11.01.2017 Views

A Technical History of the SEI

ihQTwP

ihQTwP

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Consequence: Organizations Can Determine Their Capability to<br />

Manage Resilience<br />

Organizations in <strong>the</strong> DoD, <strong>the</strong> U.S. defense industrial base, U.S. federal civilian agencies, <strong>the</strong> financial<br />

services sector, and academia have been using aspects <strong>of</strong> <strong>the</strong> CERT-RMM since 2009. It<br />

has been applied to a wide range <strong>of</strong> problems; some applications are described in podcasts<br />

(http://www.cert.org/podcasts). The range <strong>of</strong> applications includes<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

assessing <strong>the</strong> capability <strong>of</strong> U.S. IT-based critical infrastructures to be resilient in <strong>the</strong> presence<br />

<strong>of</strong> attack and <strong>the</strong> capability <strong>of</strong> external partners that provide parts <strong>of</strong> <strong>the</strong> DoD missions<br />

building an incident management capability in developing nations<br />

developing mission assurance planning guides for DoD commanders<br />

evaluating IT operations and security activities to identify potential improvements and to capture<br />

a pre-improvement baseline<br />

determining whe<strong>the</strong>r business continuity policy, when enacted, will produce <strong>the</strong> intended result<br />

determining if compliance with mandated regulations results in improved security<br />

assessing current s<strong>of</strong>tware development processes to determine if <strong>the</strong>y include s<strong>of</strong>tware resilience<br />

practices<br />

protecting personally identifiable information and eliminating its use where possible<br />

measuring operational resilience at strategic and tactical levels<br />

The <strong>SEI</strong> Contribution<br />

The <strong>SEI</strong> role has been to help organizations institutionalize improved processes for managing operational<br />

resilience and measure <strong>the</strong>ir benefit, demonstrating <strong>the</strong> value <strong>of</strong> converging operational<br />

risk disciplines, and accelerating <strong>the</strong> transition <strong>of</strong> industrial experience to <strong>the</strong> broader community.<br />

The CERT reputation and leadership role in <strong>the</strong> information security community and <strong>the</strong> <strong>SEI</strong> reputation<br />

and leadership role in <strong>the</strong> process improvement community provide <strong>the</strong> foundation for this<br />

work. The <strong>SEI</strong> has developed and is transitioning a credible, effective maturity model that allows<br />

organizations to have justifiable confidence that <strong>the</strong>y can provide essential services in <strong>the</strong> presence<br />

<strong>of</strong> disruption and stress and can return to normal operations in a reasonable period <strong>of</strong> time<br />

following disruption.<br />

References<br />

[Alberts 1999] Alberts, Christopher; Behrens, Sandra; Pethia, Richard; & Wilson, William. Operationally<br />

Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Framework, Version 1.0<br />

(CMU/<strong>SEI</strong>-1999-TR-017). S<strong>of</strong>tware Engineering Institute, Carnegie Mellon University, 1999.<br />

http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=13473<br />

[Allen 2011] Allen, Julia & Curtis, Pamela. Measures for Managing Operational Resilience<br />

(CMU/<strong>SEI</strong>-2011-TR-019). S<strong>of</strong>tware Engineering Institute, Carnegie Mellon University, 2011.<br />

http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=10017<br />

CMU/<strong>SEI</strong>-2016-SR-027 | SOFTWARE ENGINEERING INSTITUTE | CARNEGIE MELLON UNIVERSITY 126<br />

Distribution Statement A: Approved for Public Release; Distribution is Unlimited.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!