12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VulnerabilityA potential exposure or weakness that could be exploited. The susceptibility of an organizationalservice or asset to disruption. [VAR]Vulnerability Analysis and Resolution (VAR)An operations process area in <strong>CERT</strong>-RMM. The purpose of Vulnerability Analysis andResolution is to identify, analyze, and manage vulnerabilities in an organization’s operatingenvironment.Vulnerability management strategyA strategy for identifying and reducing exposure to known vulnerabilities. [VAR]Vulnerability repositoryAn organizational inventory of known vulnerabilities. [VAR]Vulnerability resolutionThe action that the organization takes to reduce or eliminate exposure to vulnerability. [VAR]WaiverDocumentation for staff members who have been exempted from awareness training or otheractivities for any reason. Such documentation includes the rationale for the waiver and approvalby the individual’s manager (or similarly appropriate person). Each required course shouldinclude criteria for granting training waivers. [OTA]238 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!