12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Identity registrationThe process of making an identity “known” to the organization as a person, object, or entity thatmay require access to organizational assets and that may need to be authenticated and authorizedto use access privileges. [ID]Identity repositoryA common accessible information repository that provides a single (or virtual) consistent sourceof information about organizational identities. [ID]Impact valuationDetermines the extent of the impact of operational risk using the organization’s risk measurementcriteria. [RISK]IncidentAn event (or series of events) of higher magnitude that significantly affects organizational assetsand requires the organization to respond in some way to prevent or limit organizational impact.[IMC]Incident closureThe retirement of an incident that has been responded to (i.e., there are no further actions required,and the organization is satisfied with the result) and for which the organization has performed aformal post-incident review. [IMC]Incident escalationThe process of notifying relevant stakeholders about an incident that requires an organizationalresponse and involves stakeholder actions to implement, manage, and bring to closure with anappropriate and timely solution. [IMC]Incident life cycleThe life cycle of an incident from detection to closure. Collectively, the processes of logging,tracking, documenting, escalating and notifying, gathering and preserving evidence, and closingincidents. [IMC]Incident <strong>Management</strong> and Control (IMC)An operations process area in <strong>CERT</strong>-RMM. The purpose of Incident <strong>Management</strong> and Control isto establish processes to identify and analyze events, detect incidents, and determine anappropriate organizational response.Incident ownerThe individuals or teams to whom an incident is assigned for containment, analysis, and response.[IMC]Incident responseThe actions the organization takes to prevent or contain the impact of an incident to theorganization while it is occurring or shortly after it has occurred. [IMC]223 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!