12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PEOPLE MANAGEMENTOperationsPurposeThe purpose of People <strong>Management</strong> is to establish and manage the contributions andavailability of people to support the resilient operation of organizational services.Introductory NotesPeople are an essential asset in the organization’s ability to produce products and deliverservices in the pursuit of strategic objectives. Without people and their skills, knowledge,information, and other valuable traits, many business processes could not operate effectivelyand the mission of organizational services would be in jeopardy.The People <strong>Management</strong> process area focuses specifically on the “people” asset and theirrole in supporting the operation of business processes and services. Unlike information,technology, and facilities, the primary resilience requirement for people is availability—theavailability of people to perform their roles and responsibilities in supporting organizationalservices as intended and when necessary. Events that disrupt the contributions of peopleaffect the successful outcome of business processes and services and may impede theorganization’s mission. Even in highly automated operating environments where people havediminished roles, the unavailability of people may render services unable to meet theirmissions.To properly manage people and their contributions to services, the organization mustaddress several key aspects of resilience. It mustidentify the vital people in the organization, based on their roles and responsibilitiesidentify and manage risks that would interrupt or disrupt the contributions of people ormake people unavailable to perform their roles and responsibilitiesmanage the processes that ensure continued availability of people or that provide forappropriate substitutions and replacements when necessary manage the availability of people during and after disruptive events and other times ofstressWhile there is an assumption that people who support organizational services are typicallyemployed directly by the organization, there are many cases where they are acquiredthrough outsourcing and supplier relationships or may be otherwise external to theorganization. These external staff are included in the scope of the People <strong>Management</strong>process area because their availability could affect the successful operation of businessprocesses and services. Therefore, the “staff” referred to in this process area can beunderstood to include both internal and external parties. In addition, the availability of peoplealso extends to staff who are deployed in vital resilience roles in disciplines such as security,business continuity and disaster recovery, first response, and IT operations management.The People <strong>Management</strong> process area considers the effects on the organization due tointerruptions and disruptions that affect the performance and availability of people. Thus,considerations such as cross-training of staff and succession planning are included to ensure164 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!