12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.1.1 Enterprise <strong>Management</strong>The enterprise is an important concept in managing operational resilience. At the enterprise level,the organization establishes and carries out many activities that set the tone for operationalresilience, such as governance, risk management, and financial responsibility.The process areas in the Enterprise <strong>Management</strong> category represent functions and activities thatare essential to broadly supporting the operational resilience management process. This does notmean that these processes are or need to be functionally positioned at an enterprise level. Instead,they represent organization-wide competencies that affect the operational resilience oforganizational units. For example, the practices in the Risk <strong>Management</strong> process area may beperformed by an organizational unit, but their effectiveness may be limited by the overall riskmanagement capability of the organization.The process areas that represent the Enterprise <strong>Management</strong> category areCommunications [COMM]Compliance <strong>Management</strong> [COMP]Enterprise Focus [EF]Financial Resource <strong>Management</strong> [FRM]Human Resource <strong>Management</strong> [HRM]Organizational Training and Awareness [OTA]Risk <strong>Management</strong> [RISK]Figure 21 depicts the relationships that drive resilience activities at the enterprise level.42 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!