12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Data Collection and Logging addresses the organization’s competencies for identifying,collecting, logging, and disseminating information needed to ensure that operationalresilience management processes are performed consistently and within acceptabletolerances.Process <strong>Management</strong> addresses the activities the organization performs to improve andoptimize operational resilience management processes and to make these processesconsistent throughout the organization.Process <strong>Management</strong> process areas areData Collection and LoggingMonitoring [MON]Process <strong>Management</strong>Organizational Process Definition [OPD]Organizational Process Focus [OPF]Measurement and Analysis [MA]4.2 Objective Views for AssetsObjective views in <strong>CERT</strong>-RMM can address a number of useful perspectives, such ashow operational resilience management is planned and executedthe specific processes that drive asset-based resilience, such as relationships that driveinformation resiliencehow people are addressed in operational resilience managementthe development and deployment of protection strategies and controlsthe service continuity planning processWith a large model, the number of possible objective views could be significant and would bebeyond the scope of this report. A basic set of objective views can address the operationalresilience management of the assets that are the focus of the model. The following describes theseviews and provides four figures that graphically depict model objectives.PeopleFigure 23 shows the <strong>CERT</strong>-RMM process areas that participate in managing the operationalresilience of people. They establish people as an important asset in service delivery and ensurethat people meet job requirements and standards, have appropriate skills, are appropriatelytrained, and have access to other assets as needed to do their jobs.46 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!