Defining a Maturity Scale for Governing Operational Resilience

Abstract

Achieving operational resilience in today's environment is becoming increasingly complex as the pace of technology and innovation continues to accelerate. Sponsorship, strategic planning, and oversight of operational resilience are the most crucial activities in developing and implementing an effective operational resilience management (ORM) system. These governance activities are described in detail in the CERT(trademark) Resilience Management Model enterprise focus (EF) process area (PA). To ensure operational resilience, an organization must identify shortfalls across these defined activities, make incremental improvements, and measure improvement against a defined, accepted maturity scale. The current version of the CERT Resilience Management Model (CERT-RMM V1.2) utilizes a maturity architecture (levels and descriptions) that may not meet the granularity needs for organizations committed to making incremental improvements in governing operational resilience. To achieve a more granular approach, the CERT-RMM Maturity Indicator Level (MIL) scale was developed for application across all CERT-RMM PAs. The CERT Division of Carnegie Mellon University's Software Engineering Institute is conducting ongoing research around the current state of the practice of governing operational resilience and developing specific actionable steps for improving the governance of operational resilience. Study results provide the specific EF PA MIL scale for assessing maturity, identifying incremental improvements, and measuring improvements.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2015
Accession Number
ADA623595

Entities

People

  • Audrey J. Dorofee
  • Julia H. Allen
  • Katie Stewart
  • Lisa Young
  • Michelle Valdez

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Best Practices
  • Communities
  • Cyberattacks
  • Department Of Defense
  • Engineering
  • Guarantees
  • Indicators
  • Information Operations
  • Management Personnel
  • Materials
  • Operations Management
  • Organizational Structure
  • Resilience
  • Security
  • Software Development
  • Standards
  • United States

Readers

  • Software Engineering.
  • Systems Analysis and Design