12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ORGANIZATIONAL PROCESS FOCUSProcessPurposeThe purpose of Organizational Process Focus (OPF) is to plan, implement, and deployorganizational process improvements based on a thorough understanding of currentstrengths and weaknesses of the organization’s operational resilience processes andprocess assets.Introductory NotesThe organization’s processes include all operational resilience processes used by theorganization and its organizational units. Candidate improvements to the organization’sprocesses and process assets are obtained from various sources, including themeasurement of processes, lessons learned in implementing processes, results of processappraisals, results of post-event or incident handling, results of customer satisfactionevaluation, results of benchmarking against other organizations’ processes, andrecommendations from other improvement initiatives in the organization.Process improvement occurs in the context of the organization’s needs and is used toaddress the organization’s objectives. The organization encourages participation in processimprovement activities by those who perform the process. The responsibility for facilitatingand managing the organization’s process improvement activities, including coordinating theparticipation of others, is typically assigned to an operational resilience process group. Theorganization provides the long-term commitment and resources required to sponsor thisgroup and to ensure the effective and timely deployment of improvements.Careful planning is required to ensure that process improvement efforts across theorganization are adequately managed and implemented. Results of the organization’sprocess improvement planning are documented in a process improvement plan.The “organization’s process improvement plan” addresses appraisal planning, process actionplanning, pilot planning, and deployment planning. Appraisal plans describe the appraisaltimeline and schedule, the scope of the appraisal, resources required to perform theappraisal, the reference model against which the appraisal will be performed, and logisticsfor the appraisal.Process action plans usually result from appraisals and document how improvementstargeting weaknesses uncovered by an appraisal will be implemented. Sometimes theimprovement described in the process action plan should be tested on a small group beforedeploying it across the organization. In these cases, a pilot plan is generated.When the improvement is to be deployed, a deployment plan is created. This plan describeswhen and how the improvement will be deployed across the organization.Organizational process assets are used to describe, implement, and improve theorganization’s processes. (See the definition of “organizational process assets” in theglossary.)157 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!