12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ProcessActivities that can be recognized as implementations of practices in the model. These activitiescan be mapped to one or more practices in process areas to allow the model to be useful forprocess improvement and process appraisal. (See related glossary terms “process area,”“subprocess,” and “process element.”)There is a special use of the phrase “the process” in the statements and descriptions of thegeneric goals and generic practices. In that context, “the process” is the process or processes thatimplement the process area.Process architectureThe ordering, interfaces, interdependencies, and other relationships among the process elementsin a standard process. Process architecture also describes the interfaces, interdependencies, andother relationships between process elements and external processes (e.g., contract management).[OPD]Process areaA cluster of related practices in an area that, when implemented collectively, satisfy a set of goalsconsidered important for making improvement in that area.Process asset libraryA collection of process asset holdings that can be used by an organization or project. (See relatedglossary term “organization’s process asset library.”)Process capabilityThe range of expected results that can be achieved by following a process. The generic goals andpractices define the degree to which a process is institutionalized; capability levels indicate thedegree to which a process is institutionalized.Process elementThe fundamental unit of a process. A process can be defined in terms of subprocesses or processelements. A subprocess can be further decomposed into subprocesses or process elements; aprocess element cannot. (See related glossary term “subprocess.”)Each process element covers a closely related set of activities (e.g., estimating element, peerreview element). Process elements can be portrayed using templates to be completed, abstractionsto be refined, or descriptions to be modified or used. A process element can be an activity or atask. [OPD]Process performanceA measure of actual results achieved by following a process. It is characterized by both processmeasures (e.g., vulnerabilities eliminated before being exploited) and product or service measures(e.g., control system network unavailability due to exploited vulnerabilities).Protection strategyThe strategy, related controls, and activities necessary to protect an asset from undesired harm ordisruptive events. The protection strategy is relative to the conditions to which the asset issubjected. (See related glossary term “condition.”)230 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!