12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ADM:GG3.GP2 Collect Improvement InformationCollect asset definition and management work products,measures, measurement results, and improvement informationderived from planning and performing the process to supportfuture use and improvement of the organization’s processes andprocess assets.Elaboration:These are examples of improvement work products and information:asset inventoryconflicts arising from asset-service relationshipsmetrics and measurements of the viability of the process (refer to ADM:GG2.GP8subpractice 2)changes and trends in operating conditions, risk conditions, and the risk environmentthat affect process resultslessons learned in post-event review of incidents and disruptions in continuityprocess lessons learned that can be applied to improve operational resiliencemanagement performance, such as poorly documented or profiled assets anddifficulties in assigning and executing asset ownership and custodianshipresponsibilitiesthe level to which the asset inventory, asset profiles, and the asset database reflect thecurrent status of all assetsreports on controls effectiveness and weaknesses, including issues related to changecontrol on the asset inventoryasset-service dependency mitigation plans that are not executed and the risksassociated with themresilience requirements that are not being satisfied or are being exceededEstablishing the measurement repository and process asset library isaddressed in the Organizational Process Definition process area. Updatingthe measurement repository and process asset library as part of processimprovement and deployment is addressed in the Organizational ProcessFocus process area.Subpractices1. Store process and work product measures in the organization’smeasurement repository.2. Submit documentation for inclusion in the organization’s process assetlibrary.3. Document lessons learned from the process for inclusion in theorganization’s process asset library.4. Propose improvements to the organizational process assets.105 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!