12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Required <strong>CERT</strong>-RMM Process AreasAssociation with FISMA,NIST Supporting DocumentsNotesCategoryProcess AreaMinimumRequiredCapabilityLevelOperationsTechnology<strong>Management</strong> (TM)Level 2FISMA – Select SecurityControlsFISMA – Develop SystemConfiguration RequirementsFISMA – Implement SecurityControlsTM addresses securitycontrols specifically fortechnology assetsincluding software,hardware, systems, andnetworksFIPS 200NIST SP 800-53NIST SP 800-70OperationsVulnerability Analysisand Resolution (VAR)Level 2FISMA – Assess SecurityControlsFISMA – Monitor SecurityStateNIST SP 800-53AConsidered part ofFISMA riskmanagement, althoughis a separate process in<strong>CERT</strong>-RMMNIST SP 800-37OMB Memorandum M-10-15Managing Cloud ComputingA suggested (but not all-inclusive) targeted improvement roadmap for determining how well theorganization is managing the potential risks when using cloud computing services is providedbelow.Process AreasAsset Definition and<strong>Management</strong>External Dependencies<strong>Management</strong>Selection RationaleAsset Definition and <strong>Management</strong> (ADM) is focused on the resilience of servicecriticalassets. Managing the risks from cloud computing means that theorganization has processes in place to identify and document assets, establishownership and custodianship for assets, and link assets to the services theysupport. The concept of asset ownership and custodianship are especiallyimportant in the cloud computing environment to establish clear lines ofdemarcation and responsibility for operational resilience.In External Dependencies <strong>Management</strong> (EXD), the organization’s process foridentifying, analyzing, and addressing the risks associated with the actions ofservice providers, the formalization of the relationship with such providers, and theongoing management of provider relationships are established. An externaldependency exists when an external entity has access to, control of, ownership in,possession of, responsibility for (including development, operations, maintenance,or support), or other defined obligations related to one or more assets or services ofthe organization. For cloud computing, managing external dependencies is anongoing concern over the life of the relationship.210 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!