12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Risk measurement criteriaObjective criteria that the organization uses for evaluating, categorizing, and prioritizingoperational risks based on areas of impact. [RISK] (See related glossary term “area of impact.”)Risk mitigationThe act of reducing risk to an acceptable level. [RISK]Risk mitigation planA strategy for mitigating risk that seeks to minimize the risk to an acceptable level. [RISK]Risk parameter (risk management parameter)Organizationally specific risk tolerances used for consistent measurement of risk across theorganization. Risk parameters include risk tolerances and risk measurement criteria. [RISK] (Seerelated glossary terms “risk tolerance” and “risk measurement criteria.”)Risk statementA statement that clearly articulates the context, conditions, and consequences of risk. [RISK]Risk taxonomySee “operational risk taxonomy.”Risk thresholdAn organizationally developed type of risk parameter that is used by management to determinewhen a risk is in control or when it has exceeded acceptable organizational limits. [RISK]Risk toleranceThresholds that reflect the organization’s level of risk aversion by providing levels of acceptablerisk in each operational risk category that the organization established. Risk tolerance, as a riskparameter, also establishes the organization’s philosophy on risk management—how risks will becontrolled, who has the authorization to accept risk on behalf of the organization, and how oftenand to what degree operational risk should be assessed. [RISK]Root cause analysisAn approach for determining the underlying causes of events or problems as a means ofaddressing the symptoms of such events as they manifest in organizational disruptions. [VAR]ScopeSee “appraisal scope,” “model scope,” and “organizational scope.”Secure design patternA general, reusable solution to a commonly occurring problem in design. A design pattern is not afinished design that can be transformed directly into code. It is a description or template for howto solve a problem that can be used in many different situations.Secure design patterns are meant to eliminate the accidental insertion of vulnerabilities intocode or to mitigate the consequences of vulnerabilities. Secure design patterns address securityissues at widely varying levels of specificity, ranging from architectural-level patterns involvingthe high-level design of the system down to implementation-level patterns providing guidance onhow to implement portions of functions or methods in the system [Dougherty 2009]. [RTSE]234 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!