12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

COMP:SG2 Establish Compliance ObligationsThe organization’s compliance obligations are identified, documented, andcommunicated.COMP:SG2.SP1 Identify Compliance ObligationsCompliance obligations are identified and documented.COMP:SG2.SP2 Analyze ObligationsCompliance obligations are analyzed and organized to facilitatesatisfaction.COMP:SG2.SP3 Establish Ownership for Meeting ObligationsThe responsibility for satisfying compliance obligations isestablished.COMP:SG3 Demonstrate Satisfaction of Compliance ObligationsThe organization demonstrates that its compliance obligations are beingsatisfied.COMP:SG3.SP1 Collect and Validate Compliance DataData required to satisfy compliance obligations is collected andvalidated.COMP:SG3.SP2 Demonstrate the Extent of Compliance Obligation SatisfactionThe extent to which compliance obligations are satisfied isdemonstrated through compliance activities.COMP:SG3.SP3 Remediate Areas of Non-ComplianceCOMP:SG4 Monitor Compliance ActivitiesRemediation of areas of non-compliance is performed to ensuresatisfaction of compliance obligations.The organization’s satisfaction of compliance obligations is monitored andadjusted as necessary.COMP:SG4.SP1 Evaluate Compliance ActivitiesSatisfaction of the organization’s compliance obligations isindependently monitored and improved.114 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!