12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Specific Practices by GoalADM:SG1 Establish Organizational AssetsOrganizational assets (people, information, technology, and facilities) areidentified and the authority and responsibility for these assets is established.The assets of the organization must be identified, prioritized, documented, andinventoried.The highest level concept in the operational resilience management process is aservice. Services are defined as the limited number of activities that the organizationcarries out in the performance of a duty or in the production of a product. Services arethe prime resource that the organization uses to accomplish its mission. Each servicehas a mission that must be accomplished in order to support the organization’s strategicobjectives. Failure to accomplish the mission of a service is a potentially seriousimpediment to accomplishing the organization’s mission.An important aspect of services is that they are “fueled” by assets—the raw materialsthat services need to operate.A service cannot accomplish its mission unless there arepeople to operate and monitor the serviceinformation and data to feed the process and to be produced by the servicetechnology to automate and support the servicefacilities in which to perform the serviceThese assets may or may not be directly owned by the organization. For example,outsourcing of call center functions may mean that the organization does not control thepeople, information, technology, or facilities that enable the service; however, theorganization retains responsibility for the ownership and resilience of the assets. Inorder to properly determine resilience requirements (and to implement appropriatestrategies for protecting and sustaining assets), the organization must define theseassets from a service perspective and establish ownership and responsibility for theirresilience.ADM:SG1.SP1 Inventory AssetsOrganizational assets are identified and inventoried.Success at achieving the organization’s mission relies upon criticaldependencies between organizational goals and objectives, services, andassociated high-value assets. Lack of performance of these assets (due todisruptive events, realized risk, or other issues) impedes mission assuranceof associated services and can translate into failure to achieveorganizational goals and objectives. Thus, ensuring the operationalresilience of high-value assets is paramount to organizational success.The first step in establishing the operational resilience of assets is toidentify and define the assets. Because assets derive their value andimportance through their association with services, the organization mustfirst identify and establish which services are of high-value. This provides81 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!