12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Required <strong>CERT</strong>-RMM Process AreasAssociation with FISMA,NIST Supporting DocumentsNotesCategoryProcess AreaMinimumRequiredCapabilityLevelOperationsEnvironmentalControl (EC)Level 2FISMA – Select SecurityControlsFISMA – Implement SecurityControlsFIPS 200NIST SP 800-53NIST SP 800-70EC addresses securitycontrols specifically forfacility assets. EC alsoaddressesdependencies on publicservices and publicinfrastructure (e.g.,telecommunications,utilities, emergencymanagement, and firstresponder services).OperationsIdentity <strong>Management</strong>(ID)Level 2FISMA – Select SecurityControlsFISMA – Implement SecurityControlsStrong connection toAccess <strong>Management</strong> in<strong>CERT</strong>-RMMFIPS 200NIST SP 800-53NIST SP 800-70OMB Memorandum M-10-15OperationsIncident <strong>Management</strong>and Control (IMC)Level 2FISMA General RequirementsNIST SP 800-61OMB Memorandum M-07-16Supports FISMA incidentmanagement andhandling provisionOMB Memorandum M-06-19OMB Memorandum in supportof Executive Order 13402OMB Memorandum M-10-15OperationsKnowledge andInformation<strong>Management</strong> (KIM)Level 2FISMA – Select SecurityControlsFISMA – Implement SecurityControlsKIM addresses securitycontrols specifically forinformation assets.FIPS 200NIST SP 800-53NIST SP 800-70EngineeringControls<strong>Management</strong> (CTRL)Level 2FISMA –Assess SecurityControlsNIST SP 800-37NIST SP 800-39NIST 800-53ALevel 2 capability forcontrols managementexceeds FISMArequirements andextends to all assettypes, not justinformation systems.OMB Memorandum M-10-15208 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!