12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ADM:SG2.SP2 Analyze Asset-Service DependenciesInstances where assets support more than one service areidentified and analyzed.Because services traverse the organization, and because there are sharedassets and resources that many services depend upon, it is important toidentify these dependencies to ensure that they are addressed during thedevelopment of resilience requirements and in the development ofstrategies to protect and sustain assets and their related services.When dependencies result in a shared environment for an asset,consideration must be given to the effects that this situation will have on thesatisfaction of resilience requirements at the service level. For example, ifresilience requirements are set for a facility and more than one service isperformed in that facility, the requirements for protecting and sustaining thefacility must be sufficient to meet the needs of both services that share thefacility. By identifying these potential conflicts early, an organization canactively mitigate them (by revising requirements or other actions) beforethey become an exposure that affects the operational resilience of theaffected services.Typical work products1. List of potential conflicts due to asset dependencies2. Mitigation actions and resolutionsSubpractices1. Identify asset dependencies and potential conflicts.2. Develop mitigation plans to reduce the effects of dependencies thatcould affect the operational resilience of associated services.3. Implement actions to reduce or eliminate conflict.This practice may require the organization to revisit existing resilience requirementsand revise them where necessary. It may also necessitate changes in currentstrategies for protecting and sustaining existing assets. Refer to the <strong>Resilience</strong>Requirements <strong>Management</strong> process area for more information about managingchange to resilience requirements. Refer to the Controls <strong>Management</strong> and the ServiceContinuity process areas for managing changes to strategies for protecting andsustaining services and their supporting assets.ADM:SG3 Manage AssetsThe life cycle of assets is managed.Changes to high-value assets may require commensurate changes in resiliencerequirements and the strategies that organizations deploy to ensure that these assetsare adequately protected and sustained. In fact, managing changes to the operationalenvironment (i.e., through keeping accurate inventories of assets and services and theirrequirements) is an essential activity for managing and controlling operational resilience.The organization must actively monitor for changes that significantly alter assets,identify new assets, or call for the retirement of assets for which there is no longer aneed or whose relative value has been reduced. The objective of this goal is to ensure89 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!