may be used in place of a FMEA when the item being analyzed is “off the shelf” or with minimum modifications that do not affect functionality. This requires approval by the RMWG. When determining use of the IAC to replace a FMEA, consideration shall be given to availability of design data from the hardware provider, benefit of developing a detailed FMEA if analysis may not drive iteration of the design, and risk to the Safety and ISS Operations community from not having all data fields of a FMEA worksheet available for review. Additionally, the IAC may be used to document criticality for items that do not require a FMEA and of which criticality is needed to support a Problem Reporting and Corrective Action (PRACA) report. The IAC is included in this document as Appendix G. The IAC is an initial assessment of criticality and FMEA applicability. The IAC can be update to change either criticality or FMEA inclusion post initial approval if deemed necessary per the RMWG Chair.
UNIQUE failure modes and effects analysis REQUIREMENTS
CABLES/HARNESSES/CONNECTORS
FMEAs shall be conducted on wire and optical fiber harnesses, cables, and electrical and optical fiber connectors. FMEA worksheets for harnesses determined to carry signals others than those assessed Criticality 3 shall be delivered in accordance with this specification. Failures of harnesses carrying signals assessed Criticality 3 can be documented by reference to the connected hardware FMEA. The referencing of harnesses to affected downstream hardware items may take the form of a matrix or table.
FLUID SYSTEMS
“External leakage” shall be considered a credible failure mode for any hardware item except one piece continuous rigid fluid lines and surfaces mated by inspectable welding, brazing, or permaswage. The internal leakage failure mode of any active fluid control hardware (e.g., valves, pumps, regulators) shall be considered a credible failure mode.
ContiNgency equipment Contingency Equipment (CE) are those items provided for ISS crew members to respond to certain hardware failures to prevent a catastrophic event from occurring. CE is often identified in retention rationale for a critical item and/or as a control for a hazard. Criticality shall be determined after (1) considering the worst case effect from total loss of functionality from the CE and (2) assessing inherent catastrophic failure effects of the CE. Because loss of functionality provided by the CE results in the same worse case effect as that of the ORUs or items that have to fail (for the CE to be used), the criticality will recognize the failure tolerance associated with hazard control. The redundancy screens become not applicable, and the CE does not become a critical item. The CE FMEA shall reference the ISS hardware FMEA in the “Remarks” data field.
If a failure of the CE has a catastrophic effect during operational use (other than loss of functionality), the criticality will reflect that catastrophic effect. Any inherent redundancy will be identified and assessed for compliance with the redundancy screens. The FMEA worksheet shall reference the appropriate hazard report, and no critical item retention rationale is required (see Paragraph 6.6).
items with hazardous effects <moved to paragraph 6.6.1> The requirements previously captured in this paragraph are now included in Paragraph 6.6.1.
pressure vessels The criticality assigned to pressure carriers shall reflect the worst case failure effect considering the design characteristic of the pressure carrier. Rupture of a metallic pressure vessel designed to “leak before burst” shall not be considered credible. Analysis of a pressure vessel does not require assessment of Micro-Meteoroid Orbital Debris (MM/OD) as a cause. MM/OD is addressed separately in the hazard analysis by the Safety Review Panel (SRP). Rupture of a composite pressure vessel designed to “leak before burst” shall be considered credible. To scope the failure effect of rupture for composite pressure vessels that may be pressurized above 1/3 design burst pressure, a blast analysis may be performed to determine impact on structure, ground personnel, and crew. Regardless of the design, any pressure vessel internal to a pressurized module shall be assessed for compartment over-pressurization potential. A single failure resulting in leakage of combustible gasses in the presence of a possible ignition source (including self-ignition) shall be listed as potential fire/explosion. The criticality shall reflect, as redundancy, any safety device(s) designed to preclude the failure effect from occurring.
Habitable Single string elements When analyzing single-string elements that are not inhabited on a full time basis, such as the Airlock, consideration shall be given to the adjoining ISS module(s) as a redundant means of providing life support functions, so long as flight crew evacuation of the affected module is a viable failure response.
Assessment of Commercial off- the-shelf hardware Commercial Off-The-Shelf hardware may be assessed using the JSC Form 1380, Initial Assessment of Criticality (IAC). If the item is being procured “as is” or with minimum modification (i.e. no change in functionality), the IAC may serve as the official FMEA. See Paragraph 5.9 for criteria on use of an IAC.
non-disabling injury and damage to hardware Failures that result in injury to ground personnel or crew members, or damage to hardware, shall be assessed Criticality 2N/2NR. For those failures where it is difficult to determine if worst case effect is injury to or loss of personnel, or damage to or loss of ISS, dialogue with a SRP chair may be required to ensure consistency with the hazard report and FMEA worksheet.
INPUTS AND OUTPUTS
All inputs to an item being analyzed shall be assumed available and within specification. For each failure mode, the outputs will be analyzed using this assumption and effects shall be documented per Paragraph 5.6.
IDENTICAL ITEMS
Identical items that perform the same function in the same environment, where the only difference is location, may be analyzed only once provided the failure effects for the items are the same. Identical items that perform different functions, or which have different functional failure effects, must be analyzed separately.
CRITICALITY DETERMINATIONS
CRITICALITY ASSIGNMENTS
Criticality is used to identify effects of a failure mode as it pertains to Space Station, personnel, and mission (as defined herein). Criticality Category 1 reflects the various criticalities that result in loss of Space Station and personnel. The criticalities include 1, 1R, 1S, and 1SR.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .