FIGURE

VIGi

141

Top NASA managers lack a clear understanding of risk management. Dr. Fletcher, NASA's Administrator, made the following statement, when asked by Mrs. Lloyd to "describe the elements of NASA's risk management activities . . .":

Well, risk management is a pretty generic term. Risk management is decided in Headquarters in terms of what are the chances of an overall failure of a system under a given set of circumstances. When you get down to the flight team, the launch crew in those last several hours or couple of days, risk management is an entirely different thing. They have to look at the factors that have come up just before launch and assess whether this is a risk we want to take. This is a judgement question; you can't make calculations at this point.124

Dr. Silveira, NASA's Chief Engineer, testified on the same day that,

As we had mentioned in the testimony that we gave previously . . ., the only time that we had gone into trying to assess a probability, if you will, or a risk, was as a result of a request that was made by DOE for their analysis that they were performing at that time, to assess the probability of failure of the vehicle, to assess the danger when we are flying the RTG's, the radioactive material. As far as in our program, and any major decisions that we would make, we have a number of reasons why our past history had indicated that that was not a good way of doing it. As a result, we don't use it generally in our risk management, we prefer using things like the failure effects and analysis that we do; the technical engineering judgement, using things to control our failures rather than depending upon a probability analysis to assess it.2 Rogers Commission Report, Volume I, p. 199. 5

However, Mr. Robert Thompson, who was Shuttle Program Manager from 1970 to 1972, testified on July 24th before the Committee in a much less ambiguous fashion regarding his view on the importance of risk management:

I would first like to make an observation on the decisionmaking process. Evidence, in retrospect, points to a long period of time, especially based on post-flight inspections when the joint design weakness was 'sending a message' and the true potential of this message was not perceived and reacted to. This, combined with perlaunch discussions between Marshall and Thiokol, points out the need that must pervade the Shuttle management team in the future. A very strong risk management . . . I have parentheses around risk management. I will be happy to expand on that. It has a certain meaning to me. A very strong risk management organization must be kept in place and a continuing search for potential failures must be maintained. . . .

124 Cmt Hgs, Transcript, June 12, 1986, p. 186. 125 Ibid. p. 187.

142

The role of the program manager in this risk management organization must be very strong and clear. The entire program organization from top to bottom must be clearly chartered and as people come and go these organizational relationships must be carefully maintained.2 Rogers Commission Report, Volume I, p. 199. 6

Based upon the divergences of these testimonies, the Committee concluded that although NASA's Space Transportation System program contains the elements of a risk management program, there needs to be a new and heightened coordination of the separate activities by NASA in order to minimize the risks inherent in Shuttle flights.

The FMEAs determine the worst case "What if' scenarios for all possible failure modes and their potential worst case or intended effects.127 As a result of performing the FMEA, a list of critical items is identified. NASA's FMEA assure that all Criticality 1 and 1R systems are properly identified and classified. The failure of these items would produce loss of life and/or loss of vehicle. The FMEA applies strictly to the hardware associated with the NSTS and is "bottoms-up" analysis, in which a single component failure is traced and its effect on a particular subsystem, subsystem interfaces, and the overall flight systems is determined. Accompanying the FMEA is the Hazard Analyses (HA) which is, according to NASA, a "top-down" approach that takes into account human factors in evaluating the consequences of particular accidents or accident scenarios. Hazard Analysis is the basic tool of the safety evaluation.

The FMEA as used by NASA assigns no probability numbers to event sequences along a given failure path. Although NASA re- gards the methodology of FMEA as rigorous, within the agency there was a wide variation in the engineering judgments among the design engineers and senior management in the NSTS program on the probability of failure of the Shuttle.128The Committee, in hearings held earlier this year related to the safety aspects of the Shuttle Centaur in its utilization of Radioisotope Thermoelectric Generators on board the Shuttle spacecraft, also found wide discrepancies in the estimate of the failure probability for the Solid Rocket Booster among the experts. 129

NASA has rejected the use of probability on the basis that such techniques are insufficient to assure that adequate safety margins can be applied to protect the lives of the crew. They also argue that their problem correction procedures preclude the establishment of a sufficient statistical database, because once a single point failure has been identified through the FMEA, steps are taken to design bid., July 24, 1986, p. 106.

12' It is the prime responsibility of the design engineers working with reliability analysts to nerform the FMEA in accordance with guidelines established in NASA documents (Apuendix b1-0. These documents are provided as part of each statement of work submitted to the contractor. From such FMEAs, a Critical Items List is established in which particular components under the responsibility of the contractor are categorized in accordance with their criticality to the mission, crew, and/or spacecraft. Included as Appendix VI-D is NASA's document 100-2G entitled Reliability Desk Instruction, Flight Hardware Failure Mode and Effects Analyses (FMEA) and Critical Items List (CIL).

Rogers Commlsslon Report, Volume 11, p. F-4.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 2 9 Hearine before Subcommittee on Energy Research and Production and Subcommittee on Space-&ien& and Applications of the Committee on Science and Technology, 99th Gong., 2nd Sew., March 4, 1986 (No. 97). "Review of RTG Utilization in Space Missions."

143

the safety features into the component, thereby eliminating the failure mode or establishing sufficient redundancy to preclude catastrophic failures associated with the particular component. This change of the component means that earlier data no longer apply.

On the other hand, with respect to certification testing of the Space Shuttle Main Engine, NASA seems to argue that a useful statistical data base can be generated even though the configuration of the engine is changed as data is accumulated. That is, as running time is accumulated in SSME certification testing, major components-e.g., the high pressure turbopumps-are replaced, and yet NASA seems to believe that the total accumulated running time has some meaning for determining engine life time. l30

All subsystems of the NSTS are intended to meet design requirements that incorporate the fail-safe features as a minimum with fail-operationaVfai1-safecriteria placed on all Orbiter avionics systems. Fail-safe requirements are defined as designs which can withstand a single failure and permit return of the crew to the ground safely. Fail-operational/fail-safeis defined as permitting two sequential failures while enabling crew return. There are some parts of the NSTS which must be exempted from meeting these criteria. The reason is that it is not possible to improve the safety features of these systems through redundancy or other means. Such systems are the primary structure, the thermal protection system, pressure vessels and the premature firing mode of the pyrotech- nics. For example, the pressure vessel cannot be provided with redundancy in a safe manner because addition of another pressure vessel would only enhance the failure probability or the criticality of this component.

The FMEA is a very conservative analysis according to NASA since it provides information on worst case situations of all possible failure modes and the potential worst case effects. Even so, the Committee was unable to determine the degree to which flight anomalies and trend analyses in historical performance data are utilized to insure that the appropriate measures are taken in the design and testing of various critical components to assure ultimate safety and minimization of risk.

NASA is presently reviewing the 748 Criticality 1 items and the 1,621 Criticality 1R items. Based upon a series of tests and analyses and the availability of methods and instrumentation to detect problems associated with various Criticality 1 and 1R items, waivers are given to permit flight of critical items. Before a waiver is granted, according to NASA, extensive documentation and review of each item on the Critical Items List (CIL) for which a waiver has been applied must be undertaken and approved all the way through Level 1 management. There is a difference between the number of waivers granted and the total number of items on the Critical Items List. For Criticality-1 items this difference reflects the number of systems exempted from the criteria of fail-safe or fail-operational/fail-safe.NASA, however, does not distinguish in its quality control procedure between exempted items and those items which are not exempt from the waiver process. According to 130 Rogers Commission Report, Volume 11, pp. K25-26

NASA Briefing on July 10, 1986.

144

NASA, this categorization of exempt versus waiver is strictly a management technique for identifying components and systems on the Space Shuttle in terms of their safety compatibility.

The Committee finds the FMEA to be a n appropriate method for identifying the Critical 1 and 1R elements of the NSTS; however, not all the elements so identified pose a n equal threat. Without some means of estimating the probability of failure of the various elements it is not clear how NASA can focus its attention and resources as effectively as possible on the most critical systems. Moreover, waivers can be granted without assurance that a n adequate level of safety has been achieved.

b. Launch Decision Process Issue 1

Is the process for establishing launch constraints and dealing with them effective? Findings

  1. There is no clear understanding or agreement among the various levels of NASA management as to what constitutes a launch constraint or the process for imposing and waiving constraints.

  2. Launch constraints were often waived after developing a rationale for accepting the problem rather than correcting the problem; moreover, this rationale was not always based on sound engineering or scientific principles. Recommendations

  3. NASA should establish rigorous procedures for identifying and documenting launch constraints, The individual(s1 responsible for implementing this procedure should be clearly identified, and well defined and understood criteria for waiving the constraints should be established.

  4. NASA should exercise extreme caution in waiving launch constraints before correcting the problem that led to the launch constraint. The rationale should be based on rigorous scientifidengi- neering analyses or tests and should be understood and accepted by the Program Manager. Discussion

No single system exists for establishing and dealing with launch constraints within the Shuttle Program; for example, Marshall maintains their own system through their Problem Assessment Center (PAC) to deal with problems affecting the propulsion system. In testimony before the Rogers Commission, Mr. Mulloy explained that the system was established to provide visability for problems relating to the propulsion system and a "launch constraint" was in effect a flag to alert the Project Office to address the problem at the Flight Readiness Review.

A launch constraint means that we have to address the observations, see if we have seen anything on the previous

145

flight that changes our previous rationale, and address that at the Flight Readiness Review. 132

The NSTS Program Manager stated that he was unaware that a launch constraint had been imposed as a result of the O-ring erosion. Unawareness of this launch constraint was also claimed by the Level I Program Office and key Thiokol personnel: Mssrs. Ebeling, Kilminster, Russell, McDonald, and Boisjoly.33 Rogers Commission Report, Volume V, p. 784. a* bid., Chart 130 (p. H-66).

In staff briefings, it was suggested by NASA personnel that perhaps "launch constraint" was a poor choice of words to describe this process for flagging problems. Those individuals who claimed no knowledge of a launch constraint had certainly been made aware of the O-ring erosion problem. This problem and the resolution had been discussed throughout the system including the FRRs. Therefore, although it is difficult to understand why the Program Manager and others weren't more familiar with the Marshall PAS, as a practical matter it probably had little effect on the final decisions. These "launch constraints" were potential problems that had to be resolved prior to flight and the Level 111 Project Managers were responsible for resolving any problems dealing with their systems. During the Rogers Commission hearings, Mr. Mulloy acknowledged that he had ultimate responsibility for waivifig the launch constraints and ultimate responsibility for the launch readiness of the Solid Rocket Boosters.

Although the O-ring erosion continued to occur, and with no apparent pattern, the SRB Project Manager repeatedly waived the launch constraint. Throughout the Rogers Commission hearings and the hearings of the Committee on Science and Technology, NASA witnesses continually justified their decision to continue flying the Shuttle based on their previous successful flights. This reliance on their "experience base" was a major factor in the repeated waivers of the Marshall imposed launch constraint on the SRBs. Chairman Rogers asked Mr. Mulloy what was meant by "addressing" the problem, and Mr. Mulloy responded:

I mean present the data as to whether or not what we have seen in our most recent observation, which may not be the last flight, it may be the flight before that, is within our experience base and whether or not the previous analyses and tests that previously concluded that was a n acceptable situation is still valid, based upon later observations.3 NASA, "Report to the President Actions to Implement the Recommendations of the Presi- dential Commission on the Space Shuttle Challenger Accident," July 14, 1986. (Hereafter r e ferred to as NASA Response to Rogers Commission.) 4

Mr. Mulloy also explained his reliance on the experience base in testimony before the Science and Technology Committee:

That was presented to me as a rationale to continue flying, one we had seen it on STS-2, what we saw on the last flight wasn't as bad, therefore it was a n acceptable risk.

l n 2 Rogers Commission Report, Volume V, p. 1513.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 3 3 Ibid., p. 1590; note: Yet it was Mr. McDonald who wrote a letter to the SRB Project Office recommending that the O-ring problem be dropped from the Problem Assessment System (PAS), which was in fact equivalent to removing the launch constraint.

L 3 4 Rogers Commission Report, Volume V, p. 1513.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 3 5 Cmte Hgs, Transcript, June 17, 1986, p. 151.

146

The Committee concurs with Dr. Feynman's analysis that NASA had no understanding of the O-ring erosion phenomenon, and their rationale for accepting it was not based on sound engineering principles.

. . . The acceptance and success of these flights is taken as evidence of safety. But erosion and blow-by are not what the design expected. They are warnings that something is wrong. . . . The fact that this danger did not lead to a catastrophe before is no guarantee that it will not the next time, unless it is completely understood. . . . The origin and consequences of the erosion and blow-by were not understood . . . officials behaved as if they understood it, giving apparently logical arguments to each other often depending on the "success" of previous flights. 36

Issue 2

Are the launch commit criteria procedures adequate to ensure the safety of the mission? Findings

  1. The procedure used for developing launch commit criteria is systematic and thorough; however, violations of the criteria do not necessarily mean "no go". Therefore, NASA sometimes relied on engineering judgments made during the terminal countdown in determining whether to launch.

  2. Launch commit criteria were sometimes waived without adequate engineering analysis or understanding of the technical reasons for establishing the criteria. Recommendations

  3. NASA should review the launch commit criteria procedures, especially those for dealing with violations, to lessen the reliance on engineering judgments under str::s.

  4. When situations arise where real time" engineering judgments are unavoidable, NASA should adopt a more conservative approach to waiving previously established criteria. In no case should a criterion be waived without a thorough understanding of the rationale for the establishment of the criterion. Discussion

Launch commit criteria define limits on specific system parameters which are required to be monitored during the terminal countdown. When these limits are exceeded the launch is held until the condition is corrected or a n acceptable alternate capability or procedure is instituted.

Proposed criteria are developed by NASA and contractor personnel and are submitted to the NSTS Program Office for review and disposition. All changes are controlled by the Level I1 PRCB (Program Requirements Change Board) and all launch commit criteria are reviewed prior to each flight a t the launch site flow review (8 weeks prior to launch), the Flight Readiness Review and the L-1

Rogers Commission Report, Volume 11, p. F-1.

147

review. Where practical Launch Commit Criteria include preplanned decisions on courses of action to be taken when violations occur.

The process described for developing and controlling the launch commit criteria is systematic and thorough; however, in briefings by NASA personnel it was learned that it is not uncommon to experience violations of the specified limits. These can often be resolved in a straight forward manner based on a prior plan of action; however, the Committee is concerned that in those situations where no preplanned course of action is available, real time engineering decisions are being made under the stress that is inherent in a pre-launch environment. This is particularly undesirable when it is perceived that there are pressures to launch.

For example, it was learned that on the morning of the scheduled launch of STS 51-L the Mission Evaluation Room (MER) Manager requested a waiver of the Launch Commit Criteria lower limit of 31 degrees F.13' The Flight Director can not unilaterally waive launch commit criteria and since the temperature at launch was above 31 degrees it became unnecessary to pursue the matter further. Had it been necessary to waive the criterion, the Flight Director would have advised the Program Manager who then would have orally polled the Project Managers before making the final decision. One can only conjecture at this point what the decision would have been; however, the Committee is concerned that at least two key managers in the decision making chain (i.e. the MER Manager and the Flight Director) were prepared to waive the criterion without thoroughly understanding it. Issue 3

Are the launch readiness review procedures and communications adequate? Finding

The Committee finds that the review procedures and communications used to assure flight readiness were systematic, thorough, and comprehensive and provided ample opportunity for surfacing hardware problems prior to flight. Level I FRRs are usually recorded (audio); however, there is often no record made of other key prelaunch meetings. Recommendation

NASA should make every reasonable effort to record meetings where key decisions might be made; in particular, all formal Flight Readiness Reviews, including the L-1 and the Mission Management Team meeting should be recorded, where feasible by video. Discussion

The Flight Readiness Review process encompasses a series of reviews beginning with contractor reviews of their systems, and going through the Project Management review (Level III), and NSTS Program Management review (the "Pre-FRR'), and culmi-

Rogers Commission Report, Volume 11, pp. 522-23.

148

nating in the Level I (Headquarters) review which is referred to as "the" FRR. One additional formal review takes place 24 hours before launch and is called the "L-1" review. This is conducted by the Mission Management Team (MMT) which is appointed by the Associate Administrator for Space Flight at the time he calls for the FRR. All open work and action items identified at the FRR are closed out at the L-1. In addition to conducting the L-1 review, the MMT functions as a technical advisory body for the Program Manager and is on call beginning 48 hours before the launch until after the mission is completed and the Orbiter is safed.

The Committee concurs with the Rogers Commission that NASA should record key pre-launch meetings; however, the Committee finds no basis for concluding that the Flight Readiness Review procedure is flawed; on the contrary, the procedure appears to be exceptionally thorough and the scope of the issues that are addressed at the FRRs is sufficient to surface any problems that the contractors or NASA management deem appropriate to surface. However, the Flight Readiness Reviews are not intended to replace engineering analysis, and therefore, they cannot be expected to prevent a flight because of a design flaw that management had already determined represented an acceptable risk. In addition all the appropriate offices, including the Chief Engineer representing SR&QA, are represented at the FRRs. Specifically, from the first evidence of 0- ring erosion to the final decision to launch 51-L, the process provided ample opportunity to review and assess the severity of the problems; moreover, all levels of NASA management were made aware of the erosion.138 However, a process is only as effective as the responsible individuals make it. For example, see section VI B.2.c. on the weakness in the SR&QA organization. Issue 4

Was the failure to inform the Level I or Level I1 Program Managers of the Teleconference involving NASA and Morton Thiokol on the eve of the launch a factor in the decision to launch? Findings

  1. The Committee finds that Marshall management used poor judgment in not informing the NSTS Program Manager or the Level I Manager of the events that took place the night before the launch, specifically the stated concerns of the Thiokol engineers. However, the Committee finds no evidence to support a suggestion that the outcome would have been any different had they been told.

  2. The Committee finds the efforts of Thiokol engineers to post- pone the launch commendable; however, Thiokol had numerous opportunities throughout the normal flight readiness process following flight 51-C in January, 1985 to have the new minimum temperature criteria established.

138 Ibid., pp. H1-97

149

Discussion

The management of the Shuttle Program has given the responsibility for the Solid Rocket Boosters to the Marshall Space Flight Center. It is the Marshall Center that contracts with Thiokol for the hardware and related services pertaining to the SRBs. The NSTS Program Manager relies on the Marshall management and technical expertise for issues relating to the SRB and it is unreasonable to expect him to take technical advice from the contractor's engineers. This position is supported by the actions taken by Mr. Aldrich and Mr. Moore with regard to the Rockwell concerns over ice. 39 Unlike the SRB situation where the Thiokol managers gave a written positive recommendation for launch, the Rockwell managers refused to give an unqualified go for launch; yet Mr. Aldrich asked for and accepted the recommendations of the Orbiter Project Manager and the Directors of Engineering at JSC and KSC. The Committee finds no evidence to suggest that in the instance of the Thiokol engineers' concerns, either Mr. Aldrich or Mr. Moore would have disregarded the recommendation of the technical managers with the expertise in solid rockets (i.e. Marshall and Thiokol) and relied instead on their own assessment of the engineers' concerns.

Launch commit criteria and launch constraints should be established well in advance of a scheduled mission and should be based on rational, scientific and engineering arguments, including previous flight experience. Thiokol engineers based their arguments for a 53 degree temperature criteria on the fact that this was the cold- est temperature experienced to date and they had experienced severe (but not necessarily the worst) erosion on that flight. However, a test firing had been conducted at 40 degrees joint temperature which resulted in no joint problems (technicians had "tamped" the joint putty before the test, however, a procedure not used on flight hardware). Moreover, it was pointed out in the hearing that this flight had occurred a year earlier and no mention had been made of changing the temperature criteria for launch.

Mr. VOLKMER. But in all of the memorandums, et cetera, that had occurred before-in-between the time, January 1985 and January 1986, you don't specifically say that. . . . Mr. BOISJOLY. That is right, . . . It was nobody's expectation we would ever experience any cold weather to that degree before we had a chance to fix it again, so that basically is why it wasn't pursued any further than that from my personal standpoint.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 4 0

That was later questioned by Mr. Nelson in remembering that flight 61-C (the flight just prior to 51-L) had been scrubbed four times for reasons unrelated to temperature when the temperatures were less than 53 degrees during several of those scrubs, reaching down into the low 40s during the first scheduled launch.

lS8 bid., Volume I, pp. 114-17.

Cmte Hgs, Transcript, June 18, 1986, pp. 83-84.

150

Mr. NELSON. . . . and so my question is, did any of these same concerns with the temperature come up in discussions during the final checks before those attempted launches? Mr. MCDONALD. I am not aware that they had, Congressman. I don't know. I wasn't at that launch, but I don't recall that that came up. l 4

Mr. Nelson later asked the Commander of 61-43, Cdr. Robert L. Gibson, whether he recalled any discussion among management or any of the contractors regarding the desirability of launching in 41 degree weather; Commander Gibson also recalled no special concerns regarding temperature.4 Rogers Commission Report, Volume 11, p. H-1. 2

Mr. Packard also questioned Mr. McDonald about the temperature during earlier attempts to launch 51-L and asked whether in fact it had been below 53 degrees during some of those attempts. Mr. McDonald replied, "That is correct", and when asked whether temperature had been discussed at those times, Mr. McDonald said, "No, it was not . . . Nowhere was it, no." Mr. Packard also asked why, in Mr. McDonald's judgment, temperature had not been discussed in as much as the temperature was below what they believed to be safe, and Mr. McDonald answered, "I don't-I can't answer that."1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 4 3

Mr. Packard also noted the delay in evaluating the effects of temperature, quoting from Mr. Kilminster's testimony, "As launch was scheduled for early the next day, our engineers immediately commenced evaluating the available data." He asked why they waited until the night before the launch to begin even considering the whole question of O-ring resiliency and O-ring problems under cold weather conditions. Mr. Kilminster replied that this was in response to a specific request by NASA.144

This indicated that the concerns and recommendations of the Thiokol engineers were solicited by NASA, and in as much as they had not come forth with the recommendation for a higher minimum temperature criterion on earlier occasions when it was planned to launch at temperatures below 53 degrees, it is unlikely that this recommendation would have been made on this occasion without the specific inquiry by NASA.

The Committee finds no evidence that new data were presented during the January 27th teleconference that were not available to Thiokol at the time of the Flight Readiness Review. Moreover, the information presented was substantially the same as that presented at the August 19th briefing (see Section VIII) a t which time they had recommended that it was safe to fly as long as the joints were leaked checked to 200 psi, were free from contamination in the seal area and met O-ring squeeze requirements. No mention was made of a temperature constraint at that time o r anytime between then and the January 27th teleconference.

The Committee finds that Thiokol's advice and recommendations to NASA were inconsistent, and therefore, the arguments presented during the January 27th teleconference might not have been as persuasive at the time as they now appear to be in hindsight. Issue 5

151

Do the principal contractors have a n appropriate role in the launch decision making process? Finding

The principal contractors have a n active role throughout the decision making process right up to the launch; however, the look of a firm requirement for their concurrence at the time of launch does partially relieve them of responsibility for mission success. Recommendation

Principal contractors should be required to make a clear, unam- biguous statement concerning launch readiness just prior to launch. Discussion

Participating contractors are required to sign off prior to launch that their flight system or facility is ready to support the flight. This is generally a one-time requirement for a given mission and although they are orally polled prior to the flight, they are not generally required to make any additional written positive commitment for a "go" prior to launch. Mr. Richard Davis, President, Martin Marietta Michoud Aerospace, explained:

Up to and including the L-minus-one-day review, there's no doubt that every company has a very strong voice; and, as a matter of fact, at the L-minus-one-day review, they

are required to stand up and commit their hardware as go or no-go. And those are very unequivocal commitments, also. After that time, then the reviews are more mission management meetings that are held, and as you get down into the countdown, it turns into more of a real time polling of the people that are actually controlling the launch.

In those latter meetings we are not, I would say, formally involved in those unless there is some problem with the hardware itself . . . We are polled by the Director of Engineering prior to the launch actually proceeding, so we are sort of polled in a n informal manner. We are not asked at any time after the L-minus-one-day for a formal go or no-go.

Contractors can stop the launch if they have serious reservations about the safety of the mission, and presumably they would.

Mr. DAVIS.. . . I have never felt that if I needed to stop a launch, I could not stop it. While I have not been asked for a positive go or no-go, the ability is always there if I decide no, to stop the launch.146

152

However, the present system permits them to "express concern" without actually saying, "stop the flight, it is unsafe". If the odds favor a successful flight they do not have to be responsible for can- celling, yet if the mission fails they are on record as having warned about potential dangers. (see Section V, discussion over Rockwell concerns over ice) Issue 6

Are astronauts adequately represented in the decision making process? Finding

The astronauts believe they currently have the opportunity to make inputs into the process and are reluctant to assume a greater responsibility for the decision to launch. Discussion

Considerable discussion at the hearing focused on the astronaut's interest in being more involved in the decision making, for example by attending management meetings. Capt. Young made the point that astronauts really didn't have the time to attend a lot of meetings, or the technical expertise to influence the decision.

We could certainly put people in those kinds of meetings. I am not sure they have the technical expertise to really be able to say go or not

With regard to the SRB seals, he pointed out that he and Captain Crippen had attended a briefing at Thiokol where it was stated that the seals weren't even necessary, and some people were complaining about having to put two seals in. And he suggested that if others in the agency had understood the problem they would have stopped the flights.

The rest of the agency, if they had been aware of this problem, we wouldn t have flown. We would have fixed it. If other people responsible in the management structure had the feeling this was a serious problem, we wouldn't have gone. We have to believe that, because there, on the Orbiter, there are 1500 criticality 1 items on the Orbiter alone, on STS-1, those items are still there, and if the management system can't make sure those things are ready to fly, we can never fly again. If you have an astronaut saying every step of the way, don't fly because of this, that or this, where they have no expertise, it would be troublesome. 14*

Mr. Lujan asked whether NASA should consider a new class of astronauts with specific technical expertise who would fly occasion- ally. Capt. Young suggested that this was not a good use of an astronaut's talents.

You can get real good engineers to do the same thing, a heck of a lot cheaper, and make just as good inputs. . . .

1*7 Ibid.,June 25, 1986,p. 42.

Ibid.,p. 44.

153

In the main, you like to keep astronauts around to fly spaceships because that is their talent, and that is what they want to do. . . .1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 4 9

General McDivitt concurred:

There should be a caution about putting too much responsibility on astronauts, when they don't have the time to do it. Like the flight crew commander is very busy prior to flight and does not have time to spend a lot of his time involved in reviewing engineering decisions that have already been made by very professional people. . . .l 5 0

In response to suggestions that the astronauts might have stopped the launch of 51-L had they been aware of the problems with the seals, Capt. Young provided an excellent analogy to illustrate his skepticism that they would have altered the decision to launch:

If an engine man comes up and says that engine is ready to fly and the turbine blades are a little cracked but we have run tests and we can show with a cracked turbine blade the engine pumps are not going to come apart and we have got to fly, would an astronaut say no, you are not going to fly until you change the turbines, for example?151

There was complete agreement among the astronauts who testified that the crew should be able to make inputs to the decision making process, but they all felt they now have this opportunity; they can and do attend FRRs and other meetings. However, there was a strong feeling among the astronauts that they had to rely on the expertise of the engineers and the technical competence of the managers and could not be expected to intervene in that process. They believed it was unrealistic to expect the crew to make the go or no-go decision; astronauts should not be expected to represent the principal concern for safety.

Major Slayton made the point that astronauts in general were willing to take more risk than management, not less.

One philosophical point that needs to be brought out here . . . is that the crew commanders and astronauts in general view things a little bit different than everybody else does to begin with and you have to recognize that and be a little bit cautious. In general a crew commander, if given a choice, is willing to take more risk than his management. That has been the case in the past and he is more likely to give you a 'go' and you need somebody at a higher level that is willing to, on his behalf, willing to take the bull by the horns and have the guts to say 'no go' on behalf of the crew.

Col. Hartsfield concurred: ~~~

154

I wanted to say that I feel that it is just like in our own government, the buck stops at the White House or the Congress perhaps, but somewhere, but certainly above the level of the rest of us. I think that the decison to go or "no go'' rightfully be- longs with the upper management, and not, my personal opinion, not with the crew. The crew input should be felt very strong.153 c. Technical Expertise of Personnel

Issue

Does NASA have an adequate level of in-house technical expertise to manage the Shuttle Program properly? Findings

  1. During the last decade NASA has had significant decreases in manpower. A disproportionate reduction may have occurred in the safety, reliability and quality assurance staff at NASA headquarters and at the Marshall Space Flight Center. Additionally during the period preceding the Challenger accident, the Office of Space Flight also suffered a decline in staff. The decreases may have limited the ability of those offices to perform their review functions.

  2. The information presented to NASA headquarters on August 19, 1985 was sufficient to require immediate and concentrated efforts to remedy the joint design flaws. The fact that NASA did not take stronger action to solve this problem indicates that its top technical staff did not fully accept or understand the seriousness of the joint problem. Recommendations

  3. NASA should review the numbers and qualifications of key staff in technical and management positions and should consider additional training and recruitment of individuals to further the quality and safety of NASA's missions.

  4. The Committee should maintain on-going oversight of this analysis and conduct an in-depth examination upon the conclusion of NASA's review. Discussion

In the wake of the Challenger accident, serious questions arose over whether NASA had sufficient technical capability to identify and solve problems like the SRB seal problem. It is argued that through reductions in staffing levels and departures to the private sector by experienced technical employees, NASA lacked in-house problem assessment capability. This is an issue that is not subject to ready answers, and an in-depth examination of NASA technical capacity was generally beyond the scope of the Committee's hearing.

However, it is clear that over the last 15 years NASA has had significant staffing reductions and that a disproportionate number of these reductions may have occurred in the areas of quality assurance and safety.5 bid. 0 %id. iNm.-The nozzle to case joint design is significantly different than the case field joint design w ich caused the Challenger accident. However, it is cited here because some of the prob- l e m are relevant to the failure of the aft field joint.] 4 While NASA argues that its personnel levels for these functions "were adequate,' l 5 5 the Rogers Commission found:

155

Reductions in safety, reliablility and quality assurance work force at Marshall and NASA Headquarters have seriously limited capability in those vital functions.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 5 6

Reductions were not limited to the safety and quality assurance program. The former Associate Administrator for Space Flight, Jesse Moore, testified that his office also experienced a decline in the number of staff. As Mr. Moore observed, "we need to . . . get as much technical expertise into the Office of Space Flight as we possibly can" in order to "work on a plane with the real experts- the contractors, the engineers, the safety people at the contractors and at the NASA centers. . ."1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 5 7

Similar views were voiced by former Shuttle program manager Robert Thompson:

I think we have to look pretty deep in our organization to make sure we are keeping enough technical muscle in the organization to continually search for these pending problems that are somtines pretty subtle. Sometimes they just don't, as I say, announce themselves. So you have to be willing to expend the resources and keep that technical muscle in place and you have to put that technical muscle close to the heart of the issue so that they can perceive a problem if it is just beginning to occur.'5*

It does not necessarily follow however, that reductions in the numbers of technical personnel automatically limit the ability of headquarters to identify and correct emerging problems. The adverse impact flows from those reductions that cut into crucial areas. Accordingly, the Committee is pleased that Admiral Truly has undertaken an examination "throughout the agency and particularly in . . . the Space Shuttle program" to make sure that 'we have not only the right numbers but the right kind of trained people .....1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 5 9 It is hoped that this analysis will identify appropriate technical staffing levels and positions that must be maintained if the agency is to properly perform its function.

NASA technical expertise is further reduced by the departure of highly skilled employees. During fiscal year 1985, approximately 1500 employees left the agency, over one-half of these (784) were engineers, technicians and scientists. If present trends continue,

166Rogers Commission Report, Volume I, p. 161.

156

NASA can expect to lose between 7500 and 9000 technical and scientific employees over the next ten years. While 50 percent of these personnel losses are formally attributed to retirement, NASA officials "know. . .that many retires leave NASA for higher paying jobs in industry." 162 Additionally, 17 percent of the departing employees acknowledge that they are leaving NASA for more finan- cially rewarding jobs. 63

NASA is concerned that the difficulty it will experience in re- placing these employees is essentially the same that led to the departures; the agency's "salary structure is not sufficiently flexible and competitive to attract the very best talent our nation has to offer." 6 4 Therefore, despite liberal hire authority for engineering positions, NASA is experiencing difficulty in recruiting entry-level engineers, largely due to salary. As noted by the Agency:

Currently the Government pays GS-7 recent college graduates in all engineering disciplines a special salary rate of $23,170. This is the statutory maximum under the current special salary rate provisions. At the same time, our private sector competitors are offering these graduates an average salary of $27,000 to $29,000 depending on the engineering discipline. It would take approximately a 20 percent increase for us to match our competitors. However, absent a legislative change, the most we could offer in the next year would be the percentage increase to the General Schedule (perhaps two or three percent in January 1987). A continuing infusion of recent college graduates is critical to the continued success of NASA's mission and accomplishing this has become increasingly difficult. Inadequate salaries are an equally significant problem at the executive levels in the agency.165

While outside witnesses did not fully concur as to the prevalence of departures for the private sector, all acknowledged the need to create incentives for qualit people to enter and remain with the agency.166 To this end, NAJA Administrator Fletcher is examining means by which his organimFn can retain its highly skilled technical employees through a more motivational type of organizational structure" and premium pay scheduled. l 6 7 The Committee shares NASA's concern that it maintain a strong in-house technical capability and support staff.

In addition to the number of technical managers, it is also necessary to examine their technical performance. Insight into NASA

18s Ibid.

166Cmte Hgs, Transcript, July 24, 1986, pp. 119-23 headquarters' technical ability to discern and react to emerging problems may be gained from an examination of the manner in which it addressed the growing concerns with the O-rings in the summer of 1985. Prior to that time the problems with the O-rings had been briefed at all levels of the agency and had been presented to headquarters on at least two occasions. 6 8 However, increasing problems with case-to-case erosion prompted headquarters to request a complete briefing "to go over the situation in detail."1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 6 9

The meeting was chaired by Mr. Moore's deputy for technical matters, L. Michael Weeks, and attended by a number of other headquarters personnel which Mr. Moore characterized as having "some knowledge about the SRB."170 In testimony before the Rogers Commission, Mr. Moore described the composition of the meeting:

Mr. Winterhalter, who was Shuttle Propulsion Division

Acting Director at that time, Mr. Bill Hamby was the STS program integration Deputy Director, Mr. Paul Wetzel, who was the Solid Rocket Booster programs chief, Mr. Paul Herr, who was the Solid Rocket Motor program manager, and Mr. Henry Quong, who was the reliability, maintainability and quality assurance director of the chief engineer's office.

Those were the group of people at NASA headquarters who attended the meeting. Mr. Mulloy of Marshall Space

Flight Center, who was a Solid Rocket Booster program manager, attended and Mr. Bob Swinghammer of Marshall also attended, who is the material and processes laboratory director at Marshall. Thiokol had a total of six people lsaSee,e.g., testimony of L. Michae; Weeks, Cmte Hgs, Transcript, June 12, 1986, p. 130; Rogers Commission Report, Volume I, pp. 120-140.

Rogers Commission Report, Volume V, 1051, testimony of Jesse Moore. A somewhat different version of the enesis of the August 1 briefing waa presented by Allen McDonald, Thio kol's Director of Solif Rocket Motor Project, in testimony before the Rogers Commission (Bid., pp. 1591-92):

Mr. MCDONALD. The meeting that occurred on August 19 came about aa a result of this problem with the nozzle eroding through, and that is what drove that meeting. Headquarters wanted to hear about that. We lost the runary seal and eroded some secondary.

We all sat down together a n i f o t together with the engineering people and put together that presentation and collective1 sai , you know, we ought to address the whole seal issue, not Just that failure, because we alf felt that if that ever happened in the field joint we were in bad trouble because the nozzle has a much better cyondary sea! than the +Id joint does.

Mr. Sumn. At this meeting on August 19th a t headquarters, that was called because of Thiokol's concern that the joint was reall in trouble?

Mr. MCD~NALD. No,, it was cald-we had had another meeting scheduled a t Washington headquarters a t that time that had a problem with the mixer fire earlier in the year, and there was a review of that.

I believe Mike Weeks either called Joe or I or one of us and said well, you're here, you ought to come and address a couple of other issues that have happened recently that we are very interested in.

One of them is we had broken the structural test article on the filament would case I believe in July down a t Marshall, and they wanted to hear about that.

The other one was they were made aware that we had violated the primary seal in the nozzle and wanted to hear about that and what our rationale waa to continue.

See also, Cmte Hgs, Transcri t, June 17, 1986, pp. 98-101.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 7 0 Cmte Hgs, Transcript, Juyy 24, 1986, p. 97.

158

there, including Mr. Mason, Mr. Wiggins, Mr. Kilminster, Mr. McDonald and Mr. Speas.171

The briefing documents prepared by ThiokoI included a detailed history of seal erosion which noted, inter alia, that the "frequency of O-ring damage has increased since incorporation of Randolph putty; higher stabilization pressures in leak test procedures; and high performance motors.'' The briefing documents also listed MTI's primary concerns; the highest concern was "Field joint- joint deflection and secondary O-ring resiliency."

It is suggested that the August 19th briefing failed to give a complete picture of the seriousness of the O-ring problem because it did not include data on the effect that temperature would have on resiliency of the seals. As Michael Weeks noted in his testimony before the Committee:

When the briefing was presented to us on August 19th of 1985-as you will look in the briefing that was provided to the Commission on February 10th-there was no temperature data presented that showed that the resiliency was such a critical factor. It wasn't until after the disaster of 51-L that I actually saw the resiliency data that showed that Viton, which is the O-ring material that we've been using, is so slow to recover at very low temperatures-lT2

Mr. Weeks correctly notes that the briefing documents did not include data which resulted from bench testing which concluded that resiliency is a function of temperature.

Other participants in the meeting felt that the temperature issue had been presented at the briefing.

General KUTYNA.Secondly, there has been some question that people understood that there was a temperature problem. I remember your conclusions chart, your file chart, and the very first bullet of that chart had the word "resiliency" in it. Do you feel when you talked about resiliency at that meeting people got the connection between resiliency and temperature, that resiliency was a function of temperature, or was that lost? Mr. MCDONALD.It may have gotten lost because we hadn't run a very long range of temperatures when we got that data. General KUTYNA.So it is possible that people at headquarters from that briefing did not understand temperature was a concern? Mr. MCDONALD. I guess it is possible they could have. General KUTYNA. Is it probable? Mr. MCDONALD. I don't know if it is probable, because we put it as the first bullet of why we thought that was

Rogers Commission Report, Volume V, pp. 1051-52.

159

our highest concern, and if that hadn't have happened, we wouldn't have had that concern.7 bid. 4

In evaluating the information presented at the August 19, 1985, briefing, the Rogers Commission found:

The O-ring erosion history presented to Level I at NASA headquarters in August 1985 was sufficiently detailed to require corrective action prior to the next flight. l

The current NASA administrator concurs in the finding.'?

Despite the clarity of the Commission's conclusions, none of the participants at this meeting (all with technical backgrounds)- NASA or Thiokol-recommended that the Shuttle be grounded until the problem with the seals was solved.178Rather, as noted above, the unanimous recommendation was to accelerate the efforts to fix the problem but continue flying. In adopting this course, did NASA take steps to seek a solution that was reasonably commensurate with a threatened failure of a criticality 1 item? Mr. 174 Rogers Commission Report, Volume V, pp. 1595-96.

Ibid., p. 1052. See also, Cmte Hgs, Transcript, June 12, 1986, pp. 143-44, and July 24, 1986,

  1. A conflict in the testimony arose on the question of the briefing Mr. Weeks provided Mr. boore following the August 19th meeting. Accordin to the testimony resented by Mr. Weeks, "I briefed on the results of that [meeting] and told t i m about the brieing and showed him the briefing [documents]." Ibid., June 12, 1986, p. 143. Mr. Moore disagreed with this recitation of the facts (Ibid., July 24, 1986, pp. 89-91):

Mr. SCHEUER. Are you telling us that you didn't receive a briefing from Mr. Weeks and that vou didn't receive the briefing documents from Mr. Weeks that waa eiven to headauarters bv

I I ihe Thiokol officials?

Mr. MOORE.To my recollection, the first time I remember seeing that document was on Aurmst-was on Januarv 29th or Januarv 30th. rieht after the Challeneer accident. I was shown a dkument which contkned the briefink materid. It also subsequently came up in one of the earlier discussions with Chairman Rogers and his Commission is the other time I have seen some of that.

Post-accident was the first time I had, to my knowledge, as I said, seen that particular briefing. I had not sat down and been given a briefing on the Thiokol presentation on August 19th.

Mr. Weeks verbally said that the meeting was held that day on August 19th and that in effect that he felt comfortable with the overall conclusions, although he did have one more concern. He felt he wanted to talk to somebody else a t Marshall and he did, I believe, talk to Mr. Hardy and said that he thought based on the data and also on the Titan success that in fact there was an acceptable position as far as he was concerned and that is where I left the information and that was the information I was given.

Mr. SCHEUER. He didn't indicate the kind of depth of concern that would have led you to believe that additional time was needed or that additional resources needed to apply to some of these problems before lunch?

Mr. MOORE.No sir. I did not get the feeling that we should have grounded the Shuttle fleet prior to the next flight as a result of that particular briefing.

In a subsequent interview with staff, Mr. Weeks recanted his earlier statement and acknowledged that he did not show Mr. Moore a copy of the briefing document and that to the best of his knowledge Mr. Moore did not see this document until after the Challenger accident. Moreover, Mr. Weeks stated that he did not tell Moore specifically that Morton Thiokol was calling for an accelerated pace to eliminate the seal erosion problem nor did he state that additional resources were needed to be committed to solve the problem.

176 Rogers Commission Report, Volume I, p. 148.

177 Cmte Hgs, Transcript, June 12, 1986, p. 129.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 7 8 Ibid., June 17, 1986, pp. 97-8, 101.

160

Moore, when asked what he would have done had he received the oral briefing and reviewed the briefing document responded:

I believe that looking at the document and looking a t some of the issues that were cited about criticality 1, flight safety issues and mission success issues that came out in the series of the document there, I believe we would have initiated a formal team to go off and take a much more concentrated look at it. So I believe my actions would have been to form a team of experts to asess this data and to make recommendations on what our course of action should be at this point in time.

Unfortunately this team of experts was not formed until after the Challenger accident. Rather, NASA proceeded on the course summarized in the following exchange between Chairman Roe and Michael Weeks:

Mr. ROE.Therefore, there are a group of people-whom- ever they were-that participated at this particular meeting, reviewed these facts that were available, and they determined two things, according to your testimony. One, they determined that if everything-if they had their "druthers," or whatever the case may be-it would take two years in their judgment to be able to correct that; but in spite of that decision they took and made the second judgement. And the second judgement, well, we can continue to fly. We'll start the mechanisms going to get this corrected, but we can continue to fly until we get that done. Isn't that the decision that was made, according to what you're saying? Mr. WEEKS.That is correct. Mr. ROE. Therefore, some people who were at that specific meeting had to be the people who made that specific decision.

In attempting to assess the reasons for NASA Level 1 managers not adopting a more aggressive posture to the O-ring problem, it is suggested that insufficient information was communicated to top.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 8 1 However, as Deputy Acting Administrator Graham observed:

They could have transmitted the information in a higher profile way, but also as engineers, as managers at headquarters, there was certainly a responsibility to perceive the significance of this.182

There was plainly a failure of NASA technical managers, and for that matter those at Thiokol, to grasp the seriousness of the problem. As former Shuttle Program Manager Robert Thompson observed:

'79 Ibid., July 24, 1986, pp. 91-2.

Ibid., June 12, 1986, p. 141.

181 The issue of whether communications are filtered so that important information is prevented from reaching decision-makers is addressed in Section VI.B.2.b.1 For the purpose of this report, a procedure is a formal set of instructions designed to guide and assist in the performance of a technical or management function. g8 mid., July 24, 1986, p. 11. 8 1 Cmte Hgs,Transcript, June 17, 1986, p. 207.

161

Sometimes these problems are very subtle. Sometimes they stand up and shout louder than at other times. Frankly, this time I think it was standing up and shouting pretty loudly.183

Why then did top technical managers in the Office of Space Flight at NASA Headquarters (Level I), Johnson Space Flight Center (Level II), and the Marshall Space Flight Center (Level 111) fail to take stronger action? (See VI. A.1.f.) The answer may be simply poor technical decision-making, perhaps in combination with a type of collective rationalization described by Larry Mulloy:

You asked why wasn't more done. You know, in the six years previous. And I have had that question posted to me many times in the last four months, and I have asked it of myself many times since the tragic accident. And my answer has been in hindsight, obviously, more should have been done. The turning, I think we started down a road where we had a design deficiency. When we recognized that it had design deficiency, we did not fix it. Then we continued to fly with it, and rationalized why it was safe, and eventually concluded and convinced ourselves that it was an acceptable risk. That was-when we started down that road, we started down the road to eventually having the inevitable accident. I believe that.lS4 d. Change Control Process

Issue 1

Has the pressure to maintain operational flight rates and schedules for the Shuttle compromised the hardware Change Control Process? Findings

  1. When NASA declared the Space Shuttle to be an operational system, additional pressure to increase flight rates impacted other aspects of the overall program such as the ability to implement, evaluate, test, and certify changes in hardware design.

  2. As a result of attempting to operate the Shuttle at increased flight rates, controlling other aspects of the program such as the flight production process and manifest also became a more complex and difficult aspect of program administration. Recommendations

  3. NASA must reconsider its efforts to categorize the Shuttle as an operational transportation system.

  4. The Configuration Management System designed to control such changes must be reexamined by NASA as to its effectiveness in assuring that all hardware changes take place in a safe and reliable fashion.

l a 3 Ibid., July 24, 1986, p. 117. I84Ibid., June 17, 1986, pp.215-16

162

Discussion

The Rogers Commission noted that, "Following successful completion of the orbital flight test phase of the Shuttle program, the system was declared to be operational."8 Ibid. Ibid. ' 0 bid. I 1bid. Morton Thiokol, "Program Plan, Protection of Space Shuttle SRM Primary Seals," TWR- 14359,May 4, 1984. s Ibid. Discussions with Allan McDonald and Carver Kennedy, Thiokol (Wasatch Operations), Brigham City, Utah,, September 4, 1986. 5 The Commission found that as a result, NASA reduced its safety, reliability and quality assurance activities related to the Shuttle. The Commission report goes on to note that this reasoning was faulty; "The machinery is highly complex, and the requirements are exacting. The Space Shuttle remains a totally new system with little or no history."

Program officials frequently find it necessary to consider changing existing hardware designs or production processes. Such changes can be required for a number of reasons, including: to correct the deficiency in a component; to improve a component's performance or the length of this operating life; to enhance the ease of maintaining the component; or to reduce the cost of manufacturing, servicing, or processing the component. Typically, change proposals originate from a manufacturer and are reviewed by the cognizant NASA field center and frequently by the Level I1 Program Office at the Johnson Space Center as well. In his review process, NASA compares the cost and schedule impacts of the proposed change against the performance improvement that is anticipated. Of particular concern are the safety aspects related to the change (e.g., What analyses and tests must be conducted to insure that the change does not directly or indirectly have a negative impact on the systems safety or reliability?).

It is clear that these activities or steps in the process of implementing essential changes are complex and time consuming, especially if the components to be evaluated are some of the larger and critical elements of the Space Shuttle. Therefore, it is the Committee's view that until such time as all elements of the Space Transportation System can be fully evaluated through extensive flight testing and trend analyses, it is premature to impose an operational flight schedule on the system in a manner comparable to that imposed upon, for example, an air transportation system. Issue 2

Is the change control process sufficiently defined for all elements of the Shuttle system? Findings

  1. The NSTS engineering and process change guidelines are, for the most part, sufficiently well-defined for the majority of the subsystems that comprise the Space Shuttle.

  2. NASA gives the same level of scrutiny to changes involving a minor component (such as moving Velcro strips in the Orbiter) as those involving mission critical elements of flight hardware. Recommendation

NASA should review its change control process to determine the usefulness of differentiating between minor changes and significant changes.

185 Rogers Commission &port, Volume I, p. 159.

163

Discussion

NASA's Change Control System is shown in Figure VI-4. From the chart, it is evident that the success of the system is highly dependent on the information flow among the various levels of management control.

1'11'111 13f i 31

  • I — 1

I 13P.31 I 1 13A31

I 1 1 1 13;5.31

165

The Configuration Management System Requirements are documented in JSC 07700 Volume 4, entitled "Configuration Management Requirements," dated March 2, 1973. Changes to this document have periodically been issued over the course of the program. The configuration management system defines requirements for all levels of management within the NSTS program. A baseline set of requirements is defined for each level of management (Level I through Level IV). This baseline establishes what is to be accomplished at each level of management and established the controlling procedures that supposedly prevent deviations from the baseline program. This baseline program is specified for each flight and includes specifications on payloads for each flight as well.

Changes to the flight and system requirements and the acceptance baselines are made, according to NASA, only by directives issued by the Program Requirements Control Board at Level I and Level I1 and the Change Control Boards. For example, there is an Orbiter Avionics Software Control Board (OASCB) that has joint Level I1 and Level I11 authority for managing the program-wide requirements for Shuttle computer hardware and software systems as part of the Orbiter project. The Board also assures the correct configuration of the software within the Orbiter avionics system for all vehicle and test operations.

Design changes at the contractor level are processed through several levels of technical and managerial reviews. Design and engineering changes on the Orbiter, for example, undergo Technical Status Reviews (TSR's), Avionics Status Reviews (ASR's), Preliminary Design Reviews (PDR's), Critical Design Reviews, (CDR's), Design Certification Reviews (DCR's), and numerous special meetings of NASA and the Rockwell management are utilized to review issues and concerns about any design drawing or specification. According to Rockwell,1s6 "Changes are reviewed at a TSR or ASR and the Change Control Board for approval. Any outstanding design dispute is tracked as an open action until it is resolved by Rockwell and NASA management."

The Committee questions, however, whether the complex and extensive processes involved in NASA's change control management system allow for sufficient distinction between minor changes and the significant changes. For example, the systems requires the same level of management attention to as minor a change as moving Velcro strips on the Orbiter as it is applied to all Criticality 1 item such as changing a turbo-pump on the SSME.