12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2. Fund the process.Elaboration:Considerations for funding the asset definition and management process shouldextend beyond the initial development of the asset inventory to the maintenance of theinventory. Initial costs may be higher if the organization does not have a formal orusable asset baseline to serve as a foundation.Refer to the Financial Resource <strong>Management</strong> process area forinformation about budgeting for, funding, and accounting for servicecontinuity.3. Provide necessary tools, techniques, and methods to perform theprocess.Elaboration:Developing and maintaining the asset inventory may require tools, techniques, andmethods that allow for asset documentation and profiling, reporting, and updating on aregular basis. The need for these tools may be greater if the asset inventory isdeveloped across many organizational units and must be aggregated at the enterpriselevel. Tools should provide for proper and secure change control over the assetdatabase and should limit access to the asset baseline. The asset inventory databaseshould be searchable and expandable to include additional information such asdocumentation of associated services and the asset’s resilience requirements.These are examples of tools, techniques, and methods for asset definition andmanagement: methods for identifying high-value assets methods, techniques, and tools for creating asset profiles and baselines methods and tools for aggregating local asset inventories into an enterpriseinventory asset inventory database management system methods, techniques, and tools for asset inventory change management andcontrolADM:GG2.GP4 Assign ResponsibilityAssign responsibility and authority for performing the assetdefinition and management process, developing the workproducts, and providing the services of the process.Elaboration:Specific practice ADM:SG1.SP2 describes the use of human resourcesdatabases to identify roles of vital staff to aid in determining high-valuepeople assets. Specific practice ADM:SG1.SP2 calls for describing rolesrather than actual persons that perform the role. Specific practiceADM:SG3.SP1 discusses the effects of changes in roles. Thesedescriptions of roles specific to the definition and management of highvaluepeople assets should not be confused with assigning the roles,responsibilities, and authorities necessary to perform the asset definitionand management process.96 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!