12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

organization, the organization must address the interaction with external entities that providetechnology assets or support for technology assets to the organization.Related Process AreasThe establishment and management of resilience requirements for technology assets areperformed in the <strong>Resilience</strong> Requirements Development and <strong>Resilience</strong> Requirements<strong>Management</strong> process areas.The identification, definition, management, and control of technology assets are addressed inthe Asset Definition and <strong>Management</strong> process area.The risk management cycle for technology assets is addressed in the Risk <strong>Management</strong>process area.The management of the internal control system that ensures the protection of technologyassets is addressed in the Controls <strong>Management</strong> process area.The selection, implementation, and management of access controls for technology assets isperformed in the Access <strong>Management</strong> process area.The development of service continuity plans for technology assets is performed in theService Continuity process area.The establishment and management of relationships with external entities to ensure theresilience of services that are executed in facilities they own and operate are addressed inthe External Dependencies <strong>Management</strong> process area.Summary of Specific Goals and PracticesGoalsTM:SG1 Establish and Prioritize TechnologyAssetsTM:SG2 Protect Technology AssetsTM:SG3 Manage Technology Asset RiskTM:SG4 Manage Technology Asset IntegrityTM:SG5 Manage Technology Asset AvailabilityPracticesTM:SG1.SP1 Prioritize Technology AssetsTM:SG1.SP2 Establish <strong>Resilience</strong>-Focused Technology AssetsTM:SG2.SP1 Assign <strong>Resilience</strong> Requirements to TechnologyAssetsTM:SG2.SP2 Establish and Implement ControlsTM:SG3.SP1 Identify and Assess Technology Asset RiskTM:SG3.SP2 Mitigate Technology RiskTM:SG4.SP1 Control Access to Technology AssetsTM:SG4.SP2 Perform Configuration <strong>Management</strong>TM:SG4.SP3 Perform Change Control and <strong>Management</strong>TM:SG4.SP4 Perform Release <strong>Management</strong>TM:SG5.SP1 Perform Planning to Sustain Technology AssetsTM:SG5.SP2 Manage Technology Asset MaintenanceTM:SG5.SP3 Manage Technology CapacityTM:SG5.SP4 Manage Technology Interoperability189 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!