12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Glossary of TermsThis document contains an alphabetical glossary of terms for the <strong>CERT</strong> <strong>Resilience</strong> <strong>Management</strong><strong>Model</strong>. The glossary provides definitions based on how the term is used in the context ofoperational resilience management. For this reason, the definitions provided may differ fromthose in common use.The origin for each term is noted in brackets at the end of each definition. The notation refers tothe operational resilience management process area where the term originates or is used. Forexample, [AM] refers to the Access <strong>Management</strong> process area.Abuse caseSee “misuse/abuse case.”Access acknowledgementA form or process that allows users to acknowledge (in writing) that they understand their accessprivileges and will abide by the organization’s policy regarding the assignment, use, andrevocation of those privileges. [AM]Access controlThe administrative, technical, or physical mechanism that provides a “gate” at which identitiesmust present proper credentials and be authenticated to pass. [AM] [KIM]Access control policy or Access management policyAn organizational policy that establishes the policies and procedures for requesting, approving,and providing access to persons, objects, and entities and establishes the guidelines fordisciplinary action for violations of the policy. [AM]Access <strong>Management</strong> (AM)An operations process area in <strong>CERT</strong>-RMM. The purpose of Access <strong>Management</strong> is to ensure thataccess granted to organizational assets is commensurate with their business and resiliencerequirements.Access privilegeA mechanism for describing and defining an appropriate level of access to an organizationalasset— information, technology, or facilities—commensurate with an identity’s jobresponsibilities and the business and resilience requirements of the asset. [AM] [HRM]Access requestA mechanism for requesting access to an organizational asset that is submitted to and approved byowners of the asset (with sufficient justification). [AM]AcculturationThe acquisition and adoption of a process improvement mindset and culture for resiliencethroughout all levels of the organization. [HRM]213 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!