SSP 50175-RevF ISS Risk Management Plan.pdf

PDF 2 MB Posted

Attached to
Research, Engineering, and Mission Integration Services 2 (REMIS2) Technical Library Federal contract opportunity
Solicitation number
80JSC023REMIS2TL
Issued by
National Aeronautics and Space Administration Johnson Space Center

View the file

Other files for this federal contract opportunity

Other files attached to Research, Engineering, and Mission Integration Services 2 (REMIS2) Technical Library, newest first.
File Type Posted
SSP 50200-10-Baseline-DCN 009-Collated Master STATION PROGRAM IMPLEMENTATION PLAN Sustaining Engineering.pdf PDF
PART IV JSC Work Instructions.zip ZIP file
PART V NASA Forms.zip ZIP file
PART VII TO Forecast and Examples.zip ZIP file
PART III JSC Forms.zip ZIP file
PART I ISS PROGRAM ORG CHARTS AND OVERVIEW.zip ZIP file
PART II JPDs and JPRs.zip ZIP file
PART VI.zip ZIP file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SSP 50175

Revision F

ISS Risk Management Plan

International Space Station Program

December 2017

National Aeronautics and Space Administration International Space Station Program Johnson Space Center Houston, Texas Contract No.: NNJ12GA46C

REVISION AND HISTORY PAGE

REV. DESCRIPTION PUB.

DATE

- Initial Release (Reference per BSCR 1.1.5, EFF. 07-05-95) 11-20-95

A Revision A (Reference per SSCD 006649, EFF. 05-29-02) 08-28-02

B Revision B (Reference per SSCD 009707, EFF. 08-02-06) 08-10-06

C Revision C (Reference per SSCD 011839, EFF. 11-03-09) 11-09-09

D Revision D (Reference per SSCD 013635, EFF. 08-27-13) 09-04-13

E Revision E (Reference per SSCD 015209, EFF. 10-11-15) 10-14-15

F Revision F (Reference per SSCD 15756, EFF. 01-26-18)

Program Release 01-29-18 i

PREFACE

ISS RISK MANAGEMENT PLAN

The contents of SSP 50175, ISS Risk Management Plan, apply to National Aeronautics and Space Administration (NASA) and its contractors. This document is developed and maintained by the Safety and Mission Assurance Office. The initial baseline release is under the control of the Space Station Program Control Board (SSPCB) and any changes or revisions will be approved by the International Space Station (ISS) Program Manager.

See Directive Approval 01-26-18 Kirk A. Shireman Manager, International Space Station Program National Aeronautics and Space Administration

Date ii

INTERNATIONAL SPACE STATION PROGRAM

ISS RISK MANAGEMENT PLAN

CONCURRENCE

DECEMBER 2017

iii

TABLE OF CONTENTS

PARAGRAPH PAGE

1.0 INTRODUCTION ................................................................................................................... 1-1

1.1 PURPOSE ............................................................................................................................. 1-1

1.2 SCOPE .................................................................................................................................. 1-1

1.3 PRECEDENCE ...................................................................................................................... 1-1

1.4 DELEGATION OF AUTHORITY ............................................................................................ 1-2

1.5 RESOURCES AND SCHEDULES ........................................................................................ 1-2

1.6 ASSUMPTIONS, CONSTRAINTS, AND POLICIES .............................................................. 1-2

1.7 SUCCESS CRITERIA ........................................................................................................... 1-2

2.0 DOCUMENTS ....................................................................................................................... 2-1

2.1 APPLICABLE DOCUMENTS................................................................................................. 2-1

2.2 REFERENCE DOCUMENTS ................................................................................................ 2-1

2.3 RISK MANAGEMENT DOCUMENT TREE ........................................................................... 2-2

3.0 OVERVIEW OF ISS RISK MANAGEMENT PROCESS ........................................................ 3-1

3.1 CONTINUOUS RISK MANAGEMENT PARADIGM .............................................................. 3-2

3.2 RISK-INFORMED DECISION MAKING PROCESS .............................................................. 3-3

3.2.1 RISK ASSESSMENT FOR MAJOR CHANGES TO ISS BASELINE ..................................... 3-4

3.2.2 RIDM AND CRM INTERFACE .............................................................................................. 3-5

3.3 PROBABILISTIC RISK ASSESSMENT ................................................................................. 3-6

4.0 ISS PROGRAM CONTINUOUS RISK MANAGEMENT PROCESS ...................................... 4-1

4.1 ISS PROGRAM ORGANIZATION ......................................................................................... 4-1

4.2 ISS PROGRAM RISK MANAGEMENT PROCESS OVERVIEW ........................................... 4-1

4.2.1 CONTINUOUS RISK MANAGEMENT PROCESS OVERVIEW ............................................ 4-3

4.2.1.1 IDENTIFICATION OF RISKS ................................................................................................ 4-4

4.2.1.2 ANALYSIS OF RISKS ........................................................................................................... 4-4

4.2.1.3 PLANNING FOR MITIGATION OF RISKS ............................................................................ 4-5

4.2.1.4 TRACKING RISKS ................................................................................................................ 4-6

4.2.1.5 CONTROL OF RISKS ........................................................................................................... 4-6

4.2.1.6 COMMUNICATION AND DOCUMENTATION OF RISKS ..................................................... 4-7

4.2.2 ISS RISK MANAGEMENT PROCESS DETAILS .................................................................. 4-8

4.3 PROGRAM RISK ADVISORY BOARD OVERVIEW ............................................................. 4-11

4.3.1 DISSENTING OPINIONS ...................................................................................................... 4-16

4.3.2 PRAB FOLLOW-UP .............................................................................................................. 4-16

4.3.3 TOP PROGRAM RISK MATRIX ............................................................................................ 4-16

4.4 CERTIFICATION OF FLIGHT READINESS (COFR) OVERVIEW ........................................ 4-16

4.4.1 FLIGHT/STAGE EFFECTIVITY DETERMINATION .............................................................. 4-17

4.4.2 MANAGING ORGANIZATION RESPONSIBILITIES ............................................................. 4-17

4.4.3 INDETERMINATE FLIGHT/STAGE APPLICABILITY RISKS ................................................ 4-18

4.5 RISK COMMUNICATION ...................................................................................................... 4-20

4.6 RISK COORDINATION ......................................................................................................... 4-20

4.7 RISK MANAGEMENT ROLES AND RESPONSIBILITIES .................................................... 4-20

4.8 PROGRAM RISK MANAGEMENT TOOLS ........................................................................... 4-25 iv

4.8.1 ISS RISK DATABASE ........................................................................................................... 4-25

4.9 ISS RISK MANAGEMENT SCORECARD ............................................................................. 4-26

4.9.1 LIKELIHOOD DEFINITIONS ................................................................................................. 4-26

4.9.2 RISK CONSEQUENCE SEVERITY DEFINITIONS ............................................................... 4-27

4.10 METRICS .............................................................................................................................. 4-27

5.0 ISS RISK-INFORMED DECISION MAKING PROCESS ....................................................... 5-1

5.1 IDENTIFICATION OF ALTERNATIVES ................................................................................ 5-1

5.2 RISK ANALYSIS OF DECISION ALTERNATIVES ................................................................ 5-2

5.2.1 RISK ASSESSMENT PROCESS FOR CHANGES TO ISS BASELINE ................................ 5-2

5.3 RISK-INFORMED ALTERNATIVE SELECTION ................................................................... 5-2

6.0 PROBABILISTIC RISK ASSESSMENT ................................................................................. 6-1

6.1 TYPES OF PRA ANALYSIS .................................................................................................. 6-1

7.0 CONTINUOUS IMPROVEMENT AND QUALITY MANAGEMENT ....................................... 7-1

8.0 ISS PROGRAM RISK MANAGEMENT TRAINING ............................................................... 8-1

9.0 DOCUMENTATION SECURITY ............................................................................................ 9-1

9.1 SECURITY OF THE ISS RISK MANAGEMENT DATABASE................................................ 9-1

10.0 RISK-BASED ACQUISITION PROCESS .............................................................................. 10-1

11.0 PROGRAM DESCOPE METHODOLOGY ............................................................................ 11-1

APPENDIX

A ACRONYMS AND ABBREVIATIONS ................................................................................... A-1 B GLOSSARY ........................................................................................................................... B-1 C OPEN WORK ........................................................................................................................ C-1 D ISS PROGRAM RISK SCORECARD .................................................................................... D-1

TABLE

4.7-1 ISS ROLES AND RESPONSIBILITIES (PAGE 1 OF 4) ........................................................ 4-21 4.7-1 ISS ROLES AND RESPONSIBILITIES (PAGE 2 OF 4) ........................................................ 4-22 4.7-1 ISS ROLES AND RESPONSIBILITIES (PAGE 3 OF 4) ........................................................ 4-23 4.7-1 ISS ROLES AND RESPONSIBILITIES (PAGE 4 OF 4) ........................................................ 4-24 4.8.1-1 ISS RISK DATABASE MANDATORY FIELDS ...................................................................... 4-26 4.10-1 ISS RISK DATABASE REPORTS ......................................................................................... 4-28 C-1 TO BE DETERMINED ITEMS ............................................................................................... C-1 C-2 TO BE RESOLVED ISSUES ................................................................................................. C-1

FIGURE

2.3-1 RISK MANAGEMENT DOCUMENT TREE ........................................................................... 2-2 3.0-1 FLOW OF REQUIREMENTS WITHIN NASA HIERARCHY .................................................. 3-2 3.1-1 CONTINUOUS RISK MANAGEMENT PARADIGM .............................................................. 3-3 3.2-1 RISK INFORMED DECISION MAKING PROCESS .............................................................. 3-4 3.2.2-1 CORRELATION BETWEEN RIDM AND CRM ...................................................................... 3-5 4.1-1 ISS PROGRAM ORGANIZATIONAL STRUCTURE .............................................................. 4-1 4.2-1 RISK MANAGEMENT COVERAGE ...................................................................................... 4-2 4.2.1-1 CRM PROCESS STEPS ....................................................................................................... 4-3 4.2.1.2-1 RISK MATRIX FOR RANKING .............................................................................................. 4-5 v

4.2.2-1 ISS RISK PROCESS FLOW.................................................................................................. 4-8 4.3-1 PRAB STRUCTURE .............................................................................................................. 4-12 4.3-2 PRAB PROCESS FLOW ....................................................................................................... 4-15 4.4-1 COFR PROCESS OF OPEN RISKS ..................................................................................... 4-19 4.8.1-1 ISS RISK DATABASE FEATURES ....................................................................................... 4-25 5.0-1 ISS RISK INFORMED DECISION MAKING PROCESS ....................................................... 5-1 6.0-1 PRA FLOW DIAGRAM .......................................................................................................... 6-1 D-1 ISS RISK MANAGEMENT SCORECARD (PAGE 1 OF 2) .................................................... D-1

1-1

1.0 INTRODUCTION

This plan defines the purpose, approaches, roles and responsibilities, processes, and tools used to manage risks in the International Space Station (ISS) Program. This plan provides a risk management framework for the ISS Program in order to achieve mission success throughout the life cycle of the Program. The framework established within this plan fosters proactive risk management through better use of risk information and then helps users to more effectively manage risks that affect baselined requirements.

This plan describes risk management activities that facilitate proactive, risk-informed decision-making. Risk management includes analysis of applicable risks and uncertainties, alternate risk mitigation paths, and development of appropriate risk mitigation strategies.

The ISS risk management approach is in accordance with NPR 7120.5, NASA Program and Project Management Processes and Requirements, and NPR 8000.4, Agency Risk Management Procedural Requirements.

1.1 PURPOSE

This risk management plan provides guidelines for, and documents, the risk management processes for the ISS Program. The ISS risk management plan describes:

A. How to use all available information (performance data, deterministic analysis, qualitative and quantitative risk analysis, etc.) to make better risk-informed decisions.

B. How to effectively manage risks relative to baselined requirements.

C. The policy and procedures that will be used to communicate and report risks vertically and horizontally across the ISS Program employing the Continuous Risk Management (CRM) paradigm.

D. Plan for risk management training.

E. Process for fostering Risk-Informed Decision Making (RIDM) by providing Risk

Assessments for significant changes to the ISS baseline.

F. Probabilistic Risk Assessment (PRA) techniques to quantify risk.

1.2 SCOPE

The risk management process described herein is applicable to, and will be implemented across, all organizations and activities that directly support the ISS Program. These include the ISS Program Offices and matrixed organizations.

1.3 PRECEDENCE

There is no ISS Program document that takes precedence over this Risk Management Plan.

1-2

1.4 DELEGATION OF AUTHORITY

This document is approved by, and is subject to, the Space Station Program Control Board (SSPCB) change control process. The Safety & Mission Assurance (S&MA)/Program Risk (PR) Office assigns a book manager for maintenance of this document.

1.5 RESOURCES AND SCHEDULES

The ISS risk management effort is allocated among the ISS elements and organizations. Each organization is responsible for providing resources required to support the activities defined in this plan. The organizational Points of Contact (POC) are funded by their owning organizations and are responsible for identifying any additional resource requirements to support risk management initiatives.

The ISS Safety and Mission Assurance Program Risk Office is responsible for the core ISS Program risk management and Probabilistic Risk Assessment (PRA) activities and associated budgets. Responsibilities include developing policies and monitoring implementation and managing the ISS risk management working group. In addition, the ISS Risk Manager consults with ISS Program organizations concerning key program risks, S&MA-proposed risks and negotiates with affected NASA organizations for needed support.

1.6 ASSUMPTIONS, CONSTRAINTS, AND POLICIES

Revisions to this plan will be implemented over time to meet the needs of a dynamic Program. Any revisions will be reviewed and approved by the Space Station Program Control Board (SSPCB). The ISS organizations will continue to have a significant role throughout the Program’s sustaining, operation, and utilization phases. It is recognized that the expertise required to address likelihood of risk occurrence, consequence of occurrence and possible mitigation strategies resides at the organization level with the individual team members. Therefore, success of ISS Program risk management is contingent upon the following: management direction and support to enforce policies and practices defined herein; organization-level support in the application of policies and practices defined herein; and sufficient resources to support the risk management processes with respect to personnel, database administration, training, and tool development.

1.7 SUCCESS CRITERIA

Objective evidence in the form of metrics will be used to demonstrate implementation of risk management in accordance with this plan. Metrics will be used to measure the effectiveness and health of the risk management process and trends in program risks.

The risk management process also will use qualitative and quantitative risk techniques to analyze and plan risk mitigation. Further, risk owners are required to specify success criteria for risk closure rationale and each mitigation step.

2-1

2.0 DOCUMENTS

2.1 APPLICABLE DOCUMENTS

The ISS risk management process was established and is implemented according to the requirements, processes, and procedures defined in the latest revisions of the documents below:

MD 1015 Risk Assessment Criteria and Procedures

NPR 1600.1 NASA Security Program Procedural Requirements

NPR 2190.1 NASA Export Control Plan

NPR 2810.1 Security of Information Technology

NPR 5100.4 NASA Federal Acquisition Regulation Supplement

NPR 7120.5 NASA Program and Project Management Processes and Requirements

NPR 8000.4 Agency Risk Management Procedural Requirements

NPR 8705.2 Human Rating Requirements for Space Flight Systems

NPR 8705.5 Probabilistic Risk Assessment Procedures for NASA Programs and Projects

NPR 8715.3 NASA Safety Manual

SSP 50108 ISS Program Certification of Flight Readiness Process Document

SSP 50200-01 Station Program Implementation Plan, Volume 1: Station Program Management Plan

2.2 REFERENCE DOCUMENTS

The following documents contain supplemental information to guide the user in the application of this document. These reference documents may or may not be specifically cited within the text of this document.

SP-2011-342 NASA Risk Management Handbook

2-2

2.3 RISK MANAGEMENT DOCUMENT TREE

FIGURE 2.3-1 RISK MANAGEMENT DOCUMENT TREE

3-1

3.0 OVERVIEW OF ISS RISK MANAGEMENT PROCESS

Risk Management is a systematic process to proactively identify, analyze, plan, track, control, communicate, and document risks in efforts to help management make risk-informed decisions that increase the likelihood of achieving program objectives.

The ISS Risk Management processes gather and communicate valuable information to help identify risks early and, when appropriate, to establish mitigation strategies to reduce the likelihood of and/or impact from the risks from being realized.

Decisions shall be made based on comprehensive data analysis and open communication within a common framework to facilitate the flow of information throughout the hierarchy of Program forums. The extent of technical analysis and evaluation should be commensurate with the risk consequences.

The Agency sets high-level strategic goals for the NASA projects and programs to accomplish, and establishes basic requirements based on the scope and type of project or program. Each project or program will then define a lower-level, more detailed, set of objectives and requirements to achieve the goals specific to its purpose and vision.

Through the decision making process, the ISS Program determines its objectives, requirements, and how the performance of the baselined requirements shall be measured.

Products of the decision making process are the baselined requirements for the ISS Program. These requirements specifically state how the hardware, software, work force, processes and other procedures shall be executed and perform once developed to specifications. Requirements are determined at the appropriate level of management and flow from a top down approach as illustrated in Figure 3.0-1, Flow Of Requirements Within NASA Hierarchy.

Measuring the performance of program objectives and requirements fall within four basic categories when assessing risk:

• Technical (mission success/operational performance).

• Safety (crew and/or vehicle).

• Cost (not initially allocated).

• Schedule (delays to program milestones).

3-2

FIGURE 3.0-1 FLOW OF REQUIREMENTS WITHIN NASA HIERARCHY

ISS Risk Management is achieved through the implementation of three main processes:

1. The Continuous Risk Management (CRM) paradigm (see Figure 3.1-1, Continuous Risk Management Paradigm).

2. The RIDM process.

3. Quantitative or Probabilistic Risk Assessment (PRA) techniques.

These processes are described in further detail in sub-sections 3.1 thru 3.3.

3.1 CONTINUOUS RISK MANAGEMENT PARADIGM

One of the foundations of the ISS risk management is the Continuous Risk Management (CRM) Paradigm. The purpose of CRM is to identify risks early so that appropriate mitigation plans may be developed and implemented to reduce the consequences of the risk and/or the likelihood that the risk will be realized. The CRM process provides systematic methods for identifying, analyzing, planning, tracking, controlling, communicating, and documenting risks on a continuous basis and is utilized throughout the life of the program. The successful implementation of the CRM approach allows for the following:

A. Open communication at and among all organizational levels.

B. Continuous monitoring of areas that may potentially cause future problems.

3-3

C. Continuous assessment of risks and the strategies to mitigate those risks.

The ISS Program implements the CRM strategy to manage risk as follows:

A. Embed risk management processes into day-to-day activities to identify and help manage Program risk.

B. Delegate risk management responsibility to the lowest possible organization with the allocated resources to mitigate the risk.

C. Dedicate a Program Risk Management organization to lead program-level risk management activities, facilitate the risk management processes, and provide analytical support and tools including PRAs, ISS risk management process training and other risk management assistance to the ISS organizations.

D. Provide the necessary resources to analyze and address all risks to the ISS.

E. Mitigate risks to reduce the likelihood and/or consequence.

F. Include the cost and schedule tracking for risks identified within the risk system.

FIGURE 3.1-1 CONTINUOUS RISK MANAGEMENT PARADIGM

3.2 RISK-INFORMED DECISION MAKING PROCESS

The RIDM process is used to inform management of the potential risks associated with various decision alternatives, or solution paths. RIDM is typically utilized when decisions involve the baselining or changing of program requirements. As illustrated in Figure 3.2-1, Risk Informed Decision Making Process, RIDM involves three main steps and are described in more detail in Section 5.0.

A. Identification of alternatives.

B. Risk analysis of alternatives.

C. Risk-informed alternative selection.

3-4

FIGURE 3.2-1 RISK INFORMED DECISION MAKING PROCESS

3.2.1 RISK ASSESSMENT FOR MAJOR CHANGES TO ISS BASELINE

Risk Assessments should be a routine part of the decision-making process. A Risk Assessment is a tool to identify, analyze, summarize, and communicate all applicable risks associated with plans that have various solution paths or decision alternatives. It provides a means to assign a quantitative or qualitative value of risk related to those decision alternatives. The value of risk is measured in likelihood and consequence.

Risk Assessments provide all of the following:

A. Help in providing more concise and effective communication.

B. Aid or improvement to decision-making.

C. More effective and efficient use of ISS Program resources.

D. An increase in the probability of meeting Program goals and objectives.

E. Ensuring safety is accounted for in all decision alternatives.

F. Documentation of all considered options for the historical record - presentation of decision options with a Risk Assessment analysis automatically adds it to the permanent record.

G. Adherence to the risk-informed decision-making model adopted across the NASA agency.

Refer to MD 1015, Risk Assessment Criteria and Procedures, for more detailed information on Risk Assessments.

3-5

3.2.2 RIDM AND CRM INTERFACE

RIDM and CRM are integrated into a coherent risk management framework within each organizational unit to:

A. Foster proactive risk management throughout the life of the Program.

B. Inform decision making through better use of risk information.

C. More effectively manage risks by focusing the CRM process on the baselined requirements emerging from the RIDM process.

RIDM is applied when deciding how to meet program objectives that usually have difference solution paths or “decision alternatives”. CRM is applied continuously to manage the risks that result from the alternative selected and to identifying other potential shortfalls not initially identified during the RIDM process.

As illustrated in Figure 3.2.2-1, Correlation Between RIDM And CRM, RIDM feeds into CRM when an alternative is selected and the risks associated with that specific alternative are transferred to CRM to be actively managed and mitigated. CRM feeds back into RIDM when the mitigation of a risk requires changes to the current baseline.

As described in Section 3.0, both RIDM and CRM facilitate the flow of risk information throughout the hierarchy of the Program forums, control boards and reviews.

FIGURE 3.2.2-1 CORRELATION BETWEEN RIDM AND CRM

3-6

3.3 PROBABILISTIC RISK ASSESSMENT

The other foundational component of ISS Risk Management is the Probabilistic Risk Assessment, or PRA, within the decision-making process. PRA is a systematic and comprehensive methodology that quantitatively evaluates risks associated with the ISS.

A PRA usually answers three basic questions:

1. What can go wrong, or what are the initiators or initiating events (undesirable starting events) that lead to adverse consequence(s)?

2. What and how severe are the negative or adverse consequences as a result of the occurrence of the initiator?

3. How likely to occur are these undesirable consequences, or what are their probabilities or frequencies?

PRA models are typically built to simulate a sequence of events leading to negative end states - Loss of Crew (LOC), Evacuation (Evac.), and Loss of Crew and Vehicle (LOCV). These entities are built using a combination of Event Trees and Fault Trees that start with initiators and basic events. PRA studies require special analysis tools like Human Reliability Analysis (HRA) and Common-Cause-Failure (CCF) analysis. HRA deals with methods for modeling human error while CCF deals with methods for evaluating the effect of inter-system and intra-system dependencies which tend to cause simultaneous failures and thus significant increases in overall risk. PRA studies are performed all phases of the life cycle.

4-1

4.0 ISS PROGRAM CONTINUOUS RISK MANAGEMENT PROCESS

The structured framework of the ISS risk management process allows the ISS community to identify, communicate and mitigate risks, support the Certification of Flight Readiness (CoFR) process, and support the Program Risk Advisory Board (PRAB) on a continuing basis. This section provides details on the ISS risk management process and key steps for implementing risk management.

4.1 ISS PROGRAM ORGANIZATION

Figure 4.1-1, ISS Program Organizational Structure, depicts the organizations that report to the ISS Program Manager. The latest ISS organization may also be found at:

https://iss-www.jsc.nasa.gov/ss/issapt/pmo/qorgchts/orgmain.html.

FIGURE 4.1-1 ISS PROGRAM ORGANIZATIONAL STRUCTURE

4.2 ISS PROGRAM RISK MANAGEMENT PROCESS OVERVIEW

The ISS risk management process will promote the use of risk management techniques and tools in making decisions. Risk management is a continuous process that:

• Identifies risks;

• Analyzes their impact in terms of likelihood and consequence;

• Develops and executes risk mitigation plans;

4-2

• Supports informed, timely, and effective decisions to control risks and mitigation plans;

• Assures that risk information is documented and communicated to appropriate ISS personnel.

Specifically, the risk process should assess continually what could go wrong (risks), determine which risks are important to deal with, implement strategies to deal with those risks, and measure effectiveness of the implemented strategies. The process considers risks related to ISS Program technical, safety, cost, and schedule objectives on a continuous basis using qualitative methods to quickly analyze and communicate risks to Program Management. Quantitative risk analysis methods (such as PRAs) are also used when possible, though these assessments generally take more time to develop than qualitative assessments.

The Program Risk Advisory Board (PRAB), in Figure 4.3-1, PRAB Structure, is the governing forum utilized to characterize and communicate risks throughout the ISS Program and ensure that:

1. The potential likelihood and consequence of each risk is understood,

2. Risks are accurately communicated to stakeholders, and

3. Appropriate visibility and resources are applied.

The PRAB is generally convened on an eight week cycle. This system is the primary process for elevating risks or potential problems to Program Management’s attention consistent with existing organizational structures. The risk process is hierarchal in nature (information flows up and resources and direction flow down) and risks are escalated when resources and/or communication of the risk is required. Risk management should permeate all facets of project management, as shown in Figure 4.2-1, Risk Management Coverage.

FIGURE 4.2-1 RISK MANAGEMENT COVERAGE

4-3

4.2.1 CONTINUOUS RISK MANAGEMENT PROCESS OVERVIEW

All ISS program management operations are responsible for performing the following functions (the CRM Paradigm). Fundamental CRM process steps are described in the following sub-sections and are summarized in Figure 4.2.1-1, CRM Process Steps.

FIGURE 4.2.1-1 CRM PROCESS STEPS

4-4

4.2.1.1 IDENTIFICATION OF RISKS

Risk identification is an organized, thorough approach for seeking out risks early enough to effectively manage them before they become problems. Care should be taken to distinguish between problems that have already occurred versus risks which are potential problems that have some probability of occurrence. The first step in the risk management process is to propose a concern and the managing organization determines if the concern should be elevated to a risk or watch item. The risk statement should be written clearly and concisely and should capture the circumstances, contributing factors, and issues related to the risk. It should provide the what, how, when, where, and why of the risk condition. The risk statement must clearly identify a condition and a consequence if the risk were to occur. A well-defined risk statement is critical to adequately understand and score the risk.

There are many useful sources of information to assist in risk identification. These sources may include but are not limited to the following:

1. Issues discussed at boards and panels.

2. Probabilistic Risk Assessments (see Section 6.0).

3. Trade Studies.

4. Event Trees.

5. Fault Trees.

6. Hazard Analysis.

7. Failure Modes and Effects Analysis.

8. Adverse Trends.

9. Historical data/experience.

10. Audits and surveillance.

11. Lessons learned.

12. Test Data.

13. Expert Opinion.

14. Independent Assessments.

4.2.1.2 ANALYSIS OF RISKS

Once a concern has been defined, it needs to be examined in detail to determine the likelihood of the risk being realized and the severity of consequences or impact to the Program or Project. A qualitative assessment is the method of assessment based on the best judgment of the assigned risk owner, team or organization initiating the risk.

The definitions used as guidelines in determining likelihood and consequence are in the risk scorecard shown in Appendix D. In the criteria for consequence, the risk level selected (1-5) is the rating which is the highest within the sub-criteria for cost, schedule, technical, and safety. When there is insufficient knowledge to reasonably assess the L x C, the estimate should be conservative (tending towards the worst case). Once the L

4-5 x C has been determined, the level of risk is plotted on the risk matrix using the L x C, see Figure 4.2.1.2-1, Risk Matrix For Ranking. This matrix is used by the Program Manager to display and communicate the Top Program Risks (TPRs) and Managing Organizations to display and communicate their Top Organizational Risks (TORs). The risk type is then chosen (i.e., keep as Concern or change to Watch Item or to Risk).

Each risk assessed is documented in the risk database. Not all risks require the same level of analysis and formal documentation. For example, watch items may not have enough mature data to define mitigation plans therefore they do not require mitigation plans. Analysis also includes the grouping of risks based on shared characteristics or identified relationships among the risks. Grouping or classifying risks contributes to the efficiency of sorting through large amounts of data, and allows for prioritizing of risks.

FIGURE 4.2.1.2-1 RISK MATRIX FOR RANKING

4.2.1.3 PLANNING FOR MITIGATION OF RISKS

Once the risks have been identified and a cause determined, the next step is risk planning. Risk planning is the process of deciding what, if anything should be done with a risk and implementing those decisions. Mitigations plans need to be detailed enough to provide a basis for activities. Managing Organizations, along with the risk owner, have the responsibility, accountability, and authority for assuring development and management of their risk mitigation plans. These plans are documented in the risk database. While risk owners are encouraged to document mitigation plans/tasks for their watch items and concerns, only risks require mitigation plans. Key elements should be addressed by a mitigation plan to include the mitigation strategy, including goals/objectives of the plan, success/closure criteria, personnel assignments and responsibilities, related risks (if any), due dates, specific actions, cost of the strategy actions, and a fallback plan. Some tips for developing mitigation plans:

1. Identify specific, implementable actions which will preempt problems.

2. Create the desired future state.

3. Do not lose sight of the end product when developing mitigation plans and do not compromise the end product while trying to fix the smaller details.

1 2 3 4 5

CONSEQUENCE

L I K E L I H O O D

4-6

Tradeoffs are usually required between the options that either reduce the likelihood of occurrence or the severity of the consequences or both. These tradeoffs may consider the cost of the risk consequence versus the cost in dollars and time to eliminate or mitigate the risk. To some degree, the approach chosen is also dependent on where it falls on the risk matrix.

Risks that have severe consequences and a high likelihood of occurring (red or higher), require major changes in plans or processes. These changes should be reflected in the mitigation plans. Risks that have an L x C within the yellow or medium range are more of a challenge since the consequences are not as compelling. Risks that have a low L x C (green) need to be monitored and tracked to closure by the risk owner and Managing Organization to assure there are no changes in the L x C.

After available options are developed and tradeoffs considered, the managing organization in coordination with the risk owner, selects the best option, i.e., the optimum combination of reduction in risk to acceptable levels and the resources required. Once the decision has been finalized, the option selected can be formed into an overall plan. For example, technical risk mitigation would require the basic design, process, or approach to be modified (i.e., workarounds) to achieve acceptable performance level. Schedule risks may require the manipulation of tasks to reduce the risk. Caution must be exercised when trying to reduce schedule risks in that new risks are not introduced.

All risk mitigation plans are documented in the risk database. The managing organization, along with the risk owner, is responsible for tracking individual steps of the mitigation plan to closure. After the mitigation plan is established, the L x C should be reassessed based upon how the risk will be avoided, eliminated, or reduced as a result of implementing the mitigation plan. This resulting L x C is documented in the ISS risk database.

4.2.1.4 TRACKING RISKS

During the tracking step of the risk management process, the managing organizations continuously measure the progress of the risk management efforts. Tracking involves collecting, updating, compiling, analyzing, and organizing risk data and reporting risk trends to determine whether particular risks are decreasing, staying the same, or increasing over time. Tracking focuses on risks identified for mitigation, although all risks, including accepted risks and watch items, should also be tracked to ensure that conditions or assumptions have not changed to the point that re-evaluation is necessary. Risk owners are responsible for tracking the individual steps of each risk’s mitigation plan through closure. The risk owner is responsible for providing routine status reports on risk mitigation plans to their management. In addition, risk owners should update and review their risks on a regular basis (at least every 30 days).

4.2.1.5 CONTROL OF RISKS

During the control step of the risk management process, the managing organizations review the summary for the risks and watch items and determine what to do with them.

4-7

The objective at this phase is to make informed, timely, and effective decisions regarding risks and their mitigation plans. The general process involves the following:

1. Analyze - Use tracking data to look for trends, deviations, and anomalies.

2. Decide - Use tracking data to determine how to proceed:

a. Replan - A new or modified plan is required when analysis shows that the mitigation plan is not working or an unexpected adverse trend is discovered.

b. Close the risk - A closed risk is one that no longer exists and further mitigation is deemed unnecessary. This occurs when:

1) the L x C is reduced to within the “green” on the ISS Scorecard,

2) the risk no longer exists, or,

3) the risk has become a problem and tracked as such.

The risk POC is responsible for notifying the PRAB which non-TPR risks have been closed. Approval for closure of TPRs is requested at the PRAB.

Closure rationale is documented in the risk database.

c. Accept the risk - Risk acceptance is a deliberate decision to acknowledge a known risk. Analysis/assessment should show that it is not feasible or desirable to fully mitigate the risk. A recovery plan should be identified to respond to the consequence of an accepted risk should that risk manifest itself as an undesired event. Periodic reviews will be conducted to ensure rationale is still appropriate and controls are in place. These risks can be re-opened or closed.

d. Continue tracking and executing the current plan - No further action is taken when analysis of the risk data indicates all is going as expected and the Managing Organization continues to track the risk and mitigation plan.

3. Execute - Implement both the decision made about a risk and mitigation plan as well as to ensure that all decisions are appropriately documented in the risk database.

4.2.1.6 COMMUNICATION AND DOCUMENTATION OF RISKS

Provide information and feedback to the Program on risk activities, risk status, and new potential risks. The risk owner is responsible for ensuring management has visibility into risk activities and that they have all of the data needed to make risk informed decisions. All risk data is documented in the risk database.

4-8

4.2.2 ISS RISK MANAGEMENT PROCESS DETAILS

This section provides the overall details of the Risk Management process for the ISS program.

FIGURE 4.2.2-1 ISS RISK PROCESS FLOW

4-9

A. New risks initially will be classified as “concerns”. Concerns are identified through the normal course of business by Program participants and stakeholders.

B. A concern is brought to the managing organizations’ internal board or panel for elevation. If the concern is determined not to be a risk, then it is maintained as a concern in the ISS risk database or closed. Concerns are only visible to the managing organization.

C. As the risk information is matured then concerns may be elevated to a risk or watch item by the organizational managers/leads.

1. Risk - A future event with a negative consequence that has some probability of occurring. A risk poses a threat to the crew or vehicle safety, program cost, schedule, or major mission objective. An item whose resolution is unlikely without focused management attention. Risks can be escalated to TORs or TPRs with the appropriate management approval. TOR and sub risks can be closed by the managing organization. Only the Program Manager can accept risks for the Program and approve closure of TPRs.

2. Watch Item - An immature risk whose complete scope, impact, and consequence is undefined. A risk where existing conditions are not favourable for taking action and the potential for significant impact exists, but the probability is low. Watch items do not require mitigation plans unless requested by the ISS Program Manager or the managing organization. Watch items can be escalated to TORs or TPRs with the appropriate management approval. TOR and sub watch items can be closed by the managing organization. Only the Program Manager can accept risks for the Program and approve closure of TPRs.

D. Risks that have been identified and documented in the ISS risk database will be scored using the ISS risk matrix scorecard, which can be seen in Appendix D.

E. Risks will be assigned one of three statuses: open, closed, or accepted. The risk category is documented in the ISS risk database.

1. Open - A risk that has not been closed or accepted. Proactive efforts will be continued to prevent their occurrence or mitigate their consequence or both.

2. Closed - A risk that has been reduced to “green” on the ISS risk matrix scorecard and further mitigation activity is deemed unnecessary by the managing organization and effected stakeholders. Closed risks will not be actively mitigated or monitored. In addition, closure rationale is clearly documented in the ISS risk database.

3. Accepted - Risk reduction action is not being taken to eliminate or reduce this risk. Efforts to prevent or mitigate this risk are deemed unpractical. Controls and acceptance rationale have been defined to justify continuation without further preventive or mitigation action. In addition, acceptance rationale is clearly documented in the ISS risk database. Periodic reviews of accepted risks will be conducted once per year to ensure that acceptance rationale is still valid and controls remain in place. Accepted risks could potentially be re-opened or closed based on progress reviews. Risks, regardless of escalation, can only be

4-10 accepted by the Program Manager at the PRAB after Acceptance Rationale is reviewed at the SSPCB.

F. The managing organization is responsible for the overall management of their risks.

Specifically the managing organization will:

1. Implement mitigation actions and propose mitigations plans to the next higher level of management when additional resources are needed.

2. Track risks and mitigation plans as approved.

3. Ensure risk information is documented in the ISS risk database.

4. Conduct internal reviews of their risks.

5. Review risk metric data to identify any negative trends with the risk or in the process.

G. Risks are assigned to an owner by the managing organization and the owner will, with support from the managing organization:

1. Determine what process and type of analysis is available and required to mitigate the risk.

2. Determine the level of resources needed to conduct the analysis to mitigate the risk.

3. Develop a mitigation plan and coordinate resource needs with management.

4. Track the risk and report changes in status to management.

5. Coordinate risk data with affected organizations.

6. Enter the risk data into the ISS risk database.

H. The risk owner will coordinate cost data associated with mitigating the risk and document the cost data in the ISS risk database. Activities that are not funded but required are carried as risks to the Program (upon management approval) and the costs may be carried as threats to the Program reserves. The ISS Program Planning and Control Office will review risks and watch items with cost data to determine if the risk should be included on the Program’s Cost Threats List. The Cost Threat List is reviewed and briefed at the PRAB. All cost threats are assigned a likelihood of occurrence level. A level one is greater than 50% chance that the cost will occur, level two is a 50/50 chance, and level 3 is less than 50% chance of occurrence. In addition, the cost data documented in the risks is also used to support the budget process.

I. Risks (TOR and below) can be either closed internally within the managing organization or escalated to the next level of management.

J. Risks are escalated to the next level if:

1. Resources are needed to mitigate.

2. Decisions are needed by the next level of management.

3. Integration with other ISS organizations is needed.

4-11

4. The significance of the risk requires broader awareness throughout the Program. Risk escalation is accomplished by selecting one of three classifications:

a. Top Sub-organizational Risk (TSOR) - ISS projects may designate risks and watch items that they own as TSORs. TSORs are considered primary risks for the sub-organization and deemed to have the greatest significance to the sub-organization.

b. Top Organizational Risk (TOR) - ISS Program organizations may designate risks and watch items that they own as TORs. TORs are considered primary risks for the organization and deemed to have the greatest significance to the organization. TORs are briefed at the PRAB.

c. Top Program Risk (TPR) - TPRs are risks that require substantial Program resources to mitigate. TPRs are risk items that have been designated as such by the Program Manager at the PRAB and management of the risk is assigned to the appropriate ISS organization.

K. The managing organization continues the mitigation process for risks with monthly updates for all their risks and regular briefings of TORs and TPRs to the PRAB. The managing organization can close a risk (non-TPR) when all of the necessary mitigation has been accomplished and the likelihood and consequence have been reduced to the “green” level on the ISS Risk Scorecard.

L. Risks that have been escalated to a TPR can only be closed or accepted by the Program Manager, typically at the PRAB.

4.3 PROGRAM RISK ADVISORY BOARD OVERVIEW

The Program Risk Advisory Board (PRAB) is chaired by the ISS Program Manager and consists of representatives from each of the ISS organizations and support organizations, see Figure 4.3-1, PRAB Structure. The ISS risk process culminates into a PRAB which is the primary process for elevating risks or potential risks to program management attention. The PRAB convenes approximately every eight weeks, see Figure 4.3-2, PRAB Process Flow. The PRAB allows for:

A. Integrated assessment of significant risks to program success.

B. Communication of risks by raising the awareness and visibility of risks to potential program stakeholders.

C. Communication and review of cost threats to the Program reserves.

D. Identification of adverse trends in mitigation or newly identified threats that impact technical, cost, and schedule to the Program.

E. Decisions on ISS Program risks.

F. Allocate resources to assist in risk mitigation.

G. Identification and prioritization of TPRs.

4-12

H. Independent path for personnel to identify concerns that are not currently being addressed by the ISS Program organizations or current concerns owned by the Program whose resolution is deemed unsatisfactory (see Paragraph 4.3.1).

FIGURE 4.3-1 PRAB STRUCTURE

The PRAB is the controlling authority for risks being managed by the ISS organizations.

Prior to each PRAB each ISS organization and supporting organization will:

A. Conduct an internal review of their risks.

B. Review their risks and identify any potential new risks. This includes the review of cost threat data to ensure that the risk reflects the latest cost data.

C. Update risk information (status, mitigation, etc.) for all existing risks in the ISS risk database.

D. Analyze and define all new risks in the ISS risk database.

4-13

E. Identify risks that are being proposed as TPRs or TORs in the ISS risk database.

F. Participate in the PRAB and invite other personnel as necessary.

G. Identify risks that require the Program Manager’s assistance.

Questions to consider when reviewing risks are:

A. What is the technical basis of the risk assessment?

B. Does the risk information adequately convey the significance of the risk to potential

Program stakeholders?

C. Is the mitigation plan on schedule?

D. Are the tasks being completed within applicable constraints?

E. Has the risk likelihood or consequence changed?

F. Are adequate mitigation resources available?

G. Are additional measures required to manage risk?

H. Are contingency plans required in order to establish a fallback in the event that risk mitigation is unsuccessful?

Risks are reported at the PRAB utilizing the reports generated by the ISS risk database.

The following describes the roles and responsibilities of PRAB participants.

ISS Program Risk Manager presents:

A. Metrics on risk staleness, mitigation tardiness, mitigation accomplishment, and risk activity by organization.

B. The TPR Matrix from the previous PRAB.

C. TPR Mitigation Waterfall. The data illustrates the TPR mitigation tasks and the resulting L x C upon completion of those tasks.

D. Risk management accomplishments and future work.

E. Process improvement recommendations.

F. Special risk topics such as risks requiring integration…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .