12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 31: <strong>Model</strong> Scope Options6.3.3 Capability Level TargetsCapability levels are used in the model to describe the achievement of the generic goals in aprocess area and are a measure of the extent to which a process area has been institutionalized(performed, managed, defined) by the organization (refer to Section 5.2). Establishing capabilitylevel targets is an important element in all <strong>CERT</strong>-RMM-based improvement efforts.When establishing capability level targets, the organization should consider the importance of thegeneric practices relative to the organization’s risk tolerance, threat environment, size,improvement timeframe, and improvement objectives. It may be valuable to review the genericgoals and generic practices and envision what the implementation of those practices and theachievement of those goals would look like for the organization during normal operations and intimes of stress. Capability level targets should be established for each process area and need notbe the same. Capability level 1 (performed) may be completely appropriate for a process area,even if capability level 3 (defined) is the established target for another process area in the modelscope. The capability level descriptions in Section 5.3 are valuable reference material for theselection of capability level targets.Targeted Improvement ProfileCapability level targets can be efficiently communicated in a targeted improvement profile (TIP),which is typically represented as a bar chart showing the capability level target for each processarea in the model scope. Figure 32 provides an example of a TIP for five process areas. Figure 33provides another TIP example in which fine-grained scoping options have been selected forseveral of the process areas. A targeted improvement profile may be integrated with a targetedimprovement roadmap. In this case, the TIR may include not only the process areas selected for aspecific objective, but also the TIP, which describes the capability levels that must be achieved ineach process area.71 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!