12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Table 1:Process Areas in <strong>CERT</strong>-RMM and CMMI <strong>Model</strong>sCMMI <strong>Model</strong>s Process AreasCAM – Capacity andAvailability <strong>Management</strong>(CMMI-SVC only)Equivalent <strong>CERT</strong>-RMM Process AreasTM – Technology <strong>Management</strong><strong>CERT</strong>-RMM addresses capacity management from the perspective oftechnology assets. It does not address the capacity of services.Availability management is a central theme of <strong>CERT</strong>-RMM, significantlyexpanded from CMMI-SVC. Service availability is addressed in <strong>CERT</strong>-RMM bymanaging the availability requirement for people, information, technology, andfacilities. Thus, the process areas that drive availability management includeRRD – <strong>Resilience</strong> Requirements Development (where availabilityrequirements are established)RRM – <strong>Resilience</strong> Requirements <strong>Management</strong> (where the lifecycle of availability requirements is managed)EC – Environmental Control (where the availability requirementsfor facilities are implemented and managed)KIM – Knowledge and Information <strong>Management</strong> (where theavailability requirements for information are implemented andmanaged)PM – People <strong>Management</strong> (where the availability requirements forpeople are implemented and managed)TM – Technology <strong>Management</strong> (where the availability requirementsfor software, systems, and other technology assets are implementedand managed)IRP – Incident Resolution andPrevention(CMMI-SVC only)IMC – Incident <strong>Management</strong> and ControlIn <strong>CERT</strong>-RMM, IMC expands IRP to address a broader incident managementsystem and incident life cycle at the asset level. Workarounds in IRP areexpanded in <strong>CERT</strong>-RMM to address incident response practices.MA – Measurement andAnalysisMA – Measurement and Analysis is carried over intact from CMMI.In <strong>CERT</strong>-RMM, MA is directly connected to MON – Monitoring, which explicitlyaddresses data collection that can be used for MA activities.OPD – Organizational ProcessDefinitionOPD – Organizational Process Definition is carried over from CMMI, butdevelopment life-cycle-related activities and examples are deemphasized oreliminated.OPF – Organizational ProcessFocusOT – Organizational TrainingOPF – Organizational Process Focus is carried over intact from CMMI.OTA – Organizational Training and AwarenessOT is expanded to include awareness activities in OTA.REQM – Requirements<strong>Management</strong>RRM – <strong>Resilience</strong> Requirements <strong>Management</strong>Basic elements of REQM are included in RRM, but the focus is on managingthe resilience requirements for assets and services, regardless of where theyare in their development cycle.RD – RequirementsDevelopmentRRD – <strong>Resilience</strong> Requirements DevelopmentBasic elements of RD are included in RRM, but practices differ substantially.11 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!