12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Resilient Technical Solution Engineering (RTSE)An engineering process area in <strong>CERT</strong>-RMM. The purpose of Resilient Technical SolutionEngineering is to ensure that software and systems are developed to satisfy their resiliencerequirements.Return on resilience investment (RORI)The return on investment for funding resilience activities. Provides a way to justify resiliencecosts and provides direct support for the contribution that managing operational resilience makesin achieving strategic objectives. [FRM]RiskThe possibility of suffering harm or loss. From a resilience perspective, risk is the combination ofa threat or vulnerability (condition) and the impact (consequence) to the organization if the threator vulnerability is exploited. In <strong>CERT</strong>-RMM, this definition is typically applied to the asset orservice level such that risk is the possibility of suffering harm or loss due to disruption of highvalueassets and services. [RISK]Risk analysisA risk management process focused on understanding the condition and consequences of risk,prioritizing risks, and determining a path for addressing risks. Determines the importance of eachidentified operational risk and is used to facilitate the organization’s risk disposition andmitigation activities. [RISK]Risk appetiteAn organization’s stated level of risk aversion. Informs the development of risk evaluation criteriain areas of impact for the organization. [RISK] (See related glossary terms “area of impact,” “riskmeasurement criteria,” and “risk tolerance.”)Risk categoryAn organizationally defined description of risk that typically aligns with the various sources ofoperational risk but can be tailored to the organization’s unique risk environment. Risk categoriesprovide a means to collect and organize risks to assist in the analysis and mitigation processes.[RISK]Risk dispositionA statement of the organization’s intention for addressing an operational risk. Typically limited toaccept, transfer, research, or mitigate. [RISK]Risk <strong>Management</strong> (RISK)An enterprise process area in <strong>CERT</strong>-RMM. The purpose of Risk <strong>Management</strong> is to identify,analyze, and mitigate risks to organizational assets that could adversely affect the operation anddelivery of services.Risk managementThe continuous process of identifying, analyzing, and mitigating risks to organizational assets thatcould adversely affect the operation and delivery of services. [RISK]233 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!