12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Technical controlA type of technical mechanism that supports protection methods for assets such as firewalls andelectronic access controls. [KIM] [TM]Technology assetAny hardware, software, or firmware used by the organization in the delivery of services. [TM]Technology interoperabilityThe ability of technology assets to exist and operate in a connected manner to meet anorganizational goal, objective, or mission. [TM]Technology <strong>Management</strong> (TM)An operations process area in <strong>CERT</strong>-RMM. The purpose of Technology <strong>Management</strong> is toestablish and manage an appropriate level of controls related to the integrity and availability oftechnology assets to support the resilient operations of organizational services.ThreatA situation, vulnerability, or condition that can be exploited to produce an unexpected orunwanted outcome for the organization. [RISK] [VAR]Threat actorA person or event that has the potential to exploit a threat. [VAR] [RISK]Threat environmentThe set of all types of threats that could affect the current operations of the organization. (Seerelated glossary term “threat.”)Threat motiveThe reason that a threat actor would exploit a vulnerability or threat. [VAR] [RISK]Unplanned downtimeInterruption in the availability of an information or technology asset (and in some cases, a facilityasset) due to an unplanned event or incident, often resulting from diminished operationalresilience. [TM]UserAny entity or object that the organization has granted some form of access to an organizationalasset. Typically referred to as an “identity.” (See related glossary term “identity.”)Vital recordsA record that must be preserved and available for retrieval if needed. This refers to records ordocuments that, for legal, regulatory, or operational reasons, cannot be irretrievably lost ordamaged without materially impairing the organization’s ability to conduct business. [KIM]Vital staffA select group of individuals who are absolutely essential to the sustained operation of theorganization, particularly under stressful conditions. [PM]237 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!