12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Part Two: Process Institutionalization and ImprovementThe concept of using a capability model to improve operational resilience may not at first glanceappear to provide significant advantages over the simple implementation of a code of practice.Codes of practice, after all, typically represent a cumulative view of how an industry faces achallenge such as information security and can be of great benefit to all organizations that sharethis challenge. For some organizations, using practices alone will bring about improvement—improvement in the way that passwords and user IDs are managed, how incidents are handled, orhow continuity plans are developed and tested. But lasting improvement depends on theorganization’s ability to develop and inculcate a culture around managing operational resilience—that the operational resilience of the organization is everyone’s job and responsibility. Securityand continuity training and awareness alone do not create such a culture or provide it with thefoundation it needs to flourish, particularly under times of stress.At its core, a capability model is about improving the organization’s capacity and competency forproducing high-quality results, no matter the circumstances. Using such an approach, the practicesperformed by the organization are embedded within a culture of improvement so that theperformance of these practices is measured and improved and the capability is sustained. This iscritical in managing operational risk because not all risks can be identified, and responses torealized risk cannot always be planned.A capability model provides a platform for measuring process institutionalization—the degree towhich a process is embedded in the culture. Measuring the level of institutionalization ofoperational resilience management processes tells the organization something about how likely itis to retain these processes in changing risk environments.In Part Two of this technical report, we discuss the capability dimension of <strong>CERT</strong>-RMM and theimpact it can have on transforming the organization’s performance. We also provide guidance onhow to use the model to begin an improvement effort or to get a “health check” on how yourorganization is managing operational resilience today.51 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!