12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

TECHNOLOGY MANAGEMENTOperationsPurposeThe purpose of Technology <strong>Management</strong> is to establish and manage an appropriate level ofcontrols related to the integrity and availability of technology assets to support the resilientoperations of organizational services.Introductory NotesTechnology is a pervasive organizational asset. Few organizational services are untouchedby some aspect of technology—hardware, software, systems, tools, and infrastructure (suchas networks) that support services. Technology assets directly support the automation (andefficiency) of services and are often inextricably tied to information assets because theyprovide the platforms on which information is stored, transported, or processed. For someorganizations, technology is a prominent driver in accomplishing the mission and isconsidered a strategic element. Technology tends to be pervasive across all functions of theorganization and therefore can be a significant contributor to strategic and competitivesuccess.From a broad perspective, technology describes any technology component or asset thatsupports or automates a service and facilitates its ability to accomplish its mission. Examplesof technology assets include software, hardware, and firmware, including physicalinterconnections between these assets such as cabling. Technology has many layers, somewhich are specific to a service (such as an application system) and others which are sharedby the organization (such as the enterprise-wide network infrastructure) to support more thanone service. Organizations must describe technology assets sufficiently to facilitatedevelopment and satisfaction of resilience requirements. In some organizations, this may beat the application system level; in others, it might be more granular, such as at the server orpersonal computer level.The Technology <strong>Management</strong> process area addresses the importance of technology assetsin the operational resilience of services, as well as unique issues specific to technology suchas integrity and availability management. In this process area, technology assets areprioritized according to their value in supporting high-value organizational services. Physical,technical, and administrative controls that keep technology assets viable and sustainable areselected, implemented, and managed, and the effectiveness of these controls is monitored.In addition, technology asset risks are identified and mitigated in an attempt to preventdisruption where possible.The integrity of technology assets is addressed through mastery of capabilities such asconfiguration, change, and release management. The availability of technology assets,critical for supporting the resilience of services, is established and managed by controllingthe operational environment in which the assets operate, by performing regular maintenanceon these assets, and by limiting the potential effects of interoperability issues. Becausetechnology assets may extend outside of the physical and logical boundaries of the188 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!