12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Generic practice elaborationAn informative model component that appears after a generic practice to provide guidance onhow the generic practice should be applied to the process area.Geographical dispersionThe specific and planned dispersion or scattering of physical structures and facilities so that theyare not all affected by a single event or incident. [EC]GovernanceAn organizational process of providing strategic direction for the organization while ensuring thatit meets its obligations, appropriately manages risk, and efficiently uses financial and humanresources. [EF]High-value assetsPeople, information, technology, or facilities on whose availability, confidentiality, integrity, andproductivity a high-value service is dependent. [ADM]High-value servicesServices on which the success of the organization’s mission depends. [RRD] [EF]Human Resource <strong>Management</strong> (HRM)An enterprise process area in <strong>CERT</strong>-RMM. The purpose of Human Resource <strong>Management</strong> is tomanage the employment life cycle and performance of staff in a manner that contributes to theorganization’s ability to manage operational resilience.IdentityDocumentation of certain information about a person, object, or entity that may require access toorganizational assets to fulfill its role in executing services. [ID]Identity communityDefines the baseline population of persons, objects, and entities—internal and external to theorganization—that could be or are authorized to access and use organizational assetscommensurate with their job responsibilities and roles. Also, the collection of the organization’sidentity profiles. [ID]Identity <strong>Management</strong> (ID)An operations process area in <strong>CERT</strong>-RMM. The purpose of Identity <strong>Management</strong> is to create,maintain, and deactivate identities and associated attributes that provide access to organizationalassets.Identity managementA process that addresses the management of the life cycle of objects (typically people, but oftensystems, devices, or other processes) that need some level of trusted access to organizationalassets. [ID]Identity profileDocumentation of all of the relevant information necessary to describe the unique attributes, roles,and responsibilities of the associated person, object, or entity. [ID]222 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!