12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3 <strong>Model</strong> ComponentsThis chapter introduces the <strong>CERT</strong>-RMM process areas and their categories and describes theprocess area components and their categories. You will need to fully understand this informationto make use of the process areas contained in Part Three. It may be helpful to skim a few processareas before you read this section to become familiar with their general construction and layout.3.1 The Process Areas and Their CategoriesAs in CMMI models, a process area in the <strong>CERT</strong>-RMM is “a cluster of related practices in anarea that, when implemented collectively, satisfy a set of goals considered important for makingimprovement in that area” [CMMI Product Team 2009, pg. 10]. The <strong>CERT</strong>-RMM has 26 processareas (PAs) that are organized into high-level operational resilience categories: Engineering,Enterprise <strong>Management</strong>, Operations, and Process <strong>Management</strong>. Table 3 shows the 26 <strong>CERT</strong>-RMM process areas by category.Table 3: Process Areas by CategoryCategoryEngineeringEngineeringEngineeringEngineeringEngineeringEngineeringEnterprise <strong>Management</strong>Enterprise <strong>Management</strong>Enterprise <strong>Management</strong>Enterprise <strong>Management</strong>Enterprise <strong>Management</strong>Enterprise <strong>Management</strong>Enterprise <strong>Management</strong>OperationsOperationsOperationsOperationsOperationsOperationsOperationsOperationsOperationsProcess <strong>Management</strong>Process <strong>Management</strong>Process <strong>Management</strong>Process <strong>Management</strong>Process AreaAsset Definition and <strong>Management</strong>Controls <strong>Management</strong><strong>Resilience</strong> Requirements Development<strong>Resilience</strong> Requirements <strong>Management</strong>Resilient Technical Solution EngineeringService ContinuityCommunicationsComplianceEnterprise FocusFinancial Resource <strong>Management</strong>Human Resource <strong>Management</strong>Organizational Training and AwarenessRisk <strong>Management</strong>Access <strong>Management</strong>Environmental ControlExternal Dependencies <strong>Management</strong>Identity <strong>Management</strong>Incident <strong>Management</strong> and ControlKnowledge and Information <strong>Management</strong>People <strong>Management</strong>Technology <strong>Management</strong>Vulnerability Analysis and ResolutionMeasurement and AnalysisMonitoringOrganizational Process DefinitionOrganizational Process FocusCategories are further elaborated and described in Section 4.1.31 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!