12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

esilience of services is key for mission assurance. Thus one of the foundational concepts in<strong>CERT</strong>-RMM is that improving operational resilience management processes has a significant,positive effect on service resilience. Figure 6 depicts the relationship between services andoperational resilience management processes.Figure 6: Relationship Between Services and Operational <strong>Resilience</strong> <strong>Management</strong> ProcessesSo what makes a service resilient? <strong>CERT</strong>-RMM identifies the following activities as contributingto service resilience:identification and mitigation of risks to the service and its supporting assets (see “Assets” inSection 2.2.3)implementation of service continuity processes and plansmanagement and deployment of people, including external partnersmanagement of IT operationsidentification and deployment of effective controls for information and technology assetsmanagement of the operational environment where services are performedA key aspect of services is the concept of high-value services, those that are critical to the successof the organization’s mission. The high-value services of the organization are the focus of theorganization’s operational resilience management activities. These services directly support theachievement of strategic objectives and therefore must be protected and sustained to the extentnecessary to minimize disruption. Failure to keep these services viable and productive may resultin significant inability to meet strategic objectives and, in some cases, the organization’s mission.To appropriately scope the organization’s operational resilience management processes andcorresponding operational resilience management activities, the high-value services of theorganization must be identified, prioritized, and communicated as a common target for success.High-value services serve as the focus of attention throughout <strong>CERT</strong>-RMM as the means bywhich to establish priorities for managing risk and improving processes, given that it is not21 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!