12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The plan for performing the process typically includes the followingelements and activities:process descriptionstandards and requirements for the work products and services of theprocessspecific objectives for the performance of the processdependencies among the activities, work products, and services of theprocessthe assignment of resources (typically funding, people, and tools)needed to perform the processassignment of responsibility and authoritytraining needed to perform and support the processwork products to be controlled and the level of control to applymeasurement requirements to provide insight into the performance ofthe process, its work products, and its servicesinvolvement of identified stakeholdersactivities for monitoring and controlling the processactivities for objectively evaluating the processactivities for management review of the process and the work productsRefer to the Enterprise Focus process area for more information aboutcreating, resourcing, and implementing a strategic resilience plan andestablishing a resilience program.Refer to individual process areas for specific guidance on creating,implementing, and managing plans, where relevant.Subpractices1. Define and document the plan for performing the process.This plan may be a stand-alone document, embedded in a more comprehensivedocument, or distributed across multiple documents. In the case of the plan beingdistributed across multiple documents, ensure that a coherent picture of who doeswhat is preserved.2. Define and document the process description.The process description, which includes relevant standards and procedures, may beincluded as part of the plan for performing the process or may be included in the planby reference.3. Review the plan with relevant stakeholders and get their agreement.Review the planned process to ensure that it satisfies policy (and the requirements forgovernance), plans, requirements, and standards to provide assurance tostakeholders.4. Revise the plan as necessary.198 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!