12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Appendix B: Targeted Improvement RoadmapsAchieving FISMA ComplianceA suggested targeted improvement roadmap 13 for using <strong>CERT</strong>-RMM to achieve FISMAcompliance is provided below.Required <strong>CERT</strong>-RMM Process AreasAssociation with FISMA,NIST Supporting DocumentsNotesCategoryProcess AreaMinimumRequiredCapabilityLevelOperationsAccess <strong>Management</strong>(AM)Level 2 14FISMA – Select SecurityControlsFISMA – Implement SecurityControlsStrong connection toIdentity <strong>Management</strong> in<strong>CERT</strong>-RMMFIPS 200NIST SP 800-53NIST SP 800-70OMB Memorandum M-10-15EngineeringAsset Definition and<strong>Management</strong> (ADM)Level 2FISMA – CategorizeInformation SystemsFIPS 199NIST SP 800-60OMB Memorandum M-10-15Level 1 base practices inADM more broadly coverall asset types—people,information, technology,and facilities—whileFISMA is focused oninformation systems.Enterprise<strong>Management</strong>Enterprise Focus(EF)Level 1FISMA – EstablishOrganizational ViewNIST SP 800-39OMB Memorandum M-10-15Level 1 base practices in<strong>CERT</strong>-RMM are moreextensive than requiredby FISMA or NIST 800-39’s ―organizationalview.‖1314See page 69 for more information about using <strong>CERT</strong>-RMM targeted improvement roadmaps.Because of the FISMA emphasis on policies and procedures to support security programs, these process areasare raised to level 2 capability in <strong>CERT</strong>-RMM, which addresses elements of process capability (such as policy,governance, resources, training, monitoring, and control) that support a ―managed‖ level of operationalresilience management. Without FISMA policy requirements, these capability levels could be established atlevel 1.207 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!