12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

into the “security” function but may also be embedded in IT operations processes. Activities thatimplement protect strategies often appear as processes, procedures, policies, and controls.Sustain strategies translate into activities designed to keep assets operating as close to normal aspossible when faced with disruptive, stressful events. These strategies aid in managing theconsequences of risk by making consequences less likely and allowing the organization torespond more effectively to address consequences when an event occurs. Such activities typicallyfall into the “business continuity” function. Activities that implement sustain strategies often alsoappear as processes, procedures, policies, plans, and controls.Figure 10: Optimizing Information Asset <strong>Resilience</strong>The optimization of protect and sustain strategies and activities that minimize risk to assets andservices while making efficient use of limited resources defines the management challenge ofoperational resilience.2.2.6 Life-Cycle CoverageEach of the assets covered in <strong>CERT</strong>-RMM has a life cycle. From a generic perspective, themajority of operational resilience management processes in <strong>CERT</strong>-RMM focus on thedeployment and operation life-cycle phases, as shown in Figure 11.Figure 11: Generic Asset Life Cycle27 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!