12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Asset-level resilience requirementsAsset-specific requirements that are set by the owners of the asset and are intended to establishthe asset’s protection and continuity needs with respect to its role in supporting mission assuranceof a high-value service. [RRD]Asset life cycleThe phases of an asset’s life from development or acquisition to deployment to disposition.[ADM]Asset ownerA person or organizational unit, internal or external to the organization, that has primaryresponsibility for the viability, productivity, and resilience of an organizational asset. Forexample, the Accounts Payable department is the owner of the vendor database. [ADM] [RRM]Asset profileDocumentation of specific information about an asset (typically an information asset) thatestablishes ownership, a common definition, and other characteristics of the asset, such as itsvalue. [ADM]Assurance caseA structured set of arguments and a corresponding body of evidence demonstrating that a systemsatisfies specific claims with respect to its security, safety, or reliability properties. [RTSE]Attack patternA design pattern describing the techniques that attackers might use to break a software product.[RTSE]Attack surfaceThe set of ways in which an attacker can enter and potentially cause damage to a system. Thelarger the attack surface, the more insecure the system [http://www.cs.cmu.edu/~pratyus/as.html].[RTSE]AvailabilityFor an asset, the quality of being accessible to authorized users (people, processes, or devices)whenever it is needed. [EC] [KIM] [PM]AwarenessFocusing the attention of, creating cognizance in, and acculturating people throughout theorganization to resilience issues, concerns, policies, plans, and practices. [OTA]Awareness activityA means for implementing the awareness approaches that the organization has considered anddeveloped to meet the specific needs of the stakeholder community. Formal awareness trainingsessions, newsletters, email messages, and posters and other signage are examples of awarenessactivities. [OTA]215 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!