12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Resilience</strong> budgetA budget specifically developed and funded to support the organization’s resilience activities.[FRM]<strong>Resilience</strong> managementSee “operational resilience management.”<strong>Resilience</strong> obligationsAn understanding of a commitment, promise, or duty to follow and enforce the resiliencerequirements of the organization. [HRM]<strong>Resilience</strong> requirementA constraint that the organization places on the productive capability of an asset to ensure that itremains viable and sustainable when charged into production to support a service.<strong>Resilience</strong> Requirements Development (RRD)An engineering process area in <strong>CERT</strong>-RMM. The purpose of <strong>Resilience</strong> RequirementsDevelopment is to identify, document, and analyze the operational resilience requirements forhigh-value services and related assets.<strong>Resilience</strong> Requirements <strong>Management</strong> (RRM)An engineering process area in <strong>CERT</strong>-RMM. The purpose of <strong>Resilience</strong> Requirements<strong>Management</strong> is to manage the resilience requirements of high-value services and associated assetsand to identify inconsistencies between these requirements and the activities that the organizationperforms to meet the requirements.<strong>Resilience</strong> specificationsCriteria that the organization establishes for a working relationship with an external entity, whichmay be incorporated into contractual terms. Typically include the resilience requirements of anyof the organization’s high-value assets and services that are placed in the external entity’s control.Also may include required characteristics of the external entity (e.g., financial condition andexperience), required behaviors of the external entity (e.g., security and training practices), andperformance parameters that must be exhibited by the external entity (e.g., recovery time after anincident and response time to service calls).<strong>Resilience</strong> staffInternal or external staff who are specifically involved in or assigned to resilience-focusedactivities that are typically found in security, business continuity, and IT operations disciplines.[OTA]<strong>Resilience</strong> trainingThe process and activities focused on imparting the necessary skills and knowledge to people forperforming their roles and responsibilities in support of the organization’s operational resiliencemanagement process. [OTA]<strong>Resilience</strong> training needsTraining requirements related to the skills and competencies required at a tactical level to carryout the activities required for managing operational resilience. [OTA]232 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!