Software Engineering Institute Carnegie Mellon

RSS  

Sustaining Operational Resiliency: A Process Improvement Approach to Security Management

Parent SEI Program

Networked Systems Survivability

 

Related Publications

Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process

Introducing the CERT Resiliency Engineering Framework: Improving the Security and Sustainability Processes

Applying OCTAVE: Practitioners Report

 

Author
Richard A. Caralli

Principle Contributors:
James F. Stevens
Charles M. Wallen (Financial Services Technology Consortium)
William R. Wilson

 

Technical Note
CMU/SEI-2006-TN-009

PDF File
HTML File

Additional Author Publications

Richard A. Caralli
James F. Stevens
Charles M. Wallen
William R. Wilson
transparent transparent

Organizations face an ever-changing risk environment. The risk that emanates from the day-to-day activities of the organization, operational risk, is the subject of increasing attention, particularly in the banking and finance industry, because of the potential to significantly disrupt an organization's pursuit of its mission. Security, business continuity, and IT operations management are activities that traditionally support operational risk management. But collectively, they also converge to improve the operational resiliency of the organization--the ability to adapt to a changing operational risk environment as necessary. Coordinating these efforts to sustain operational resiliency requires a process-oriented approach that can be defined, measured, and actively managed. This report describes the fundamental elements and benefits of a process approach to security and operational resiliency and provides a notional view of a framework for process improvement.

transparent transparenttransparent transparent