Draft SSP XXXX_ USDV Operations Standards.pdf
PDF 1 MB Posted
- Attached to
- International Space Station Deorbit Capability Federal contract opportunity
- Solicitation number
- 80JSC022ISSDeorbit
View the file
Other files for this federal contract opportunity
Show all 26
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
National Aeronautics and Space Administration
DRAFT
SSP-XXXX
Revision: Draft
U.S. Deorbit Vehicle Operations Standards
Joel Montalbano Date Manager, Insternational Space Station Program
USDV Operations Standards SSP-XXX Revision: DRAFT
TABLE OF CONTENTS
1.0 INTRODUCTION
1.1 PURPOSE
1.2 VERB APPLICATION
1.3 PRECEDENCE
1.4 DELEGATION OF AUTHORITY
2.0 REFERENCE DOCUMENTS
3.0 OPERATIONS PLANNING
3.1 GENERAL OPERATIONS STANDARDS
3.2 STANDARDS FOR MISSION MANIFESTING
3.3 STANDARDS FOR FLIGHT DESIGN
3.4 STANDARDS FOR NOMENCLATURE DEFINITION
3.5 STANDARDS FOR OPERATIONS PROCEDURES
3.6 STANDARDS FOR VEHICLE TIMELINES
3.7 STANDARDS FOR OPERATIONS FACILITIES AND GROUND MONITORING/CONTROL SYSTEMS
3.8 STANDARDS FOR LAUNCH COMMIT CRITERIA
3.9 STANDARDS FOR FLIGHT RULES
4.0 OPERATIONAL CONTROLS
4.1 OPERATIONAL HAZARD ANALYSIS AND PROCEDURAL MITIGATION
5.0 OPERATIONS TRAINING
5.1 OPERATIONS PERSONNEL TRAINING STANDARDS
5.2 OPERATIONS TRAINING STANDARDS ASSESSMENT
6.0 OPERATIONS EXECUTION
6.1 OPERATIONAL COMMUNICATION PLANS
6.2 OPERATIONS MANAGEMENT PLANS
6.3 REAL-TIME ANALYSES
6.4 CONTINGENCY ACTION PLAN
7.0 ANOMALY AND LESSONS LEARNED TRACKING AND RESOLUTION
7.1 ANOMALY TRACKING AND RESOLUTION
APPENDIX A: ACRONYMS
APPENDIX B: DEFINITIONS
1.0 Introduction
TBR
1.1 Purpose
TBR
1.2 Verb Application
Throughout this document set, will is used in a statement of fact, declaration of purpose, or expected occurrence; shall is used for binding requirements that must be verified and have an accompanying method of verification; and should denotes a statement of best practice.
1.3 Precedence
TBR
1.4 Delegation of Authority
This document was prepared by NASA’s ISSP, and will be maintained in accordance with standards for ISSP documentation. The ISSP is responsible for assuring the definition, control, implementation, and verification of the requirements identified in this document.
a. Include expected launch dates.
b. Ensure additional assigned hardware elements (such as spacecraft, engines, launch vehicle)have been accounted for through a configuration management system that identifies any changes from the baseline manifest.
c. Identify flight unique ground support requirements for the mission,GFE, NASA-provided supplies, and logistics.
d. Include flexibility to accommodate late changes due to unforeseen events such as weather, , range scheduling issues or other such circumstances.
3.2.1 Mission Manifesting Process Assessment
NASA will review the mission manifesting processes and audit the mission manifesting products.
3.3 Standards for Flight Design
3.3.1 Mission Trajectory Analyses Process
Pre-mission trajectory analysis should be performed to ensure that safety and mission requirements can be successfully met. These requirements include, but are not limited to, performance, constraint, and dispersion characteristics that influence or limit trajectory design and USDV certification requirements.
This process should include:
a. Design and analysis of the nominal and off-nominal trajectories flown by the integrated space vehicle, vehicle elements, and jettisoned or expended components during the ascent, orbit, rendezvous, re-rendezvous, and de-orbit phases of flight under nominal, dispersed, and pre-determined failure conditions.
b. Satisfaction of mission, hardware, and software constraints.
c. Provisions for incorporating changes to mission requirements into revised analyses.
d. Coordination as appropriate to meet all other regulatory requirements for launch.
e. Pre-launch Range clearance and orbital collision avoidance.
3.3.2 Mission Design Analyses
To ensure a mission is operated safely, mission design analyses should:
a. Assess separation from the launch vehicle and separation of jettisoned or expended components during all flight phases to ensure that recontact does not occur.
b. Analyze all operations within proximity of another spacecraft to ensure safety of relative motion, including off-nominal events, breakouts, etc.
c. Ensure that trajectory plans allow for converged orbit determination prior to targeting and executing subsequent maneuvers.
d. Assess nominal and contingency deorbit opportunities.
e. Analyze the communication coverage and availability of ground and orbital assets.
f. Determine public and mission essential personnel safety risks for launch, ascent, aborts, and re-entry, including disposal of non-recoverable elements and coordinate with appropriate responsible external entities (e.g. FAA, launch range, etc.).
g. Be performed with math models that include sufficient dispersions to assure that trajectory-driven mission objectives and safety constraints (e.g., rendezvous, re-rendezvous, etc.) are not compromised.
h. Provide for the capability to assess trajectory changes and deviations in near real-time and to develop alternate trajectory plans as required to ensure mission success.
3.3.3 Consumables and Resources Analyses Process
Analyses should be generated for propulsive and non-propulsive consumables and onboard resources used by the integrated space vehicle.. The intent of these analyses is to:
a. Determine the minimum required on-orbit propellant, plus reserves, required to support all nominal and off-nominal trajectories flown by the integrated space vehicle during the ascent, orbit, rendezvous, re-rendezvous, and de-orbit phases of flight under nominal, dispersed, and pre-determined failure conditions, including dispersions deemed highly probable and/or critical to integrated space vehicle safety and the high-priority mission objective.
b. Provide consumables loading profile and integrated space vehicle mass properties data to ensure the integrated space vehicle is operated within capability/certification limits for the duration of the mission.
c. Assess and manage propulsive consumables profile and integrated space vehicle mass properties with respect to nominal mission plan..
d. Assess and manage on-orbit power and resource demand for vehicle systems based on mission profile, as required.
3.3.4 Flight Design Standards Assessment
NASA will review the flight design processes, tools, and analyses, and the consumables budgeting process. NASA will also review any tools used in real-time or near real-time to assess or alter vehicle trajectory. NASA will also observe simulations to verify operations personnelhave adequate situational awareness and capability to safely and accurately fly nominal and off-nominal trajectories and make changes to the trajectory as needed to account for perturbations, dispersions, off-nominal situations and other events.
3.4 Standards for Nomenclature Definition
In order to provide consistent terminology across the USDV elements for operational use, a standard operational nomenclature should be developed.
3.4.1 Standards for Nomenclature Definition
The Contractor should identify how launch vehicle and spacecraft components will be labeled and referred to in operational documentation, including procedures. This operational nomenclature should be consistent in ground test procedures to minimize confusion across various phases of ground processing, launch, and mission phases. In some cases, this nomenclature may already be defined by existing components (e.g. existing launch vehicle nomenclature). The intent is not to change this existing nomenclature, but the Contractor should still list these in the nomenclature definition to ensure operations personnel use the same terminology and to ensure it does not conflict with other vehicle terminology. The nomenclature list should be easily accessible to operations personnel who develop operational documentation. The list should also take into consideration the nomenclature used by ISS and attempt to avoid conflicts with this existing nomenclature as much as possible. The ISS operations nomenclature definition can be found in SSP-50254 or in the operations nomenclature database at http://www.nasa.gov/centers/johnson/slsd/about/divisions/hefd/project/op-nom.html.
3.4.2 Nomenclature Definition Assessment
NASA will review the Contractors process for development of an operational nomenclature standard and audit the documentation or database that stores the standard nomenclature. NASA will also observe the Contractorsuse of operations nomenclature and adherence to their standards during training, simulations and other activities.
3.5 Standards for Operations Procedures
Validated operations procedures are fundamental for successful operations. Defective procedures can lead to errors or omissions that can endanger the mission. The generation and maintenance of procedures is critical to ensuring ground and flight operations occur in a consistent high-quality manner.
3.5.1 General Standards for Procedures
All procedures, whether developed for ground operations, and in-flight operations should follow these general standards:
a. Procedures should be validated prior to use in operations. Validation of procedures may include human-in-the-loop testing, real or simulated flight or ground hardware, operational or programmatic simulations, etc. Validation of procedures involving software should utilize real flight (or ground) software to the greatest extent practical.
b. Procedures should address nominal operations, as well as off-nominal and emergency scenarios, which have been identified by test, analysis, or system experience, or which are determined to be safety critical based on likelihood or resulting consequence.
c. Procedures should include placards, cautions, warnings, or other notes when a hazardous operation or procedure affects or could affect a safety-critical system or the safety of personnel, the public, or the environment.
d. .
e. Procedures should be written in a standard Contractors-defined format, consistent among
USDV elements to the greatest extent possible, to facilitate ease of use by operations personnel, and adhere to the nomenclature standard.
f. Procedures should verify hardware is within the life-cycle and/or shelf-life limits and will remain so throughout ground processing and mission execution (e.g., ordnance, batteries, paints, soft goods, sealants, desiccants, etc.).
g. Procedures should verify constraints prior to performing a task.
3.5.2 Standards for Ground Operations Procedures
Ground operations procedures are designed to protect personnel, flight hardware, and facilities during the assembly/integration/test, launch preparation, launch countdown, and post-launchphases of a mission. All ground operations procedures should:
a. Verify critical skills/certifications and task team readiness of personnel required to perform tasks.
b. Maintain/verify the integrity of the flight hardware preserved within USDV certification while interfacing with all Ground Support Equipment (GSE) and facility systems, and account for natural and induced environments encountered throughout the handling/transportation operations, assembly/integration/testing, pre-launch processing, and launch operations phases.
c. Include instructions for the reconfiguration of flight hardware (e.g., rotating orientation).
d. Include instructions for installation and removal of non-flight hardware on or into the launch vehicle or spacecraft (e.g., platforms, protective covers, remove before flight tagged items, non-flight switch covers, etc.).
e. Verify ground hardware readiness prior to continuing into subsequent phases of processing.
f. Support processes for metrology and other critical support activities and ground related records.
g. Include instructions for test, checkout, power on/off, and monitoring.
h. Include instructions for handling, storing, sampling/testing, and servicing of commodities of the USDV (e.g., fuel, oxidizer, helium, nitrogen, etc.).
i. Configuration accounting and verification of requirements and procedures
j. Photograph closed-out areas and final configuration.
k. Include emergency instructions for launch vehicle and spacecraft safing for any hazardous operation or emergency power down procedures.
l. Include vendor specific support and maintenance plans.
m. Include sufficient reference to engineering drawings and photographs where drawings/photographs are needed for clarification or orientation.
n. Identify and account for ground access and handling (i.e. protective covers, guards, etc.)
o. Include adverse weather plans (e.g. lightning retest, hail, high winds).
p. Define rules governing handoff of authority or control from one USDV element to another that:
1) Clearly identify roles and responsibilities of each party involved in the handoff.
2) For the receiving party, clearly define and document the current configuration including any incomplete or unplanned work at the time of the handoff.
q. Ensure successful assembly/integration/test ground procedures by including the following:
1) Flight element mating and interface testing.
2) Inventory assignment/distribution process and records which provide adequate control and traceability of critical parts and materials from the source to the final “as built” configuration.
3) Include instructions for the inspection of the flight hardware prior to, and after, any handover transaction between USDV elements occurs.
r. Ensure successful launch preparation and countdown by including the following:
1) Process to prepare and safely operate the launch site prior to and after a launch.
2) Timeline for execution of operations.
3) Updated weather reports as required.
4) Launch readiness polling process (e.g. Range, Program Management, Technical
Authorities, weather).
5) Execution plan for launch countdown, scrub, and recycle.
6) Plan for safely entering blast danger area after hazardous commodity loading on launch day (e.g., control switching, configuration monitoring and visibility, restricted access control).
7) Contingency operations (e.g. launch scrubs post fueling of the launch vehicle).
8) Fault detection and response.
9) End-to-end verification of all communication and command interfaces.
10) Establishing and maintaining communications with the, spacecraft, operations personnel, and external stakeholders.
11) Remote commanding of the integrated space vehicle.
12) Telemetry processing and management.
3.5.3 Standards for Flight Operations Procedures
Flight operations procedures for mission controllers and flight crew should encompass all aspects of final launch preparations, integrated space vehicle operations, and mission-specific tasks/payloads/experiments to safely and successfully execute missions.. The procedures should follow these standards:
a. Flight operations procedures should clearly designate who is to perform which actions, especially between mission control personnel, as required. Identify if the action must be performed at a specific time or if the action is time-critical.
b. A process should exist for the generation or modification of procedures in real-time in the event a procedure error is found or an unexpected situation is encountered. This process should involve review by appropriate engineering teams and validation of the procedure on simulated or real flight hardware, if time permits.
3.5.4 Operations Procedures Standards Assessments
NASA will review documentation, tools and standards that define how ground and flight procedures will be generated, validated and updated. NASA will review a subset of ground and flight operations procedures. The emphasis of the review will be on the content provided and the operations personnel’s ability to understand and execute required tasks during nominal and off-nominal scenarios. NASA will also observe the use of procedures by operations personnel during training, simulations and operations to ensure standards are exercised.
3.6 Standards for Vehicle Timelines
Vehicle timelines, sometimes called flight plans, provide a framework of the nominal mission and select contingencies, including scheduled operation of flight hardware and software, mission objectives and events, and attitude timeline.The plans should encompass the entire mission from launch countdown through ascent, orbit, docking, ISS-mated operations, and de-orbit operations.
3.6.1 Standards for Vehicle Timelines
Generic and mission-specific planning ground rules and constraints should be developed to provide the operations personnel activity guidelines for generation of the mission timeline, including ground commanding. Effective flight plans should:
a. Integrate mission objectives, integrated space vehicle requirements, trajectory, consumables, and resource usage into an efficient and cohesive plan.
b. Integrate operations timelines across all USDV elements.
c. Provide a timeline of nominally scheduled mission events, spacecraft maneuvers, and attitude hold periods, including estimated durations for each, to be utilized for mission execution, as well as power and consumables analyses.
d. Identify the availability of communication coverage to flight operations personnel.
e. Designate operations personnel responsible for each mission event, task, and command execution, if appropriate.
f. Ensure that the timing of major events is coordinated to a standard reference time across all systems.
g. Be created in a format which allows for revisions/replanning to occur in a timely manner.
h. Coordinate a joint timeline with the ISS.
3.6.2 Vehicle Timelines Assessment
NASA will review the Contractorstimelines. An emphasis will be placed on the mission controller’s ability to understand what activities will be performed at any given time, to correctly identify the appropriate procedure to run and to update the timeline as necessary. NASA will also review any configuration management process and documented constraints used in generation of timelines.
3.7 Standards for Operations Facilities and Ground Monitoring/Control Systems A part of the planning process should include the development of facilities and operations products needed for ground monitoring and control of the spacecraft. The facilities used in operations include those needed for prelaunch ground processing and for mission controllers to perform in-flight monitoring and control.
3.7.1 Standards for Operations Facilities
Operations facilities will ensure that mission critical infrastructure is protected, maintained, and kept in a state of readiness. All facilities used in operations should:
a. Ensure appropriate security (access control) protocols are used to limit access to the facility and its critical infrastructure to only those personnel who are qualified. These security protocols should ensure that unauthorized personnel cannot have access to or damage flight hardware during ground processing or gain access to systems that would allow for unauthorized commanding of a spacecraft during flight.
b. Ensure that sensitive data transmitted to and from the facility is secure and that unauthorized personnel cannot access private or critical information about the spacecraft..
c. Allow for maintenance of the facility without interruption to ongoing operations (e.g. coordinate planned outages, be able to perform equipment changeout during a flight by switching temporarily to a backup equipment set).
d. Ensure that facility operations do not induce hazards into the flight hardware.
e. Provide redundancy in critical systems to allow operations to continue despite ground component or system failures.
f. Ensure that the facility can support flight-specific configuration changes.
g. Provide documented organization interface agreements that define the responsibilities of external organizations that use or operate the facility and how those organizations work together.
h. Provide operations personnel with near-real-time access to stored engineering data and telemetered/stored flight data for the launch vehicle and spacecraft. This data should be available to assess the health of the integrated space vehicle for launch countdown or the ongoing flight, to support troubleshooting during a mission or major test.
i. Ensure that data availability and integrity is maintained for operations personnel continuously and redundantly during a mission to protect for ground systems failure(s).
j. Develop a plan that implements an integrated system architecture to capture, confiscate, and embargo all data for use in reconstruction of an accident or mishap. Coordinate this plan with the Contingency Action Plan (reference section 6.4).
3.7.2 Ground Control/Monitoring Systems
Mission operations infrastructure also requires operations products that may include configuration files, display definitions, settings and databases that provide the means for mission controllers to monitor data, send commands and plan/organize operations during the mission. The operations products that support ground monitoring and control should:
a. Have a defined process to ensure that onboard flight software is synchronized with ground tools.
For example, ensure that telemetry available on the ground matches telemetry generated by the vehicle.
b. Be tested in an end-to-end environment that includes the facility, the integrated space vehicle(s) and/or a high-fidelity simulator, and other USDV elements.
c. Have documented standards for software validation for any software that will be used to make mission-critical decisions, including any tools used by mission controllers to perform calculations necessary to the operation of the spacecraft.
d. Have a qualification process for all planning tools, such as timeline/procedure viewers, messaging tools, software used to create or modify procedures in real-time, etc.
3.7.3 Facilities and ground monitoring/control systems products assessment NASA will inspect operations facilities. NASA will also review any documentation that defines the process for generating, updating and testing products that are used as part of ground monitoring and control, such as telemetry displays, alarm engines, command databases and other such products. NASA will review documentation that describes how ground facilities interface directly with flight hardware.
NASA will also observe the facility performance during training exercises and simulations. This review will ensure a clearly defined process that is configuration managed and ensures facilities and products used in ground systems are adequately tested before flight.
3.8 Standards for Launch Commit Criteria
The Commercial Provider should utilize launch commit criteria (LCC) to minimize the amount of real-time rationalization that is required when off-nominal situations occur during launch countdown. These LCCs contain several types of important information:
a. Definition of authority and roles/responsibilities
b. Supporting rationale and history for provided limits in the LCC
c. Affected measurements/telemetry
d. Time efficacy of the LCC
e. Violation criteria of the LCC
f. Justification for continuing launch countdown through a LCC violation
g. LCC should constrain launch if a subsequent problem could result in a vehicle loss unless an assessment of subsequent problem likelihood and specific effects determines the condition is acceptable.
The Commercial Provider should ensure that the information listed above is readily available to operations personnel, whether in the form of a Launch Commit Criteria document or through other electronic or documented means. This material should adhere to the following expectations:
a. Pre-determined decisions should be supported by analysis using validated methods or tools to ensure that all expected flight configurations are within the design limits of the USDV.
b. Supporting rationale should be documented as applicable.
c. These documents should be reviewed and approved by appropriate subject matter experts or other USDV personnel.
d. A process should be developed to ensure that any violation of design/operational limits, operations controls or pre-defined decisions is tracked. Appropriate personnel, such as management or subject matter experts, should be made aware of any such violations through this process and impacts to other operations and/or hardware capabilities should be assessed and documented.
3.8.1 Standards for Launch Commit Criteria Assessments
NASA will review the structure and process for the generation and configuration management of LCC to ensure it contains adequate information to guide operator decision-making during launch countdown.
A subset of LCC will also be reviewed.
3.9 Standards for Flight Rules
Flight rules are used to guide operational personnel. These flight rules contain several types of important information:
a. Definition of authority and roles/responsibilities of operations personnel, control centers and flight crew throughout all mission operations.
b. Design and operational limits of hardware and human limitations to which the operations team should adhere.
c. Operational controls to hazards.
d. Predefined decisions as a response to off-nominal situations or as a criteria for continuing into the next phase of an operation or mission (e.g. go to continue the rendezvous if this computer fails). This also includes LCC that define the system capability and redundancy required to proceed with a launch.
The Commercial Provider should ensure that the information listed above is readily available to operations personnel, whether in the form of a flight rules document or through other electronic or documented means. This material should adhere to the following expectations:
a. Predetermined decisions should be supported by analysis using validated methods or tools to ensure that all expected flight configurations are within the design limits of the USDV.
b. Supporting rationale should be documented as applicable.
c. These documents should be reviewed and approved by appropriate subject matter experts or other USDV personnel that provide data or constraints driving flight rules.
d. A process should be developed to ensure that any violation of design/operational limits, operations controls or pre-defined decisions is tracked. Appropriate personnel, such as management or subject matter experts, should be made aware of any such violations through this process and impacts to other operations and/or hardware capabilities should be assessed and documented.
3.9.1 Flight Rules Standards Assessment
NASA will review the structure and process for flight rules generation and configuration management to ensure it contains adequate information to guide operator decision-making during flight. A subset of flight rules will also be reviewed.
4.0 Operational Controls
Operations products will employ structured and documented processes for ensuring safety, monitoring ground processing and mission progress, making informed decisions, and addressing situations outside of nominal planned events. These processes will include sufficient technical rationale based upon the best available analysis and understanding of USDV design and capabilities.
4.1 Operational Hazard Analysis and Procedural Mitigation
The approved hazard analysis process should identify operationally induced risks and the mitigation of identified risks through operational controls. A closed-loop process should be incorporated to verify that all hazards accepted on the basis of an operational control (e.g., flight rule, limit, or procedural control) are accurately reflected in the operations products.
The Operational Hazard Analysis and implementation of resultant procedural mitigations should:
a. Identify and document operational hazards and operational controls for hazards, and ensure that hazards identified in hazard reports as having operational controls can be clearly linked to a specific operational product (e.g. procedure, flight rule, etc.).
b. Identify accepted hazards that have no operational controls and document strategies to mitigate those hazards and maximize mission success.
c. Ensure that any hazards associated with or controlled by an operation are clearly identified (e.g., through physical placards or warning notes in a procedure) and cannot be changed or waived without approval per the Hazard Report approval process or section 6.2 Operations Management Plan.
d. Ensure that the process allows for operational control implementors to modify or reject operational controls that cannot be implemented as written.
e. Establish a verification process to ensure that all hazards accepted as operationally-controlled are implemented (e.g. procedures, flight rules and/or training) and in place to accomplish that control.
f. Ensure that personnel who may be exposed to hazards or hazardous operations are appropriately trained and informed.
g. Address perceived hazards brought forth by stakeholders or external partners.
4.1.1 Operational Hazard Analysis and Procedural Mitigation Assessment NASA will review the Commercial Provider’s documented process(es) for identifying and implementing operational controls to hazards. NASA will also review the implementation of all operational hazard controls. NASA will confirm that the implementation of operational hazard controls can be executed as planned through observation of training exercises such as simulations.
5.0 Operations Training
All personnel with safety critical or mission critical roles should be adequately trained and fully capable of performing their duties in a competent manner. Documented training plans should be established for each unique safety critical or mission critical position staffed by operations personnel. These training plans should culminate in a certification that is valid for a set period of time. Proficiency training and evaluation should be performed to renew certifications on a periodic basis. Industry standards may be utilized to fulfill some certificationsif applicable.
Training plans may consist of self-study/readings, classroom lessons, computer-based training, hands-on training with hardware, simulations, evaluations or other methods. Personnel who conduct training lessons or simulations should be certified to conduct these lessons.
The following standards should be employed for training all operations personnel:
a. Training programs should include evaluation standards for demonstrating student mastery of the subject material.
b. Formal training records and evidence of satisfactory completion should be documented, maintained, and made readily accessible to ensure that necessary certification, licensing, or currency requirements are met prior to performance of safety and mission critical tasks.
c. There should exist at least one training environment that includes high-fidelity hardware representations of the USDV and at least one that includes a high-fidelity functional representation of the USDV (i.e. operates as the real vehicle even if hardware does not exactly match the physical layout of the real vehicle). These capabilities might also be available in a single training facility.
d. Certification for joint operations (involving cooperative operations with another vehicle, program, or external organization) should include joint integrated simulations with the appropriate external organization(s) using a high-fidelity vehicle simulation. Joint integrated simulation capability may require the ability to connect a USDV simulator to the joint operation partner’s simulators. Joint integrated simulations should cover nominal and off-nominal scenarios and the capability to conduct training in parallel with an ongoing mission should exist.
For more information about conducting joint training with the ISS operations team, refer to JSC- 35089, Visiting Vehicle Operations Document.
e. Ensure ground simulations conducted for launch countdownare conducted using high-fidelity flight representative systems and functional representation of the USDV, including support services, as applicable.
f. Identify or establish medical certification standards for safety critical positions. Medical standards should be consistent with comparable aviation or other applicable occupational standards or certifications appropriate for the criticality of the function and should be approved by qualified medical personnel. Medical certifications should be renewed on a periodic basis, the frequency of which is appropriate to a task or as otherwise recommended/required by standards established by the responsible medical authority.
g. Ensure that training programs are updated to incorporate lessons learned from training, actual operations, and changes in hardware/software design, or changes in external interfaces, with a process for tracking these updates.
h. Provide specific training for any events or objectives that are unique to a given mission (i.e.
mission specific vs. generic training).
5.1 Operations Personnel Training Standards
These standards apply to personnel who have been assigned roles and responsibilities that ensure the safety and integrity of flight and ground hardware and software, and the general public. Assignments include, but are not limited to, assembly/integration/test, launch preparation, launch countdown, pre-flight planning and product development, training of operations personnel, integrated space vehicle and subsystem performance analysis, mission execution and operations support.. Training for operations personnel should include, at a minimum:
a. Instruction on and execution of all nominal and off-nominal operations, joint operations, and emergency procedures relevant to their roles and responsibilities.
b. In-depth knowledge of all applicable flight and ground systems, data monitoring and analysis tools, and procedures that are primary to their assigned roles, responsibilities, and tasks.
c. General knowledge of additional flight systems, procedures, processes, and tools utilized in, assembly/integration/test, launch, and missionoperations that are not directly covered by, but may influence or affect, their assigned roles, responsibilities, and tasks.
d. General knowledge of additional ground hardware systems, procedures, processes and tools utilized in, assembly/integration/test, launch, and missionoperations that are not directly covered by, but may influence or affect their assigned roles, responsibilities, and tasks.
e. Failure recognition and response.
f. General knowledge of standard operations common to all missions (including integrated space vehicle(s), facility(s), and personnel interactions).
g. Communication skills and protocol with other operations personnel, flight crew, and external organizations, if applicable.
h. Simulation or supervised on-the-job training of critical procedures and events, if applicable.
i. Proper physical and medical certifications for participants in hazardous and contingency operations.
5.2 Operations Training Standards Assessment
NASA will review the training plans the Commercial Provider will use to certify safety critical and mission critical operational positions, including the medical standards which are required for those positions. NASA will also review the Commercial Provider’s plans for certifying student lessons, conducting those lessons, setting evaluation standards needed for demonstrating student progression/mastery, and evaluating resulting student performance. NASA personnel will observeoperations personnel lessons to ensure that those lessons meet the standards above. NASA will also review the Contractorsplans for certifying and conducting ground processing mission critical and safety critical personnel lessons and the training plans that the Contractorswill use to certify those personnel for ground processing operations. NASA will also observe training exercises such as simulations to evaluate the adequacy of the Contractors training. NASA will also audit training and certification records to ensure personnel performing tasks have the appropriate certifications.
ground processing, and pre-flight planning among flight crew and operations personnel throughout the life-cycle of the USDV. The protocol should define methods and oral standards by which the communication among USDV elements will occur.
b. External communication- Establish plans for communicating with external entities, such as NASA Program Management, Range Authority, FAA, external customers, STRATCOM,and others as appropriate.
c. Joint operations- For joint operations with cooperative spacecraft or ground stations, the Commercial Provider should develop plans for coordinating or participating in communications among all participants. Some cooperative spacecraft, such as the ISS, or ground stations, such as Mission Control Center - Houston (MCC-H) and ground-based communications and tracking stations, already utilize well-established communication protocols. The Commercial Provider should adhere to established protocols and must be able to perform joint operations in a coherent, integrated, and effective manner.
6.1.1 Communications Plans Assessments
NASA will review the Commercial Provider’s documented communications plans and standards. These plans will be assessed for consistent use of the communication protocol across all phases of ground processing and mission.
6.2 Operations Management Plans
An operations management structure should be developed for the USDV. This structure should include a definition of the authority and roles/responsibilities of all involved parties during the mission, launch countdown through the final de-orbit burn. These authority definitions should clearly state when decision-making authority is delegated to the mission operations team and when decisions must be approved by the management team. See CCT-PLN-1100 and CCT-PLN-1200 for information regarding the Mission Management Team (MMT). For example, the mission management team may make a formal Go/No-go decision to proceed with the rendezvous after spacecraft launch and checkout but may delegate the Go/No-go decision for final approach to the mission operations team. The management structure should be documented and should:
a. Assume responsibility for all significant management decisions involving USDV operations, including proceeding with a major test or granting authority to proceed to the next mission phase (e.g., Go/No-go for launch, docking, etc.) and state when such authority is delegated to others.
b. Manage and coordinate the response to an anomaly, contingency event, or emergency.
c. Manage the process for making an informed decision on acceptance of increased risk when departing from previously agreed-to operational controls, operational plans or integrated space vehicle limits.
6.2.1 Operations Management Plan Assessment
NASA will review the Commercial Provider’s Operations Management Plan.
6.3 Real-Time Analyses
Analyses will be performed during mission execution to evaluate actual ascent and on-orbit spacecraft performance against pre-flight analysis products (i.e., trajectory, mission design, consumables, and resources utilization predictions). In addition, analysis may be required in certain off-nominal situations that were not envisioned before flight. These planned or unplanned analyses may require the support of specialized personnel who are not otherwise designated as operations support team. There should be plans in place to ensure the appropriate personnel are available to be contacted by the operations team to support planned or unplanned real-time analyses within the needed timeframe. The necessary computational, test and analysis equipment and facilities must also be available to support real-time analysis.
Detailed spacecraft design data should also be readily available to operations personnel to assist in troubleshooting and resolving off-nominal situations and understanding spacecraft behavior. This data should be up-to-date and contain information about any late changes made to the spacecraft hardware or software.
Flight test objectives require that certain objectives be analyzed and confirmed successful prior to proceeding with other test flight objectives on the same mission, a plan should be developed which describes what real-time analysis will be required to verify objectives are complete before proceeding with addition flight test events. Such a plan for any test flights that include ISS as a destination is called out in JSC-35089, Visiting Vehicle Operations Document.
6.3.1 Real-Time Analysis Plan Assessment
NASA will review the Commercial Provider’s plans to have real-time analyses performed with personnel available during the mission execution. NASA will inspect the capability for operations personnel to readily access design data including as-flown hardware and software data.
6.4 Contingency Action Plan
A contingency action plan contains provisions for immediate protection/recovery of operations personnel in the event of a mishap, emergency, natural disaster, or act of terrorism. The plan should provide notifications and coordinated interactions with other NASA or external Agency/Center Mishap Preparedness and Contingency Plans, as appropriate (for example, in the case of a launch using KSC or Eastern Range facilities).
At a minimum, the contingency action plan should:
a. Include provisions to minimize losses and control public and environmental hazards, as well as for the immediate embargo of operations personnel, data, telemetry, and recovered hardware to ensure integrity of mishap information for coordinating an immediate mishap response.
b. Identify the responsibilities of internal parties, the external organizations that must be notified, and any existing agreements with external entities for mishap response (such as NASA, SAR team, State Department, DOD, Intergovernmental Agreements, etc.).
6.4.1 Contingency Action Plan
NASA will review the contingency action plan.
7.0 Anomaly and Lessons Learned Tracking and Resolution
7.1 Anomaly Tracking and Resolution
A closed-loop anomaly tracking and resolution process will be developed for ground processing and flight operations that identifies and resolves any hardware or software performance characteristic that is or may be inconsistent with operational or design expectations. These anomalies can include, but are not limited to, ground hardware or integrated space vehicle problems, operations issues, non-conformances, deficiencies, in flight anomalies, and ‘process escapes.’
The assembly/integration/test launch preparation, and mission phases of ground processing should include an anomaly tracking and resolution process that identifies how anomalies are reported, tracked, investigated, and resolved. This process should address the following:
a. Documentation of conditions detected during testing or operations that do not fall within the listed acceptance or rejection criteria of the procedure being performed.
b. Identify anomalies initiated on GSE or facilities that directly interface with flight hardware.
c. Identify if non-conformance is a result of a faulty part or unexpected part failure.
d. Any anomaly resolution that includes a hardware design change.
e. Include an effectivity and rationale of acceptance for any anomaly that is not fully resolved through retest or replacement.
f. Impacts to Ground Processing and Operational Constraints – Any impacts to on-going or upcoming operations, including constraints that have been or need to be established to protect the integrated space vehicle systems, ground hardware, or software, as a result of the anomaly will be documented. The establishment of temporary placards or constraints should be documented.
g. Anomaly report history should be readily available to operations personnel in order to assist with training and allow them to understand if an anomaly on a spacecraft has been previously seen and what response was taken during that time.
h. Resolution process should include incorporation of process improvements, lessons learned, and replacement or retest of failed hardware/software prior to closure.
i. Any long-term impacts to hazard analysis (new causes, changes to controls or verifications, etc.)
need to be reported back to the hazard analysis authors for hazard analysis impact evaluation, updates and safety community approval.
During the launch and mission phases, anomaly tracking and resolution process should identify how anomalies are reported, tracked, investigated, and resolved. This process should address the following:
a. Immediate response – Through established LCC, flight rules, training, procedures or other plan(s), the process should provide documented guidance for an immediate response required from operations personnel, or automated software to maintain the integrated space vehicle and related ground hardware in a safe state, if possible. This response will account for:
1) Short-term impacts to the USDV hardware, software and operations personnel.
2) Short-term corrective actions to resolve and/or mitigate the impacts associated with the anomaly.
3) Measures for preventing or minimizing recurrence of the anomaly.
4) Any other actions or controls required for safety or mission assurance.
b. Long-term recovery actions required – The process will provide guidance to determine and document whether any actions, beyond those already taken by the flight crew, operations personnel, or automated software, are required to reduce the risk to the USDV or to restore systems to nominal or degraded functionality. The long-term action may involve recommended hardware/software changes for future flights to correct the anomaly.
c. Root cause – The process should determine the root or probable cause(s) of an anomaly in order to determine if any future changes to design or operations are required.
d. Safety hazards and risks – The process will document the current and potential safety hazards and risks associated with the anomaly and any recovery actions already taken or being considered.
e. Impacts to mission operations and operational constraints – Any impacts to on-going or upcoming operations, including constraints that have been or need to be established to protect the mission,integrated space vehicle systems, hardware, or software, as a result of the anomaly will be documented. The establishment of temporary placards or constraints should be documented.
f. Anomaly report history should be readily available to operations personnel in order to assist with training and allow them to understand if an anomaly on a spacecraft has been previously seen and what response was taken during that time.
7.1.1 Anomaly Tracking Process Assessment
NASA will review the Commercial Provider’s anomaly resolution and tracking processes. NASA will also observe simulations and operations to ensure anomaly response and tracking are exercised per Commercial Provider’s processes.
Appendix B: Definitions
TBR
Term Definition
File details come from the government source that posted it. Updated .