12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Key control indicatorsOrganizationally specific indicators that provide information about the effectiveness of theorganization’s internal control system. [EF]Key performance indicatorsOrganizationally specific performance metrics that measure progress against the organization’sstrategic objectives and critical success factors. [EF]Key risk indicatorsOrganizationally specific thresholds that, when crossed, indicate levels of risk that may be outsideof the organization’s risk tolerance. [EF] [RISK]Knowledge and Information <strong>Management</strong> (KIM)An operations process area in <strong>CERT</strong>-RMM. The purpose of Knowledge and Information<strong>Management</strong> is to establish and manage an appropriate level of controls to support theconfidentiality, integrity, and availability of the organization’s information, vital records, andintellectual property.Line of businessA logical grouping of organizational units that have a common purpose, such as production ofproducts for a particular market segment.Managed processA performed process that is planned and executed in accordance with policy; employs skilledpeople having adequate resources to produce controlled outputs; involves relevant stakeholders; ismonitored, controlled, and reviewed; and is evaluated for adherence to its process description.(See related glossary term “performed process.”)Measurement and Analysis (MA)A process management process area in <strong>CERT</strong>-RMM. The purpose of Measurement and Analysisis to develop and sustain a measurement capability that is used to support managementinformation needs for managing the operational resilience management process.Measurement objectivesDocuments the purpose for which measurements and analysis are done and specifies the kinds ofactions that may be taken based on the results of data analysis. [MA]MeasuresMeasurements of the resilience process that may be categorized by obtaining direct measurements(base measures) or by obtaining measurements that are a combination of two or more basemeasures (derived measures). [MA]Misuse/abuse caseA descriptive statement of the undesirable, nonstandard conditions that software is likely to faceduring its operation from either unintentional misuse or intentional and malicious misuse orabuse. [RTSE]225 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!