12.07.2015 Views

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

CERT Resilience Management Model, Version 1.0

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

are defined and satisfied to keep the asset productive and viable for use inservices.Asset custodians are persons or organizational units, internal or external tothe organization, who are responsible for implementing and managingcontrols to satisfy the resilience requirements of high-value assets whilethey are in their care. For example, the customer data in the above examplemay be stored on a server which is maintained by the IT department. Inessence, the IT department takes custodial control of the customer dataasset when the asset is in its domain. The IT department must commit totaking actions commensurate with satisfying the owner’s requirements toprotect and sustain the asset. However, in all cases, owners areresponsible for ensuring that their assets are properly protected andsustained, regardless of the actions (or inactions) of custodians.In practice, custodianship brings many challenges for asset owners inensuring that the resilience requirements of their assets are being satisfied.In some cases, custodians of assets must resolve conflicting requirementsobtained from more than one asset owner. This can occur in cases where aserver contains more than one information asset from different owners withunique and sometimes competing requirements. In addition, custodianshipmay occur outside of organizational boundaries, as is commonly seen inoutsourcing arrangements. In such a case, asset owners must clearlycommunicate the resilience requirements of their assets to externalcustodians and must expend additional effort in monitoring the satisfactionof those requirements.The owner of each high-value asset is established in order to defineresponsibility and accountability for the asset’s resilience and itscontributions to services. Accordingly, owners are responsible fordeveloping and validating the resilience requirements for high-value assetsthat they own. They are also responsible for the implementation of propercontrols to meet resilience requirements, even if they assign thisresponsibility to a custodian of the asset.The identification, documentation, analysis, and management of asset-levelresilience requirements are addressed in the <strong>Resilience</strong> RequirementsDevelopment and <strong>Resilience</strong> Requirements <strong>Management</strong> process areas.86 | CMU/SEI-2010-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!