12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A capability level for a process area is achieved when all of the generic goals are satisfied up tothat level. By design, capability level 2 is defined by generic goal 2 and capability level 3 isdefined by generic goal 3. Thus, the generic goals and practices at each level define the meaningof the capability levels. Because capability is cumulative, reaching capability level 3 means thatthe organization is also performing the goals and practices at capability levels 1 and 2. (SeeSection 5.4 for more information about generic goals and practices.)5.3 Connecting Capability Levels to Process InstitutionalizationCapability levels describe the degree to which a process has been institutionalized. Likewise, thedegree to which a process is institutionalized is defined by the generic goals and practices. Table 7links capability levels to the progression of processes and generic goals.Table 7:CapabilityLevelNumberCapability Levels Related to Goals and Process ProgressionGenericGoalNumberCapability LevelProgression of Processes0 N/A Incomplete No process or partially performed process1 GG1 Performed Performed process2 GG2 Managed Managed process3 GG3 Defined Defined processThe progression of capability levels and the degree of process institutionalization is characterizedin the following descriptions.5.3.1 Capability Level 0: IncompleteAn incomplete process is a process that either is not performed or is partially performed. One ormore of the specific goals of the process area are not satisfied. No generic goals exist for this levelsince there is no reason to institutionalize a partially performed process [CMMI 2007].5.3.2 Capability Level 1: PerformedCapability level 1 characterizes a performed process. A performed process is a process thatsatisfies all of the specific goals of the process area. 10 It supports and enables the work needed toperform operational resilience practices as defined by the specific goals.Although achieving capability level 1 results in important improvements, those improvements canbe lost over time if they are not institutionalized. The application of institutionalization throughthe generic goals at levels 2 and 3 helps to ensure that improvements are maintained [CMMI2007].When organizations perform a compliance review against a code of practice, they are in essenceevaluating whether a process is performed. However, because operational resilience managementprocesses are critically important during times of stress, simply verifying that a process isperformed does not provide any indication or predictability about how the organization will10In <strong>CERT</strong>-RMM as in CMMI models, all of the specific goals of a process area must be satisfied to state that theprocess is being performed or that the organization is performing the process at capability level 1.54 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!