<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SEI Blog | Enterprise Risk and Resilience Management</title><link>http://www.sei.cmu.edu/feeds/topic/</link><description>Updates on changes and additions to the                         SEI Blog for posts matching Enterprise Risk and Resilience Management</description><atom:link href="http://www.sei.cmu.edu/blog/feeds/topic/enterprise-risk-and-resilience-management/rss/" rel="self"/><language>en-us</language><lastBuildDate>Mon, 20 Apr 2026 00:00:00 -0400</lastBuildDate><item><title>Using Data and Data Analytics to Improve Cyber Resilience</title><link>https://www.sei.cmu.edu/blog/using-data-and-data-analytics-to-improve-cyber-resilience/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Our post highlights the use of data analytics as a force multiplier for cyber resilience as well as best practices to help organizations gain situational awareness on their current security posture.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patsy Bulisco</dc:creator><pubDate>Mon, 20 Apr 2026 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/using-data-and-data-analytics-to-improve-cyber-resilience/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>The Top 10 Skills CISOs Need in 2024</title><link>https://www.sei.cmu.edu/blog/the-top-10-skills-cisos-need-in-2024/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post outlines the top 10 skills that CISOs need in 2024 and beyond.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gregory Touhill</dc:creator><pubDate>Wed, 24 Jan 2024 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/the-top-10-skills-cisos-need-in-2024/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Process and Technical Vulnerabilities: 6 Key Takeaways from a Chemical Plant Disaster</title><link>https://www.sei.cmu.edu/blog/process-and-technical-vulnerabilities-6-key-takeaways-from-a-chemical-plant-disaster/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Weak processes can be as risky as technical vulnerabilities. This post describes how both of them worsened a cyber attack on a chemical plant.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Kambic</dc:creator><pubDate>Mon, 08 May 2023 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/process-and-technical-vulnerabilities-6-key-takeaways-from-a-chemical-plant-disaster/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cyber Risk and Resilience Management</category><category>Operational Resilience</category><category>Resilience Management Model (RMM)</category><category>Cybersecurity</category><category>Cybersecurity Controls</category><category>Enterprise Risk and Resilience Management</category><category>Best Practices in Network Security</category><category>Critical Infrastructure Protection</category></item><item><title>2 Approaches to Risk and Resilience: Asset-Based and Service-Based</title><link>https://www.sei.cmu.edu/blog/2-approaches-to-risk-and-resilience-asset-based-and-service-based/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>There are benefits and challenges of the two approaches to risk and resilience management: one based on an organization’s assets and the other on its services.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Emily Shawgo</dc:creator><pubDate>Mon, 06 Feb 2023 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/2-approaches-to-risk-and-resilience-asset-based-and-service-based/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cyber Risk and Resilience Management</category><category>Operational Resilience</category><category>Resilience Management Model (RMM)</category><category>Cybersecurity</category><category>Enterprise Risk and Resilience Management</category><category>Risk</category><category>Critical Infrastructure Protection</category></item><item><title>IT, OT, and ZT: Implementing Zero Trust in Industrial Control Systems</title><link>https://www.sei.cmu.edu/blog/it-ot-and-zt-implementing-zero-trust-in-industrial-control-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post introduces fundamental ZT and ICS concepts, barriers to implementing ZT principles in ICS environments, and potential methods to leverage ZT concepts in this domain.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brian Benestelli, Daniel Kambic</dc:creator><pubDate>Mon, 18 Jul 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/it-ot-and-zt-implementing-zero-trust-in-industrial-control-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Risk</category></item><item><title>System End-of-Life Planning: Designing Systems for Maximum Resiliency Over Time</title><link>https://www.sei.cmu.edu/blog/system-end-of-life-planning-designing-systems-for-maximum-resiliency-over-time/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Deployment plans for computing environments must account for hardware replacements and decommissions even though such activities may not occur until years later.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Grant Deffenbaugh, Lyndsi Hughes</dc:creator><pubDate>Mon, 27 Sep 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/system-end-of-life-planning-designing-systems-for-maximum-resiliency-over-time/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Enterprise Risk and Resilience Management</category><category>Best Practices</category><category>Systems Engineering</category></item><item><title>Translating the Risk Management Framework for Nonfederal Organizations</title><link>https://www.sei.cmu.edu/blog/translating-the-risk-management-framework-for-nonfederal-organizations/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post translates federal-government-specific aspects of the Risk Management Framework into processes for nonfederal organizations.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Emily Shawgo, Brian Benestelli</dc:creator><pubDate>Mon, 23 Aug 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/translating-the-risk-management-framework-for-nonfederal-organizations/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cyber Risk and Resilience Management</category><category>Cybersecurity</category><category>Cybersecurity Controls</category><category>Enterprise Risk and Resilience Management</category><category>Risk</category></item><item><title>How to Use the CMMC Assessment Guides</title><link>https://www.sei.cmu.edu/blog/how-to-use-the-cmmc-assessment-guides/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post is intended for DoD contractors looking for additional clarification as they prepare for a CMMC assessment. It will walk you through the assessment guides, provide basic CMMC concepts and definitions, and introduce alternate descriptions of some practices.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Douglas Gardner</dc:creator><pubDate>Wed, 03 Mar 2021 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/how-to-use-the-cmmc-assessment-guides/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cybersecurity Maturity Model Certification (CMMC)</category></item><item><title>10 Steps for Managing Risk: OCTAVE FORTE</title><link>https://www.sei.cmu.edu/blog/10-steps-managing-risk-octave-forte/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post, adapted from a recently published technical note, outlines OCTAVE FORTE's 10-step framework to guide nascent organizations as they build an ERM program and mature organizations as they fortify existing ERM programs, making them more reliable, measurable, consistent, and repeatable.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brett Tucker</dc:creator><pubDate>Mon, 07 Dec 2020 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/10-steps-managing-risk-octave-forte/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Risk</category></item><item><title>Balancing Cyber Confidence and Privacy Concerns</title><link>https://www.sei.cmu.edu/blog/balancing-cyber-confidence-and-privacy-concerns/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Learn about the privacy protocols that make it hard to protect enterprise networks, and their impact on network traffic monitoring in this SEI Blog post.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Reed, Dustin Updyke</dc:creator><pubDate>Mon, 21 Sep 2020 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/balancing-cyber-confidence-and-privacy-concerns/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Enterprise Risk and Resilience Management</category><category>Cyber Risk and Resilience Management</category></item><item><title>Follow the CUI: 4 Steps to Starting Your CMMC Assessment</title><link>https://www.sei.cmu.edu/blog/follow-the-cui-4-steps-to-starting-your-cmmc-assessment/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>One of the primary drivers of the DoD's Cybersecurity Maturity Model Certification (CMMC) is the congressional mandate to reduce the risk of accidental disclosure of controlled unclassified information (CUI).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matthew Trevors</dc:creator><pubDate>Mon, 24 Aug 2020 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/follow-the-cui-4-steps-to-starting-your-cmmc-assessment/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cybersecurity Maturity Model Certification (CMMC)</category></item><item><title>Beyond NIST SP 800-171: 20 Additional Practices in CMMC</title><link>https://www.sei.cmu.edu/blog/beyond-nist-sp-800-171-20-additional-practices-cmmc/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>These 20 practices are intended to make DoD contractors more security conscious.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Hoover, Katie Stewart</dc:creator><pubDate>Mon, 22 Jun 2020 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/beyond-nist-sp-800-171-20-additional-practices-cmmc/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cybersecurity Maturity Model Certification (CMMC)</category></item><item><title>Cybersecurity Maturity Model Certification (CMMC) Part 2: Process Maturity's Role in Cybersecurity</title><link>https://www.sei.cmu.edu/blog/cybersecurity-maturity-model-certification-cmmc-part-2-process-maturitys-role-in-cybersecurity/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Mature cybersecurity processes will improve an organization's ability to prevent and respond to a cyberattack</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Hoover, Katie Stewart</dc:creator><pubDate>Mon, 01 Jun 2020 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/cybersecurity-maturity-model-certification-cmmc-part-2-process-maturitys-role-in-cybersecurity/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cybersecurity Maturity Model Certification (CMMC)</category></item><item><title>The Latest Work from the SEI: DevSecOps, Artificial Intelligence, and Cybersecurity Maturity Model Certification</title><link>https://www.sei.cmu.edu/blog/the-latest-work-from-the-sei-devsecops-artificial-intelligence-and-cybersecurity-maturity-model-certification/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>As part of an ongoing effort to keep you informed about our latest work, this blog post summarizes some recently published SEI reports, podcasts, conference papers, and webcasts highlighting our work....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Douglas Schmidt</dc:creator><pubDate>Mon, 25 May 2020 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/the-latest-work-from-the-sei-devsecops-artificial-intelligence-and-cybersecurity-maturity-model-certification/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cybersecurity Maturity Model Certification (CMMC)</category></item><item><title>An Introduction to the Cybersecurity Maturity Model Certification (CMMC)</title><link>https://www.sei.cmu.edu/blog/an-introduction-to-the-cybersecurity-maturity-model-certification-cmmc/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>A cyber attack within the DIB supply chain could result in devastating losses of intellectual property and controlled unclassified information.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Katie Stewart, Andrew Hoover</dc:creator><pubDate>Mon, 30 Mar 2020 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/an-introduction-to-the-cybersecurity-maturity-model-certification-cmmc/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cybersecurity Maturity Model Certification (CMMC)</category></item><item><title>Programmer Moneyball: Challenging the Myth of Individual Programmer Productivity</title><link>https://www.sei.cmu.edu/blog/programmer-moneyball-challenging-the-myth-of-individual-programmer-productivity/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>A pervasive belief in the field of software engineering is that some programmers are much, much better than others (the times-10, or x10, programmer), and that the skills...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bill Nichols</dc:creator><pubDate>Mon, 27 Jan 2020 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/programmer-moneyball-challenging-the-myth-of-individual-programmer-productivity/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Measurement and Analysis</category><category>Software Quality</category></item><item><title>After the Cyber Resilience Review: A Targeted Improvement Plan for Service Continuity</title><link>https://www.sei.cmu.edu/blog/after-the-cyber-resilience-review-a-targeted-improvement-plan-for-service-continuity/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>In 2011, the SEI's CERT Division developed and published the Cyber Resilience Review (CRR) on behalf of the Department of Homeland Security....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert Vrtis, Jeffrey Pinckard</dc:creator><pubDate>Mon, 03 Jun 2019 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/after-the-cyber-resilience-review-a-targeted-improvement-plan-for-service-continuity/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Operational Resilience</category><category>Cyber Risk and Resilience Management</category></item><item><title>Evaluating Threat-Modeling Methods for Cyber-Physical Systems</title><link>https://www.sei.cmu.edu/blog/evaluating-threat-modeling-methods-for-cyber-physical-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Addressing cybersecurity for a complex system, especially for a cyber-physical system of systems (CPSoS), requires a strategic approach during the entire lifecycle of the system....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nataliya Shevchenko</dc:creator><pubDate>Mon, 04 Feb 2019 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/evaluating-threat-modeling-methods-for-cyber-physical-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Vulnerability Analysis</category><category>Security-Related Requirements</category><category>OCTAVE</category><category>Cyber Risk and Resilience Management</category><category>Network Situational Awareness</category><category>Enterprise Risk and Resilience Management</category><category>Cyber Missions</category><category>Threat Modeling </category><category>Best Practices in Network Security</category><category>Risk</category><category>Cyber-Physical Systems</category><category>Critical Infrastructure Protection</category></item><item><title>Threat Modeling: 12 Available Methods</title><link>https://www.sei.cmu.edu/blog/threat-modeling-12-available-methods/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Almost all software systems today face a variety of threats, and the number of threats grows as technology changes....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nataliya Shevchenko</dc:creator><pubDate>Mon, 03 Dec 2018 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/threat-modeling-12-available-methods/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Vulnerability Analysis</category><category>Security-Related Requirements</category><category>OCTAVE</category><category>Cyber Risk and Resilience Management</category><category>Network Situational Awareness</category><category>Enterprise Risk and Resilience Management</category><category>Cyber Missions</category><category>Threat Modeling </category><category>Best Practices in Network Security</category><category>Risk</category><category>Cyber-Physical Systems</category><category>Critical Infrastructure Protection</category></item><item><title>Adding Red to Blue: 10 Tactics Defenders Can Learn from Penetration Testers</title><link>https://www.sei.cmu.edu/blog/adding-red-to-blue-10-tactics-defenders-can-learn-from-penetration-testers/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This SEI Blog post, in collaboration with The Veris Group, highlights 10 low-disruption, freely available penetration testing tactics that benefit network defenders.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brent Kennedy</dc:creator><pubDate>Mon, 14 Dec 2015 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/adding-red-to-blue-10-tactics-defenders-can-learn-from-penetration-testers/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Cyber Risk and Resilience Management</category></item></channel></rss>