FIGURE

126

At 7.7 months before launch, the Cargo Integration Review (CIR) occurs. This is a critical point in the mission definition and launch process. The customer participates in this review. All baseline re- quirements for flight design, flight and ground operations, and crew size are defined. The engineering requirements for a particu- lar mission are approved. The CIR essentially separates the design process and concept documentation from the actual Orbiter proc- essing, installation and certification of the hardware and software, and final crew training and engineering verification of the various systems on the Orbiter. Typically 10 to 20 percent of the mission- specific preparation work is accomplished by the time of the CIR, and after the CIR the process is driven by the Shuttle mission preparation milestones.

At L-3 months the flight operations review (FOR) takes place. This freeze point allows the customer to review all final flight oper- ations plans. At approximately the same time the launch site flow review (LSFR) takes place, at which the timing and flow of the Shuttle and its cargo through the Orbiter processing facility (OPF), the vehicle assembly building (VAB), and to the launch pad are all reviewed and baselined. No changes should occur after this point in time, but, of course, some do.

At L-2 weeks the Flight Readiness Review (FRR) takes place. Its purpose is to verify the-fact that for this mission the hardware and software are ready for flight. It is here that the final commitment to a specific launch date and time is made.

At the FOR typically 40 to 50 percent of the work of the produc- tion process has been accomplished. At the time of the Flight Read- iness Review, almost all of the work must have been accomplished because the Flight Readiness Review is not for the purpose of working out problems but merely to certify that problems have been resolved.

AS the targeted flight date approaches, conditions are continually reviewed and last minute changes are made as necessary through a series of meetngs and teleconferences.

This simplified description does not begin to reveal the details of the launch production process but study of the template should give some indication of its complexity. With over 50 percent of the work typically needing to be accomplished in the last three months before launch, and with typically 20 or more flights in work at any given time, it should be clear that last minute changes can be very disruptive and costly.

The developmental or non-operational status of the Shuttle also contributed to problems as the flight rate increased. Less time be- tween flights meant that results from one flight could not be incor- porated into the early planning for the next one. In other words, any change resulting from feedback from the previous flight was necessarily a last-minute change. Because of the developmental nature of the Shuttle system, such changes were to be expected. At 24 flights a year there would be about two weeks between flights. Allowing some time for flight data analysis, this would mean that results of the previous flight typically would not be available at the Flight Readiness Review. Indeed, the O-ring erosion results of flight 61-C were available only immediately before the 51-L launch.

127

The complex and lengthy mission planning process was under in- creasing pressure and was being strained to achieve the planned launch rate. Two activities that were compressed were training of the flight crew and training of the ground launch crew.

Training.-When training and other preparations is compressed, progam quality is likely to suffer, and errors become more likely. Given the situation with NASA's safety program-which the Rogers Commission described as "silent"-errors were less likely to be detected before harm could occur. Errors can be caused by per- sonnel taking shortcuts with respect to established procedures. Two examples are given in the Pre-Launch Activities Team report:

The most significant error encountered was during the launch countdown. While preparing for propellant loading, the LH2 Orbiter to ET disconnect Valve was opened by the console operator. He had erroneously failed to follow the required steps in the OMI. A follow-on error was made in that this occurrence was not properly documented. Since proper documentation was not present, a full assessment of the problem was not made prior to the launch of STS 51-L. Flight data from STS 51-L indicated the valve did perform satisfactorily. Another major error occurred when the integrity seals on the ET aft restraints were broken and not reported. It is believed that the seals were broken in error, but the break of integrity was not reported in accordance with es- tablished procedures. The underlying factors contributing to these errors were not determined during the processing reviews. O

These errors apparently had no adverse impact on the mission, but indicate a breakdown of the discipline so necessary for a proc- ess as complex as launching a Shuttle.

Shuttle crew training is an important part of mission prepara- tion. The crew of 51-L had training loads as high as 70, 63, 65, 59 and 58 hours in the several weeks before their launch. This was due to the fact that their training started some 3 weeks later than scheduled.

It must be noted that the crew also had 3 easy weeks during this period. During the weeks which included Thanksgiving, Christmas and New Year's they only trained 31,27 bid., p. 201. Rogers Commission Report, Volume 11, p. F-2. and 49 hours, respectively. No harmful effects of compressed Shuttle crew training have been documented but common sense indicates that the situation must have been less than optimal.

It will be recalled that the launch of flight 61-C, which immedi- ately preceded 51-L, was delayed several times. It was originally scheduled to launch on December 18th and eventually launched on January 6th. The Commission report describes how the launch date slips for 61-C became a scheduling factor for the training through integrated simulations for 51-L.lo6 Delay of 61-C launch pushed a bow wave of tests at the Kennedy Space Center which required 51- L prime crew and/or mission control center resources and thereby

105 Rogers Commission Report, Volume 11, p. 1-15 loe bid., p. 5-13, constrained the time at which integrated simulation training could be conducted. The 51-L training schedule was changed several times during the last weeks prior to launch due to launch slips of 61-C and the desire to suspend work between the Christmas and the New Year holidays. Eventually all 51-L training was accom- plished with some change of spacing between the simulations. If the originally planned spacing of simulation training was optimum, then the changed spacing probably was not.

128

It is not clear exactly why the 51-L crew was late in starting its training, because it should have started training before the delays of the 61-C launch began. What is clear is that the crew training is a serial effort which cannot occur until software is available to drive the simulation computers. O7 The necessary software cannot be written until the specific flight configuration of the mission has been designed. This is a situation in which each event must wait on the completion of the previous one. In the case of 51-L there were delays and development of some software elements. But it is not clear that the development of these elements was in fact started on time. It is clear that there was considerable remanifesting of 51-L, for example during most of 1984 the Cargo Integration Review was scheduled to occur on September 4 but due to remanifesting this slipped and the CIR eventually occurred on J u n e 18, 1985. In April 1985 a major change was made when the Orbiter assigned to the mission was changed (from OV-104 to OV-099) and major payload changes were made. This caused a slip of launch date from Novem- ber, 1985, to January, 1986. There were small middeck payload changes in October, November and December of 1985.loS

It is clear that these changes must have delayed the delivery of software which, in turn would delay the start of crew training. Crew training was not related to the accident, but it does seem clear that the system was breaking down (i.e., data presented in the Commission report shows that in January of 1986 the delays in the projected start of crew training were growing).log

Examination of the record shows that pressure to achieve the planned flight rate was forcing the crew to train later and later, which meant higher weekly training loads. This was very likely compromising the effectiveness o i the crew training and thus the safety of the missions, although no harm had been documented a t the time of the accident.

Manifest Changes-As described in detail above, the planning of a Shuttle mission requires more than a year of significant work, with the first major "freeze point" occurring 15 months before planned launch. A freeze point is a place in the mission planning schedule where decisions are made about the mission and its imple- mentations. In theory, these decisions are made in a cumulative fashion so that earlier decisions do not have to be changed as the mission is refined through the planning process. Indeed, if there are no changes, this is in fact the way the system works; however, there are changes.

107 Ibid., p. 5-38. lo8 Ibid., pp. 5-7-12, *OQ Ibid., p. 5-42.

129

The first freeze point occurs when the mission is officially de- fined and payloads are assigned to a specific Orbiter. Another major freeze point occurs approximately seven months before launch at the Cargo Intergration Review (CIR). Typically, more than 80 percent of the work necessary to prepare a mission occurs after the Cargo Integration Review. Changes in the mission after the CIR tend to be much more expensive than changes made earli- er in the process. O The Rogers Commission has adequately docu- mented the fact that changes to the Shuttle manifest were common and major. As of April, 1986, the six missions planned to follow flight 51-L which were not dedicated missions, i.e., not missions having only one customer, had a total of 30 changes or a n average of five each after the start of the production process. Eleven of these changes were major that is, they involved the exchange of different types of major payloads. l 2

Manifest changes can be divided into four basic categories de- pending on the origin of the change. Some changes are caused by hardware problems such as when the Tracking and Data Relay Satellite was found to have a problem and was deleted from flight 51-E. As there is no reason to launch a faulty satellite, NASA vir- tually is obligated to allow such faulty satellites to be changed out.

The second category of manifest change results from what could be called "customer request." For example, many communication satellites have been rescheduled at the customer's request for busi- ness reasons. Again, NASA is in a n awkward position because if the satellite is not needed, NASA would not want to be in the posi- tion of insisting that it be launched. (Although there have been cases when customers launched satellites and stored them on- orbit.)

A third category is caused by the belated recognition of oper- ational constraints in the Shuttle system. For example, it has been found that a payload combination would exceed the landing weights for the transatlantic abort sites.

In another example of this type of change, it was found that there was no acceptable launch window for a planned combination of payloads which needed to be put in different orbits. It would seem that NASA could improve its mission planning production process to minimize this kind of manifest change by doing a better job of assessing the impact of operational constraints on payload combinations earlier in the planning process. Of course, one must allow for the late emergence of subtle operational constraints which would only be discovered as a result of deep analysis rela- tively late in the process. Nevertheless the MPOT report suggests that NASA sometimes carries unworkable flights on the mani- fest. l

The fourth category of manifest change is due to external fac- tors, many of which are totally within NASA's power to deny. It appears that many of the Headquarters requests for changes are made in order to put on the manifest science experiments which

I I 0 NASA briefing on STS Production Process by Elaine Hofstetler-Presented to Committee Staff on May 19, 1986.

Rogers Commission Report, Volume I, pp. 166-73; Volume 11, pp. 5-26-29,J-33-51.

l 1 * NASA briefing, May 19, 1986.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 1 9 9 Ibid., June 25, 1986, p. 52. 1 5 Rogers Commission Report, Volume 11, p. 5-46.

130

are essentially payloads of opportunity. This would include the Get Away Specials (or GAS-cans). It has been considered highly desira- ble to give this kind of standby status to scientific experiments be- cause they have had low priority on the manifest. That is, it is a way for such experiments to get a relatively early flight.

When changes are made in the manifest they tend to ripple through the system and affect not only the mission in work but also all the other missions in work. For example, changes mean rework-things need to be done over. Software for the mission may have to be rewritten. Inevitably, this causes some delay and com- presses the time available for other work scheduled downstream in the process if the launch date is to be maintained. Of course, if the flight rate is to be achieved, launch dates must be kept.

Other missions are affected because the reworks necessary as a result of changes will pull engineers and technicians away from other projects. For example, in January, 1986, there were 21 flights in process. Given the fact that that resources available were finite, more work on one mission means that other missions have to wait. The result is that the mission preparations for the other missions also are compressed as they wait for the proceding mission to clear the process. The world system becomes less and less resilent, there is more and more overtime, and there is temptation to take short- cuts in the process.

It is important to note that "manifest changes" can also be viewed as "payload flexibility" as in the case of the "GAS-cans" mentioned above. Therefore, there may be a need to decide more specifically what we intend the Shuttle system to accomplish. If maximizing flight rate is to be the overriding consideration, then flexibility will have to suffer. However, if NASA adopts to rigid a posture with regard to payload changes, customers or users may object. For example, as pointed out above, there is no point in launching a faulty satellite. Most space operations are simply not mature enough for NASA to enforce a rigid manifest.

It would seem that a better way to minimize the adverse impacts of manifest changes would be to simplify the mission planning process so that freeze points could be later, that is nearer to the launch date, so that consequently changes would occur relatively earlier in the process, therefore with less impact.

Given the history of the program, it is known that there will be changes in the manifest and that the impact of these changes will be serious. It does not seem, therefore, that it would be particularly fruitful to try to develop analytical management tools to predict the impact of changes in the existing system (an effort NASA has suggested). Rather, effort should be directed toward developing a new, improved mission planning system. Also, the MPOT report claims that the impact of changes is already predictable, and can be budgeted. *

Operational Status of the System.-In addition to reconsidering the priority which should be attached to maximizing flight rate, there is also a need to consider the degree to which the Shuttle itself can be made more "operational." 1'4 Ibid., p. 5-38,

131

The Rogers Commission Report makes much of the fact that the Shuttle is not operational. The same point was made strongly to Committee staff in interviews with personnel at Kennedy Space Center involved in launch processing. The Roger Commission made no recommendation on this matter and NASA in its reponse to the Commission has not direcly commented on it.

As early as 1981, senior NASA officials agreed that the Shuttle should be brought 'lto a cost-effective operational status" and that to that end Shuttle design should be "frozen".1l6

The Shuttle was declared operational after its fourth flight, but that the program clearly was not capable of functioning in a manner that would be called operational in any other milieu. Each Shuttle flight is, indeed, unique. Large amounts of software must be written de nouo for each flight. This is appropriate for a develop- mental program but clearly but clearly will not work as NASA tries to move into a truly operational phase.

Prior to the Challenger accident NASA had realized that the mission planning process had to be drastically improved, probably through standardization. Unfortunately, pressure to increase the flight rate was driving all available resources into speeding up the existing system. There simply were not resources available to ana- lyze the mission planning system and see where it could be simpli- fied.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 1 9 9 Ibid., June 25, 1986, p. 52.

If the Shuttle is to fly routinely, the mission planning system must be reworked to that end. For example, the Commission report makes the point that the two flight simulators were a bottleneck in the astronaut training process. l a Undoubtedly this was true. What is not clear is whether there is another way. For example, would it be possible to develop specialized crews, say a group of as- tronauts trained to deploy communication satellites, who would need much less training to repeat identical or similar missions, thus reducing the demands on the simulators? The point is not that such savings must be found or can be found, but that they must be sought and resources must be dedicated to the search €or such savings. If, indeed, no such standardization of mission plan- ning is possible, NASA must face up to this fact and operate the Shuttle accordingly. As mentioned above, there are disturbing signs that NASA is moving once again toward achieving the high- est possible flight rate without fundamentally changing its ap- proach to Shuttle operations.

Pressure to Reduce Cost and Turn-around Time.-NASA was under pressure to reduce flight costs and to reduce turn-around time between flights. In some cases they could achieve both objec- tives at once by eliminating work done between flights (e.g., testing and refurbishment). A NASA memo shows that such actions were being pursued as early as August, 1981, after only one Shuttle

Ibid., Volume I, p. 170-71. Memo from W. R. Lucas, Director, Marshall Space Flight Center, to James M. Beggs, Ad-

ministrator, dated August 21, 1981; subject: "ET/SRB Productibility/Cost Reduction"; the rele- vant sentence reads: "I wholeheartedly agree with your statements that Shuttle performance requirements and design should be frozen so that we can concentrate all efforts on bringing the system to a cost-effective operational status."

11' Rogers Commission Report, Volume 11, p. 5-31

1 1 8 Ibid., Volume I, p. 170.

132

flight.llg Attached to the memo are lists of activities to improve the producibility and reduce the cost of the SRB and ET. These in- clude reduction of "mandatory government inspection require- ments" for SRM processing by Thiokol and reduction of SRM pro- pellant verification testing.

The point is not that these particular actions were unsafe, but that even very early in the flight program there were pressures on testing and inspection activities in the program.

Shuttle Process Issues.-Section VI.A.2.a. of this report, on "Shut- tle Processing Issues" discusses several matters such as the avail- ability of spares, overtine, and the adequacy of OMIs. It is clear that operating pressure aggravated and issues discussed there. For example, had there been no operating pressure there would have been less pressure on spares, less overtimd, and more time either to revise OMIs or to execute them.

Change Control Process.-Section VI.B.1.d. on "Change Control Process discusses how the pressure to increase flight rate compro- mised the hardware change control process. An important factor is the developmental (i.e., not-yet-operational) nature of the Shuttle System which means that large numbers of significant hardware changes can be expected.

d. Other Safety Issues Issue 1

What is the criticality of landing safety associated with pro- grammed and abort landing sites and their local characteristics? Findings

  1. The Committee finds that many of the normal and abort land- ing safety problems will be alleviated when the Rogers Commis- sion's and the Committee's (section V.A.l.b., this report) recommen- dations to upgrade the landing gear system are implemented. When the landing gear system is understood, straightforward cal- culations and operational rules will determine acceptable runway dimensions and conditions.

  2. The Committee found no reason to fault NASA's current pro- cedure on launch constraints based upon operational judgement and conservative rules on local conditions at planned abort and landing sites. However, since an obvious finding is that the Orbiter is a developmental system, it is axiomatic that unanticipated "dicey" circumstances will arise.

  3. It was found that for the least landing gear system stress, runway preference is Edwards Air Force Base (EAFB) (concrete), KSC, and Rogers Dry Lake (EAFB "lake bed") in that order. No reason was found to invalidate the KSC runway design. The rea- sons for the "dry" course surface still prevail over concern about wear on tires designed for one landing. Additional constraints at KSC because of lesser lateral stabilized overrun area may be needed to bring its safety to the level of the EAFB runway.

  4. The NASA Landing Safety Team's proposal to provide stand- ard landing aids and arresting barriers at all sites and their em119 NASA Memo from W.R. Lucas, to James M. Beggs, Administrator, dated August 21, 1981.

133

phasis on runway surface characteristics for repetitive tire use takes on a new dimension that is in addition to the Rogers Com- mission's recommendations.5 bid. 0 %id. iNm.-The nozzle to case joint design is significantly different than the case field joint design w ich caused the Challenger accident. However, it is cited here because some of the prob- l e m are relevant to the failure of the aft field joint.] . Weather, by far, is the most significant factor governing oper- ational decisions, Orbiter damage, and landing safety. The con- straint is simply that acceptable weather must be forecast with confidence within the time frame needed. Ultra-conservative rules prevail because of the predictable unpredictability of Cape weather. New and innovative local weather analysis and forecasting re- search is a high priority. The African Coast and southwestern United States sites enjoy more stable and predictable weather. Recommendations

The first priority to achieve a n acceptable degree of landing safety and to have a sensible base to work from for improvement is to implement the recommendations of the Rogers Commission and the Committee on the landing gear system improvement to attain a n operational capability. Then:

Instrument the system, and schedule all landings a t Edwards runway for systematic concurrent testing until the landing gear system is understood. Write a clean sheet set of rules based on results. Determine the risk of accident with the B-747 Shuttle Carri- er Aircraft (SCA) and its impact upon the Shuttle program. Extend every reasonable effort to assure a mission planning process to minimize the need for abort site landings. Reevaluate and determine the degree of risk acceptable at abort site landings and bring abort site capability up to meet that risk level. Expand astronaut matched team flight landing practice to cover all known exigencies. Propose additional training craft if necessary. Join in a venture with NOAA to invent new technology and techniques to learn new ways to understand the dynamics of Cape Kennedy weather phenomena to supplant current inad- equacy to forecast two hours ahead.

Discussion

This discussion assumes that landing gear system improvements are to be implemented. The substance of the testimony and results of the Committee investigation are fairly clear.

The EAFB runway will remain the primary programmed landing site for the duration of the Shuttle program simply because of the capricious nature of the Cape weather. All landing parameters favor Edwards runway as the best for safety and it approaches 100 percent predictable availability.

The safety of Rogers dry lake is permanently compromised be- cause of the lake bed surface. Its firmness and surface strength are variable and the surface has considerable debris scattered on it. Should the tires blow on one strut, it would dig in and the Orbiter would not be controllable as it would be on a concrete runway with nose wheel steering and brakes. This is also true of stabilized later- al and longitudinal overrun areas of the concrete runway.

134

From the body of testimony, it can be deduced that given a land- ing gear system that meets operational requirements, acceptable weather, and an adequately trained pilot, the Orbiter can consist- ently achieve the acceptable level of low risk landings that was originally intended at Edwards and KSC. The worst KSC case is the heavy weight abort Return To Launch Site (RTLS) landing. Night landings at these sites add an element of risk that cannot be evaluted until day landing confidence is restored. The only astro- naut testimony on night landings was not favorable.2 Rogers Commission Report, Volume I, p. 199. o bid., Chart SRB-4. 2 1 Larry Mulloy, NASA, Marshall Space Fli ht Center, "STS-51L Level I1 Flight Readiness Review,'' January 14,1986. See Appendix VIII-g. 2 2 Discussion with Allan McDonald, September 4, 1986. Z3 Rogers Commission Report, Volume 11. See Chart 15 (p. H-10) and Chart 19 (p. H-12). s Ibid., Chart 30 (p. H-18). o

Landing safety a t remote abort sites presents, by far, the worst case including all facets of navigation, weather, energy manage- ment, depth of pilot training, other air traffic intrusion, alignment, approach, heavy weight high speed landing, narrow and short run- ways, and fire and rescue support, and perhaps even terrorism or sabotage. In short, the classical emergency landing is just that-an emergency landing. It will surely test the skill of the pilot. The only sure cure for abort landing exposure is a successful launch.

Testimony gave reference to one RTLS site (KSC), five TAL (Trans Atlantic or Trans Abort Site) sites (Casablanca, Dakar, Moron, Rota, Zaragoza), and three AOA (Abort Once Around) sites (EAFB, White Sands Northrop, KSC). At least one each of these must be available within the rules of visibility, wind, dew point, precipitation, ceiling, cloud cover, turbulence, and gusts, and pro- vide TACAN, MLS, PAPI (Precision Approach Path Indicators), and Ball Bar lights as deemed necessary for the mission; the RTLS within 25 minutes of launch, the TAL at about 35 minutes, and the AOA in an hour and 45 minutes.

The Orbiter is not a good handling airplane to fly. The Orbiter landing is the most demanding task of airmanship expected of an aviator today. It is a complex and sophisticated blend of automa- tion, systems management, and manual skills:

The Orbiter re-enters with a 1100 mile cross track capability to begin the Terminal Area Management phase, 52 miles out at Mach 2.5 and 82,000 feet. Computer energy management delivers the Orbiter to the alignment circle on TACAN where the pilot takes over at three minutes out on a 19 degree glide scope aligning on PAPI lights. At 13,000 feet, 6 miles and two minutes out, he initiates flare to intercept the 1.5 degree glide slope at 275 knots. Guiding on the Ball Bar lights, he approaches and lands around 200 knots depending on his weight. At 140 to 120 knots, he begins to brake and decelerates to a stop.

If MLS terminal navigation is not available, the pilot can rely upon onboard radar for precision altitude and use his heads up dis- play to assist what is nominally a visual approach and landing. There is no room for computer, navigation or pilot error. Training aircraft training and practice IS an element of major importance to successful Orbiter landings under the variety of conditions facing the pilots. Unrationed crew team flight training is deemed essenlZo Rogers Commission Report, Volume V, p. 1455.

135

tial to landing safety. Conversely, suggested autoland systems for this application did not find much support because they would pose a whole new development and certification hazard.

Landing safety will make a lot more sense if and when the cloud of imminent landing gear system failure is dissipated. That has been a pervasive note through the entire testimony and investiga- tion. Issue 2

Has adequate provision been made for crew safety in case of in- flight emergencies? That is, has adequate provision been given to launch abort options and crew escape options? Findings

  1. Crew escape options were considered when the Shuttle was originally designed and the basic situation has not changed. Many initially attractive options do not significantly reduce risk to the crew either because they may not reduce exposure to the principal hazards or because they add risks of their own.

  2. A crew escape system for use in controlled gliding flight might be feasible and worthwhile.

  3. Crew escape during the ascent phase appears infeasible.

  4. Launch abort during SRB burn appears impossible but it may be possible to decrease risk to the crew after SRB separation, pri- marily through mission design. Recomrnendation

NASA should continue to respond to the recommendations of the Rogers Commission regarding (i) crew escape during controlled gliding flight and (ii) increasing the possibility of successful emer- gency runway landings. NASA should re-examine all crew survival options and report to the Committee on its findings. Discussion

Before addressing the particulars of the findings and recommen- dations regarding launch abort and crew escape a few general com- ments on safety and risk will establish a useful framework.

Any new safety equipment installed on the Orbiter will bring with it its own new risks. It will also add weight to the Orbiter and will have associated capital and operating costs. Each of these must be addressed.

New Risks.-Consider for example the possibility of adding ejec- tion seats to the Orbiter. The United States A i r Force experience with ejection seats has been that they are only about 80 percent effective. The point is that ejection seats are not a panacea. Any safety equipment has a chance of failing; ejection seats in particu- lar always have a potential of premature activation which would result in the crew being ejected when there is no need.

Additional Weight.-In order to accomplish its purpose, the Shuttle must put payloads, i.e., weight, in orbit. Adding weight to

121 Briefing to Committee Staff, May 28, 1986, "Report of the First Stage Abort Options Histo- ry Task Group Chartered by the Mission Planning and Operations Team '-Barney Roberts, Ad- vanced Programs Office,Johnson Space Center.

136

the Orbiter reduces the payload weight that can be orbited and therefore reduces the justification for the program. This is perhaps made clearer by considering a reductio ad absurdum. Suppose one could develop a new escape system-perhaps a n ejection pod which could reduce risks to the crew by 90 percent but weighed approxi- mately 65,000 pounds. Since the Shuttle payload capability is only about 65,000 pounds there would be no remaining payload capacity in the Shuttle, and some risk would still remain. There would be no point to installing such a system because it would be a very bad trade. Evidently, one must do an engineering cost-benefit calcula- tion and decide if the benefit is worth the penalty for each pro- posed change.

New Costs.-The same type of cost-benefit calculation must be done in the financial dimension. It is important to emphasize that the question is not "how much is a life worth?," but rather "where can a n extra amount of funding best be spent to reduce total risk to the crew, the mission, and the Orbiter?"

Risks will never be zero-what NASA must do is to better under- stand the risks and minimize the most dangerous exposures.

The risk, cost and weight penalties of crew escape systems that could hope to operate effectively while the SRB are thrusting are very large. This dictates that it is much more efficient to put pro- gram resources into reducing risks by improving the reliability of the SRB's and the whole Shuttle system during the period of time that the SRB's are thrusting. For example, if one of the SRB's should develop a problem so that there was a need to separate the Orbiter from 11:e SRB's and External Tank, it is essentially impos- sible to do this successfully while the SRB's are still thrusting. There are potential means of terminating SRB thrust which amount to explosively opening holes in the rocket casing. The holes allow the burning gases to exit the casing at several places so that there is no net thrust. Such a mechanism has the potential of pre- mature activation which could lead to loss of the crew and the mis- sion. In addition, the resulting deceleration loads on the Orbiter would require significant redesign, if the Orbiter were to sur- vive.lZ2

A large part of the problem is that the launch situation is very dynamic. Decisions and implementation of decisions must be made very rapidly. The decisions are binary; that is, either "go" or "no- go," and the implementation must be largely automated for speed of execution. Thus, if a premature activation begins it will almost certainly go to completion.

In the case of 51-L accident, the first ambiguous indication of a problem came at about 65 seconds into the mission. At 72 seconds the system was coming apart and by 74 seconds the Orbiter was destroyed. The first signs of trouble were ambiguous because indi- cations that the Orbiter was adjusting to aerodynamic forces due to the leak in the SRB joint appear very similar to signals generated when the Orbiter responded to upper atmosphere winds. It would be very risky to initiate any kind of crew escape action based on

122 Cmte Hgs, Transcript, June 25, 1986, pp. 132-35,1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 1 9 9 Ibid., June 25, 1986, p. 52. 3 - 4 1 , Former astronaut, General Thomas Stafford. testified strongly in favor of crew escape systems but seemed to represent a minority view this sort of signal. The Solid Rocket Boosters began coming off the system at 72 seconds, after which an escape system might well have been inoperable due to mechanical deformations of the Orbit- er structure under the aerodynamic loads that resulted, Thus, there was a period of time of something less than 9 seconds during which some kind of escape system might have been able to help the crew. It seems clear that attempting to develop a system to respond effectively to a situation such as this would be unproductive and that it would be wiser to improve the safety and realiability of the system during this ascent phase.

137

After the termination of SRB thrust, immediate crew escape is difficult because the Orbiter has achieved a very high altitude. However, under a range of circumstances it is possible to fly the Orbiter back to a controlled gliding landing at a runway. Under other circumstances, for example if the main engines fail shortly after SRB termination, the Orbiter may be forced to ditch into the ocean and such a ditching is not survivable.

After SRB termination a principal risk is that the Orbiter could lose one, two or three main engines. Depending on when and how this occurred it might be possible to fly the Orbiter to a landing site. It may be possible and perhaps practical to increase the proba- bility of the Orbiter successfully accomplishing this maneuver through flight design. That is, it might be possible to accept some- what reduced payloads and achieve more conservative trajectories which would minimize the exposure of the Orbiter to ditching or crash landing if main engine failure were to occur during the accent phase.

If the Orbiter finds itself in a situation (due to Main Engine fail- ure or other failure) where it cannot fly to a runway but is other- wise under control, the crew might be able to escape during the controlled gliding descent. This would apply not only during the ascent phase but also during the landing phase. For example, if the reentry trajectory were miscalculated and the Orbiter could not reach the planned landing site the crew might have adequate time to bail out. There is a change that such a bailout system could be achievable with acceptable performance penalties. Certainly this last option-crew bail-out during gliding flight-must be very care- fully studied.

The trade offs and calculations that have to be made in the area of crew escape and launch abort are activities in which astronaut involvement would be most useful.

Astronauts clearly represent the principal source of flight experi- ence and therefore can make major inputs to decisions regarding what is practical to accomplish during flight. It is pointless to add risks, weight, and cost for a system that cannot be operated by the astronauts during flight conditions. Involvement of astronauts in management is discussed in section VI. B. 2. a. of this report.

138

In summary, space flight will always be a bold and dangerous venture. NASA must work to better understand the risks of space flight and in particular the risks of each Shuttle launch and to reduce these to an acceptable level.

MANAGEMENT ISSUE