12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Measurement and analysis activities are often most effective when focused at theorganizational unit or line of business level. Since operational resilience management is anenterprise-wide concern, however, it’s important for the enterprise to have mechanisms inplace to make use of that local data at the enterprise level, particularly as the enterprisematures. Repositories for measurement data at the organizational unit or line of businesslevel will be purposeful for local optimization, but as data is shared across organizationalunits for the overall improvement benefit of the enterprise, measurement repositories mayalso be needed at the enterprise level.Related Process AreasMeasurement and analysis needs are informed by the organization’s governance activities,which are addressed in the Enterprise Focus process area.Some of the data specified for Measurement and Analysis may be gathered and distributedthrough processes described in the Monitoring process area.Measurements may be necessary as evidence of compliance; compliance requirements areaddressed in the Compliance process area.Summary of Specific Goals and PracticesGoalsMA:SG1 Align Measurement and AnalysisActivitiesMA:SG2 Provide Measurement ResultsPracticesMA:SG1.SP1 Establish Measurement ObjectivesMA:SG1.SP2 Specify MeasuresMA:SG1.SP3 Specify Data Collection and Storage ProceduresMA:SG1.SP4 Specify Analysis ProceduresMA:SG2.SP1 Collect Measurement DataMA:SG2.SP2 Analyze Measurement DataMA:SG2.SP3 Store Data and ResultsMA:SG2.SP4 Communicate ResultsSpecific Practices by GoalMA:SG1 Align Measurement and Analysis ActivitiesMeasurement objectives and activities are aligned with identified informationneeds and objectives.MA:SG1.SP1 Establish Measurement ObjectivesMeasurement objectives are established and maintained based oninformation needs and objectives.MA:SG1.SP2 Specify MeasuresThe measures necessary to meet measurement objectives areestablished.MA:SG1.SP3 Specify Data Collection and Storage ProceduresThe techniques for collecting and storing measurement data arespecified.150 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!