12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

egularly analyzing the requirements to ensure alignment with current organizationaldrivers, to identify conflict between enterprise and asset-level requirements, and tosatisfy operational constraintsvalidating the requirements against organizational drivers and operational constraintsThe <strong>Resilience</strong> Requirements Development process area has three specific goals:1. The Identify Enterprise Requirements goal addresses the development of enterpriselevelrequirements that potentially affect all services and assets.2. The Develop Service Requirements goal addresses the development of service-levelrequirements through the identification of asset requirements and the assignment ofenterprise requirements to services.3. The Analyze and Validate Requirements goal addresses the analysis of service-levelrequirements to ensure that they support strategic drivers and the resolution of conflictingrequirements.The goals of the <strong>Resilience</strong> Requirements Development process area are supported andmanaged long term by achievement of the goals in the <strong>Resilience</strong> Requirements<strong>Management</strong> process area.Related Process AreasThe identification of high-value assets and the assignment of resilience requirements toassets and services are performed in the Asset Definition and <strong>Management</strong> process area.The identification of high-value services is performed in the Enterprise Focus process area.The identification and prioritization of risks to high-value services and supporting assets isperformed in the Risk <strong>Management</strong> process area.<strong>Resilience</strong> requirements are managed in the <strong>Resilience</strong> Requirements <strong>Management</strong> processarea.Summary of Specific Goals and PracticesGoalsRRD:SG1 Identify Enterprise RequirementsRRD:SG2 Develop Service RequirementsRRD:SG3 Analyze and Validate RequirementsPracticesRRD:SG1.SP1 Establish Enterprise <strong>Resilience</strong> RequirementsRRD:SG2.SP1 Establish Asset <strong>Resilience</strong> RequirementsRRD:SG2.SP2 Assign Enterprise <strong>Resilience</strong> Requirements toServicesRRD:SG3.SP1 Establish a Definition of Required FunctionalityRRD:SG3.SP2 Analyze <strong>Resilience</strong> RequirementsRRD:SG3.SP3 Validate <strong>Resilience</strong> Requirements173 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!