12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RISK:SG2 Establish Risk Parameters and FocusRisk tolerances are identified and documented and the focus of riskmanagement activities is established.RISK:SG3 Identify RiskRISK:SG4 Analyze RiskRISK:SG2.SP1 Define Risk ParametersThe organization’s risk parameters are defined.RISK:SG2.SP2 Establish Risk Measurement CriteriaCriteria for measuring the organizational impact of realized risk areestablished.Operational risks are identified.RISK:SG3.SP1 Identify Asset-Level RisksOperational risks that affect assets that support services areidentified.RISK:SG3.SP2 Identify Service-Level RisksOperational risks that potentially affect services as a result of assetrisk are identified.Risks are analyzed to determine priority and importance.RISK:SG4.SP1 Evaluate RiskRisks are evaluated against risk tolerances and criteria, and thepotential impact of risk is characterized.RISK:SG4.SP2 Categorize and Prioritize RiskRisks are categorized and prioritized relative to risk parameters,and risks that need to be mitigated are identified.RISK:SG4.SP3 Assign Risk DispositionRISK:SG5 Mitigate and Control RiskThe disposition of each identified risk is documented andapproved.Risks to assets and services are mitigated and controlled to preventdisruption of operational resilience.RISK:SG5.SP1 Develop Risk Mitigation PlansRisk mitigation plans are developed.169 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!