12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Operational resilience addresses the organization’s ability to adapt to risk that affects its coreoperational capacities. It is an emergent property of effective and efficient operational riskmanagement [Caralli 2006].Operational resilience management defines the processes and related practices that anorganization uses to design, develop, implement, and control the strategies to protect and sustain(i.e., make operationally resilient) high-value (organizationally critical) services, related businessprocesses, and associated assets such as people, information, technology, and assets. Operationalresilience managementincludes both developmental (build, acquire) and operational (manage) aspectsactualizes the concept of convergencecharacterizes an active and directly controlled activity, rather than a passive activitySimply put, comprehensive management of operational resilience includes four objectives:Prevent the realization of operational risk to a high-value service (instantiated by a protectstrategy).Sustain a high-value service if risk is realized (instantiated by a sustain strategy).Effectively address consequences to the organization if risk is realized, and return theorganization to a “normal” operating state.Optimize the achievement of these objectives to maximize effectiveness at the lowest cost.Requirements form the basis for managing operational resilience. Protect and sustain strategies foran organizational service and associated assets are based on resilience requirements that reflecthow the service and assets are used to support the organization’s strategic objectives. When theorganization fails to meet these requirements (either because of poor practices or as a result of anincident, disaster, or other disruptive event), the operational resilience of the service and assets isdiminished, the service mission is at risk, and thus one or more of the organization’s strategicobjectives is not met. Thus, operational resilience depends on establishing requirements in orderto build resilience into assets and services and to keep these assets and services productive in theaccomplishment of strategic objectives.Through extensive review of existing codes of practice in the areas of security, businesscontinuity, and IT operations management, as well as from experience with helping organizationsto adopt a convergent view, <strong>CERT</strong> developers have codified in <strong>CERT</strong>-RMM a process definitionfor resilience management processes. The process definition embodies a requirements-drivenfoundation and describes the range of processes that characterize the organizational capabilitiesnecessary to actively direct, control, and manage operational resilience.2.2 Elements of Operational <strong>Resilience</strong> <strong>Management</strong><strong>CERT</strong>-RMM defines several foundational concepts that provide useful levels of abstractionapplied throughout the model. These concepts includeservicesbusiness processesassets19 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!