Columbia Accident Investigation Board Report, Volume I

10.2 CREW ESCAPE AND SURVIVAL

10.2 CREW ESCAPE AND SURVIVAL

The Board has examined crew escape systems in historical context with a view to future improvements. It is important to note at the outset that Columbia broke up during a phase of flight that, given the current design of the Orbiter, offered no possibility of crew survival.

The goal of every Shuttle mission is the safe return of the crew. An escape system—a means for the crew to leave a vehicle in distress during some or all of its flight phases and return safely to Earth – has historically been viewed as one "technique" to accomplish that end. Other methods include various abort modes, rescue, and the creation of a safe haven (a location where crew members could remain unharmed if they are unable to return to Earth aboard a damaged Shuttle).

215

While crew escape systems have been discussed and studied continuously since the Shuttleʼs early design phases, only two systems have been incorporated: one for the developmental test flights, and the current system installed after the Challenger accident. Both designs have extremely limited capabilities, and neither has ever been used during a mission.

Developmental Test Flights

Early studies assumed that the Space Shuttle would be operational in every sense of the word. As a result, much like commercial airliners, a Shuttle crew escape system was considered unnecessary. NASA adopted requirements for rapid emergency egress of the crew in early Shuttle test flights. Modified SR-71 ejection seats for the two pilot positions were installed on the Orbiter test vehicle Enterprise, which was carried to an altitude of 25,000 feet by a Boeing 747 Shuttle Carrier Aircraft during the Approach and Landing Tests in 1977.19

Essentially the same system was installed on Columbia and used for the four Orbital Test Flights during 1981-82. While this system was designed for use during first-stage ascent and in gliding flight below 100,000 feet, considerable doubt emerged about the survivability of an ejection that would expose crew members to the Solid Rocket Booster exhaust plume. Regardless, NASA declared the developmental test flight phase complete after STS-4, Columbiaʼs fourth flight, and the ejection seat system was deactivated. Its associated hardware was removed during modification after STS-9. All Space Shuttle missions after STS-4 were conducted with crews of four or more, and no escape system was installed until after the loss of Challenger in 1986.

Before the Challenger accident, the question of crew survival was not considered independently from the possibility of catastrophic Shuttle damage. In short, NASA believed if the Orbiter could be saved, then the crew would be safe. Perceived limits of the use of escape systems, along with their cost, engineering complexity, and weight/payload tradeoffs, dissuaded NASA from implementing a crew escape plan. Instead, the agency focused on preventing the loss of a Shuttle as the sole means for assuring crew survival.

Post-Challenger: the Current System

NASAʼs rejection of a crew escape system was severely criticized after the loss of Challenger. The Rogers Commission addressed the topic in a recommendation that combined the issues of launch abort and crew escape:20

Launch Abort and Crew Escape. The Shuttle Program management considered first-stage abort options and crew escape options several times during the history of the program, but because of limited utility, technical

infeasibility, or program cost and schedule, no systems were implemented. The Commission recommends that NASA:

  • Make all efforts to provide a crew escape system for use during controlled gliding flight.
  • Make every effort to increase the range of flight conditions under which an emergency runway landing can be successfully conducted in the event that two or three main engines fail early in ascent.

In response to this recommendation, NASA developed the current "pole bailout" system for use during controlled, sub- sonic gliding flight (see Figure 10.2-1). The system requires crew members to "vent" the cabin at 40,000 feet (to equalize the cabin pressure with the pressure at that altitude), jettison the hatch at approximately 32,000 feet, and then jump out of the vehicle (the pole allows crew members to avoid striking the Orbiterʼs wings).

Figure 10.2-1. A demonstration of the pole bailout system. The pole is extending from the side of a C-141 simulating the Orbiter, with a crew member sliding down the pole so that he would fall clear of the Orbiterʼs wing during an actual bailout.

Current Human-Rating Requirements

In June 1998, Johnson Space Center issued new Human- Rating Requirements applicable to "all future human-rated spacecraft operated by NASA." In July 2003, shortly before this report was published, NASA issued further Human-Rating Requirements and Guidelines for Space Flight Systems, over the signature of the Associate Administrator for Safety and Mission Assurance. While these new requirements "… shall not supersede more stringent requirements imposed by individual NASA organizations …" NASA has informed the Board that the earlier – and in some cases more prescriptive – Johnson Space Center requirements have been cancelled.

216

NASAʼs 2003 Human-Rating Requirements and Guidelines for Space Flight Systems laid out the following principles regarding crew escape and survival:

2.5.4 Crew survival

2.5.4.1 As part of the design process, program management (with approval from the CHMO [Chief Health and Medical Officer], AA for OSF [Associate Administrator for the Office of Spaceflight ], and AA for SMA [Associate Administrator for Safety and Mission Assurance] shall establish, assess, and document the program requirements for an acceptable life cycle cumulative probability of safe crew and passenger return. This probability requirement can be satisfied through the use of all available mechanisms including nominal mission completion, abort, safe haven, or crew escape.

2.5.4.2 The cumulative probability of safe crew and passenger return shall address all missions planned for the life of the program, not just a single space flight system for a single mission.

The overall probability of crew and passenger survival must meet the minimum program requirements (as defined in section 2.5.4.1) for the stated life of a space flight systems program.21 This approach is required to reflect the different technical challenges and levels of operational risk exposure on various types of missions. For example, low-Earth-orbit missions represent fundamentally different risks than does the first mission to Mars. Single-mission risk on the order of 0.99 for a beyond-Earth-orbit mission may be acceptable, but considerably better performance, on the order of 0.9999, is expected for a reusable low-Earth-orbit design that will make 100 or more flights.

2.6 Abort and Crew Escape

2.6.1 The capability for rapid crew and occupant egress shall be provided during all pre-launch activities.

2.6.2 The capability for crew and occupant survival and recovery shall be provided on ascent using a combination of abort and escape.

2.6.3 The capability for crew and occupant survival and recovery shall be provided during all other phases of flight (including on-orbit, reentry, and landing) using a combination of abort and escape, unless comprehensive safety and reliability analyses indicate that abort and escape capability is not required to meet crew survival requirements.

2.6.4 Determinations regarding escape and abort shall be made based upon comprehensive safety and reliability analyses across all mission profiles.

These new requirements focus on general crew survival rather than on particular crew escape systems. This provides a logical context for discussions of tradeoffs that will yield the best crew-survival outcome. Such tradeoffs include "mass-trades" – for example, an escape system could add weight to a vehicle, but in the process cause payload changes that require additional missions, thereby inherently increasing the overall exposure to risk.

Note that the new requirements for crew escape appear less prescriptive than Johnson Space Center Requirement 7, which deals with "safe crew extraction" from pre-launch to landing.22

In addition, the extent to which NASAʼs 2003 requirements will retroactively apply to the Space Shuttle is an open question:

The Governing Program Management Council (GPMC) will determine the applicability of this document to programs and projects in existence (e.g., heritage expendable and reusable launch vehicles and evolved expendable launch vehicles), at or beyond implementation, at the time of the issuance of this document.

Recommendations of the NASA Aerospace Safety Advisory Panel

The issue of crew escape has long been a matter of concern to NASAʼs Aerospace Safety Advisory Panel. In its 2002 Annual Report, the panel noted that NASA Program Guidelines on Human Rating require escape systems for all flight vehicles, but the guidelines do not apply to the Space Shuttle. The Panel considered it appropriate, in view of the Shuttleʼs proposed life extension, to consider upgrading the vehicle to comply with the guidelines.23

Recommendation 02-9: Complete the ongoing studies of crew escape design options. Either document the reasons for not implementing the NASA Program Guidelines on Human Rating or expedite the deployment of such capabilities.

The Board shares the concern of the NASA Aerospace Safety Advisory Panel and others over the lack of a crew escape system for the Space Shuttle that could cover the widest possible range of flight regimes and emergencies. At the same time, a crew escape system is just one element to be optimized for crew survival. Crucial tradeoffs in risk, complexity, weight, and operational utility must be made when considering a Shuttle escape system. Designs for future vehicles and possible retrofits should be evaluated in this context. The sole objective must be the highest probability of a crewʼs safe return regardless if that is due to successful mission completions, vehicle-intact aborts, safe haven/rescues, escape systems, or some combination of these scenarios.

217

Finally, a crew escape system cannot be considered separately from the issues of Shuttle retirement/replacement, separation of cargo from crew in future vehicles, and other considerations in the development – and the inherent risks of space flight.

Space flight is an inherently dangerous undertaking, and will remain so for the foreseeable future. While all efforts must be taken to minimize its risks, the White House, Congress, and the American public must acknowledge these dangers and be prepared to accept their consequences.

Observations:

O10.2-1 Future crewed-vehicle requirements should in-

corporate the knowledge gained from the Challenger and Columbia accidents in assessing the feasibility of vehicles that could ensure crew survival even if the vehicle is destroyed.

10.3 SHUTTLE ENGINEERING DRAWINGS AND CLOSEOUT PHOTOGRAPHS

In the years since the Shuttle was designed, NASA has not updated its engineering drawings or converted to computer-aided drafting systems. The Boardʼs review of these engineering drawings revealed numerous inaccuracies. In particular, the drawings do not incorporate many engineering changes made in the last two decades. Equally troubling was the difficulty in obtaining these drawings: it took up to four weeks to receive them, and, though some photographs were available as a short-term substitute, closeout photos took up to six weeks to obtain. (Closeout photos are pictures taken of Shuttle areas before they are sealed off for flight.) The Aerospace Safety Advisory Panel noted similar difficulties in its 2001 and 2002 reports.

The Board believes that the Shuttleʼs current engineering drawing system is inadequate for another 20 yearsʼ use. Widespread inaccuracies, unincorporated engineering updates, and significant delays in this system represent a significant dilemma for NASA in the event of an on-orbit crisis that requires timely and accurate engineering information. The dangers of an inaccurate and inaccessible drawing system are exacerbated by the apparent lack of readily available closeout photographs as interim replacements (see Appendix D.15).

Findings:

F10.3-1 The engineering drawing system contains out-

dated information and is paper-based rather than computer-aided.

F10.3-2 The current drawing system cannot quickly

portray Shuttle sub-systems for on-orbit troubleshooting.

F10.3-3 NASA normally uses closeout photographs but

lacks a clear system to define which critical sub-systems should have such photographs. The

trieval of closeout photos.

Recommendations:

R10.3-1 Develop an interim program of closeout pho-

tographs for all critical sub-systems that differ from engineering drawings. Digitize the closeout photograph system so that images are immediately available for on-orbit troubleshooting.

R10.3-2 Provide adequate resources for a long-term pro-

gram to upgrade the Shuttle engineering drawing system including:

  • Reviewing drawings for accuracy
  • Converting all drawings to a computer-aided drafting system
  • Incorporating engineering changes

10.4 INDUSTRIAL SAFETY AND QUALITY ASSURANCE

The industrial safety programs in place at NASA and its contractors are robust and in good health. However, the scope and depth of NASAʼs maintenance and quality assurance programs are troublesome. Though unrelated to the Columbia accident, the major deficiencies in these programs uncovered by the Board could potentially contribute to a future accident.

Industrial Safety

Industrial safety programs at NASA and its contractors— covering safety measures "on the shop floor" and in the workplace – were examined by interviews, observations, and reviews. Vibrant industrial safety programs were found in every area examined, reflecting a common interview comment: "If anything, we go overboard on safety." Industrial safety programs are highly visible: they are nearly always a topic of work center meetings and are represented by numerous safety campaigns and posters (see Figure 10.4-1).

Figure 10.4-1. Safety posters at NASA and contractor facilities.

current system does not allow the immediate re-Initiatives like Michoudʼs "This is Stupid" program and the United Space Allianceʼs "Time Out" cards empower employees to halt any operation under way if they believe industrial safety is being compromised (see Figure 10.4-2). For example, the Time Out program encourages and even rewards workers who report suspected safety problems to management.

218

ASSERTIVE STATEMENT

OPENING Get person's attention.

CONCERN State level of concern.

Uneasy? Very worried?

PROBLEM State the problem, real or perceived.

SOLUTION State your suggested solution, if you have one.

AGREEMENT Assertively, respectfully

ask for their response. For example: What do you

think? Don't you agree? EVERY EMPLOYEE

When all else fails, use "THIS IS STUPID!" to