12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Related Process AreasThe identification of vulnerabilities that may pose risk to the organization is performed in theVulnerability Analysis and Resolution process area.The development and implementation of control strategies to mitigate risk is performed in theControls <strong>Management</strong> process area.The development, testing, and implementation of service continuity plans to address theconsequences of realized risk is performed in the Service Continuity process area.Summary of Specific Goals and PracticesGoalsRISK:SG1 Prepare for Risk <strong>Management</strong>RISK:SG2 Establish Risk Parameters and FocusRISK:SG3 Identify RiskRISK:SG4 Analyze RiskRISK:SG5 Mitigate and Control RiskRISK:SG6 Use Risk Information to Manage<strong>Resilience</strong>PracticesRISK:SG1.SP1 Determine Risk Sources and CategoriesRISK:SG1.SP2 Establish an Operational Risk <strong>Management</strong>StrategyRISK:SG2.SP1 Define Risk ParametersRISK:SG2.SP2 Establish Risk Measurement CriteriaRISK:SG3.SP1 Identify Asset-Level RisksRISK:SG3.SP2 Identify Service-Level RisksRISK:SG4.SP1 Evaluate RiskRISK:SG4.SP2 Categorize and Prioritize RiskRISK:SG4.SP3 Assign Risk DispositionRISK:SG5.SP1 Develop Risk Mitigation PlansRISK:SG5.SP2 Implement Risk StrategiesRISK:SG6.SP1 Review and Adjust Strategies to Protect Assetsand ServicesRISK:SG6.SP2 Review and Adjust Strategies to SustainServicesSpecific Practices by GoalRISK:SG1 Prepare for Risk <strong>Management</strong>Preparation for risk management is performed.RISK:SG1.SP1 Determine Risk Sources and CategoriesThe sources of risk to assets and services are identified and thecategories of risk that are relevant to the organization aredetermined.RISK:SG1.SP2 Establish an Operational Risk <strong>Management</strong> StrategyA strategy for managing operational risk relative to strategicobjectives is established and maintained.168 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!