12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Subpractices1. Identify process skill needs.2. Identify process skill gaps based on available resources and theircurrent skill levels.3. Identify training opportunities to address skill gaps.4. Provide training and review the training needs as necessary.GG2.GP6 Manage Work Product ConfigurationsPlace designated work products of the process under appropriatelevels of control.The purpose of this practice is to establish and maintain the integrity of thedesignated work products of the process (or their descriptions) throughouttheir useful life. Work products of the process must be managed andcontrolled as operating conditions change and evolve.The designated work products are specifically identified in the plan forperforming the process, along with a specification of the appropriate level ofcontrol.Different levels of control are appropriate for different work products and fordifferent points in time. For some work products, it may be sufficient tomaintain version control (i.e., the version of the process work product in useat a given time, past or present, is known, and changes are incorporated ina controlled manner). <strong>Version</strong> control is usually under the sole control of theowner of the process work product (typically an individual, group, or team).Sometimes it may be critical for work products to be placed under formal orbaseline configuration management. This type of control includes definingand establishing baselines at predetermined points. These baselines areformally reviewed and agreed upon and serve as the basis for furtherdevelopment and use of the process work product.Additional levels of control between version control and formal configurationmanagement are possible. An identified work product may be under variouslevels of control at different points in time.Because change control, version control, and configuration managementare fundamental activities in many operational resilience managementprocesses, this generic practice also addresses the processes andpractices necessary to establish baseline work products (e.g., developingan asset database) and for performing change control on these workproducts as the operational environment changes and evolves. In somecases, the management of work products is critical to the operationalresilience management process and therefore is included in the specificpractices of the process area, ranging from simple change control activitiesto baseline-driven configuration management. Examples of these practicescan be found throughout process areas such as Access <strong>Management</strong>,Asset Definition and <strong>Management</strong>, and Incident <strong>Management</strong> and Control.201 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!