12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ENTERPRISE FOCUSEnterprisePurposeThe purpose of Enterprise Focus is to establish sponsorship, strategic planning, andgovernance over the operational resilience management process.Introductory NotesManaging operational resilience requires a vast array of skills and competencies. Theseskills and competencies traverse the organization and must converge to achieve and sustaina desired level of operational resilience.Because resilience is an enterprise concern, the focus and direction for the operationalresilience management process must come from the top: leadership to set direction andethical standards, sponsorship to provide support and resources, and governance to ensurethat the process is achieving its goals as expected. In addition, managing operationalresilience must be aligned with and supportive of the achievement of the organization’sstrategic objectives. Focusing on these objectives provides the rationale for investing inresilience activities—because they enable the organization to achieve its mission.The Enterprise Focus process area seeks to ensure that the enterprise owns the operationalresilience management process and provides the necessary level of leadership andgovernance over the process. The strategic objectives of the organization are explicitlydefined as the alignment factor for resilience plans, programs, and activities. Higher levelmanagers provide sponsorship to ensure resilience activities are properly and adequatelyfunded and to promote and nurture a resilience-aware culture throughout the organization.Finally, the organization’s governance activities are expanded to focus directly onresilience—program objectives are set, standards for acceptable and ethical behavior areestablished, and the process is monitored to ensure it is achieving its goals. Higher levelmanagers also provide input and recommendations when the operational resiliencemanagement process is not performing within established standards.Enterprise Focus establishes the “critical few” for the organization—the high-value servicesthat must be resilient to ensure mission achievement. This sets the focus for all operationalrisk-based activities in the organization. Through an enterprise focus, the direction and targetfor operational resilience management is established, operational risk management activitiesare coordinated, and actions are taken that enable the organization to perform adequately inachieving its targets.Related Process AreasOrganizational risk drivers, risk appetite, and risk tolerance are established in the Risk<strong>Management</strong> process area.The establishment of plans and programs to ensure service continuity is addressed in theService Continuity process area.122 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!