12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Table 4:<strong>CERT</strong>-RMM Components by CategoryRequired Expected Informativespecific goal statements specific practice statements purpose statementsgeneric goal statements generic practice statements introductory notes3.2.1 Required Componentsrelated process areas sectionsummary of specific goals and practicesgoal and practice titlestypical work productssubpracticesnotesexample blocksgeneric practice elaborationsreferencesamplificationsRequired components describe what an organization must achieve to satisfy a process area. Thereare two required components in <strong>CERT</strong>-RMM: specific goal statements and generic goalstatements. Goal satisfaction is used in <strong>CERT</strong>-RMM-based capability appraisals in determiningcapability levels (see Part Two, Section 6.4). Satisfaction of a goal means that it is visibly andverifiably implemented in the organization’s processes.Note that it is the goal statements that are required components, not the goal titles. The goal nameof specific goal 1 in Asset Definition and <strong>Management</strong> is “Establish Organizational Assets”; thegoal name of generic goal 1 is “Achieve Specific Goals.”3.2.2 Expected ComponentsExpected components describe the practices that an organization will typically implement toachieve required components. Specific practice statements and generic practice statements areboth expected components in <strong>CERT</strong>-RMM. To satisfy goals, the specific and generic practices areexpected to be present in the planned and implemented processes of the organization unlessacceptable alternatives are present.Again, note that it is the practice statements that are expected components, not the practice titles.3.2.3 Informative ComponentsInformative components provide guidance and suggestions about how to achieve the required andexpected components. The informative components in <strong>CERT</strong>-RMM are listed in Table 4.For example, “Identify organizationally high-value services” is a subpractice in Asset Definitionand <strong>Management</strong> specific practice 1 of specific goal 2, and “List of organizationally high-valueservices and associated assets” is a typical work product.33 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!