12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Subpractices1. Establish governance over process activities.Elaboration:Governance over the asset definition and management process may be exhibited by developing and publicizing higher level managers’ objectives and requirements sponsoring policies, procedures, standards, and guidelines, including thedocumentation of assets and for establishing asset ownership and custodianship making higher level managers aware of applicable compliance obligations relatedto the process, and regularly reporting on the organization’s satisfaction of theseobligations to higher level managers sponsoring and funding process activities aligning asset inventory, asset ownership, and asset-service relationship activitieswith identified resilience needs and objectives and stakeholder needs andrequirements sponsoring the development, documentation, and management of assetinventories verifying that the process supports strategic resilience objectives and is focused onthe assets and services that are of the highest relative value in meeting strategicobjectives regular reporting from organizational units to higher level managers on processactivities and results creating dedicated higher level management feedback loops on decisions aboutthe process and recommendations for improving the process providing input on identifying, assessing, and managing operational risks to assets,including guidance for resolving asset inventory inconsistencies and otheranomalies conducting regular internal and external audits and related reporting to auditcommittees on process effectiveness creating formal programs to measure the effectiveness of process activities, andreporting these measurements to higher level managers93 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!