12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GG1 Achieve Specific GoalsThe operational resilience management process supports and enablesachievement of the specific goals of the process area by transformingidentifiable input work products to produce identifiable output work products.GG1.GP1 Perform Specific PracticesGG2 Institutionalize a Managed ProcessPerform the specific practices of the process area to develop workproducts and provide services to achieve the specific goals of theprocess area.This practice requires the organization to perform the practices, produce thework products, and deliver the services that are contained in the processdefinition for a process area. The organization may perform these practicesin an improvised or reactive manner, and there may not be any processdefinition to support the performance of the practices. The degree to whichthe performance of practices is formalized varies from organization toorganization and may be inconsistent within an organization. The successof achieving the work products and delivering the service of the practicesmay be directly related to the staff involved in the process.The process is institutionalized as a managed process.GG2.GP1 Establish Process GovernanceEstablish and maintain governance over the planning andperformance of the process.This practice establishes the foundation for higher level managers’responsibility for overseeing, directing, and guiding the operationalresilience management process. Higher level managers set expectationsfor managing operational resilience in this practice and communicate theseexpectations to those who are responsible as appropriate. Regular reviewsof operational resilience activities are performed and reported to higherlevel managers for interpretation. Higher level managers makerecommendations where gaps are perceived in process performance.The behavioral expectations of higher level managers are instantiated inorganizational policies that address operational resilience management, aswell as in expectations for planning and performing operational resilienceprocesses.Higher level managers are also responsible for ensuring appropriate levelsof compliance with legal, regulatory, contractual, and governmentobligations.Refer to the Enterprise Focus process area for more information aboutproviding sponsorship and oversight to the operational resiliencemanagement process.196 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!