12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

equirement is “all health-related information that is covered by HIPAA regulations mustbe kept confidential to health workers and patients.”Service. Service requirements establish the resilience needs of a service in pursuit of itsmission. But because the capability of a service to meet its mission is directly related tothe resilience of the assets that support the service, service requirements must reflectand be congruent with the operational resilience requirements of supporting assets.Service requirements tend to concentrate on the service’s availability and recoverability,but these quality attributes can be directly affected by failure to meet the confidentiality,integrity, and availability requirements of people, information, technology, and facilities.Asset. Asset-specific requirements are set by the owners of the asset and are intendedto establish the needs for protecting and sustaining an asset with respect to its role insupporting mission assurance of a service. In practice, asset-specific resiliencerequirements generally reflect the security objectives of confidentiality and integrity andthe continuity requirement of availability. It must be considered that assets also mayhave conflicting requirements, particularly where they are deployed in supporting morethan one service (e.g., a network server may support more than service). This conflictmust be resolved to ensure that all services that are dependent on the asset areprovided the necessary level of resilience to meet their mission.The applicability of a specific type of resilience requirement varies depending on the assettype, as shown in Table 1.Table 1: Extension of resilience requirements to all types of resilience assets<strong>Resilience</strong>RequirementAsset TypePeople Information Technology FacilitiesConfidentiality -- x -- --Integrity -- x x xAvailability x x x xThere are many ways in which an organization can elicit resilience requirements. Strategicplanning efforts may establish enterprise-level requirements, as would direct interviewing ofvital organizational managers. Service-level requirements may be established by owners ofthe service (e.g., an organizational unit or a line of business). Asset-level requirements maybe established through regular security risk assessment and business impact analysisactivities and through directly interviewing the owners of the assets, who understand theirimportance to services and are responsible for their productivity and resilience.All resilience requirements must be analyzed for conflicts and interdependencies and mustbe validated against and support the accomplishment of enterprise-level organizationaldrivers (goals, objectives, and critical success factors). Otherwise, the protection andcontinuity strategies developed and implemented for assets and services will not align withwhat the organization needs to accomplish in order to remain viable.The development of resilience requirements typically includes the following activities:identifying organizational drivers and preparing these work products so that they can beused as the foundation for setting resilience requirementsdeveloping and communicating enterprise-level requirementsdeveloping and communicating service and asset-level requirements172 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!