CERT Resilience Management Model (RMM): A Maturity Model for Managing Operational Resilience (Hardcover)
暫譯: CERT 韌性管理模型 (RMM):運營韌性管理的成熟度模型 (精裝版)
Richard A. Caralli, Julia H. Allen, David W. White
- 出版商: Addison Wesley
- 出版日期: 2010-12-04
- 定價: $2,800
- 售價: 5.0 折 $1,400
- 語言: 英文
- 頁數: 1056
- 裝訂: Hardcover
- ISBN: 0321712439
- ISBN-13: 9780321712431
-
相關分類:
管理與領導 Management-leadership、資訊安全
立即出貨 (庫存 < 3)
相關主題
商品描述
Description
CERT® Resilience Management Model (CERT-RMM) is an innovative and transformative way to manage operational resilience in complex, risk-evolving environments. CERT-RMM distills years of research into best practices for managing the security and survivability of people, information, technology, and facilities. It integrates these best practices into a unified, capability-focused maturity model that encompasses security, business continuity, and IT operations. By using CERT-RMM, organizations can escape silo-driven approaches to managing operational risk and align to achieve strategic resilience management goals.
This book both introduces CERT-RMM and presents the model in its entirety. It begins with essential background for all professionals, whether they have previously used process improvement models or not. Next, it explains CERT-RMM’s Generic Goals and Practices and discusses various approaches for using the model. Short essays by a number of contributors illustrate how CERT-RMM can be applied for different purposes or can be used to improve an existing program. Finally, the book provides a complete baseline understanding of all 26 process areas included in CERT-RMM.
Part One summarizes the value of a process improvement approach to managing resilience, explains CERT-RMM’s conventions and core principles, describes the model architecturally, and shows how itsupports relationships tightly linked to your objectives.
Part Two focuses on using CERT-RMM to establish a foundation for sustaining operational resilience management processes in complex environments where risks rapidly emerge and change.
Part Three details all 26 CERT-RMM process areas, from asset definition through vulnerability resolution. For each, complete descriptions of goals and practices are presented, with realistic examples.
Part Four contains appendices, including Targeted Improvement Roadmaps, a glossary, and other reference materials.
This book will be valuable to anyone seeking to improve the mission assurance of high-value services, including leaders of large enterprise or organizational units, security or business continuity specialists, managers of large IT operations, and those using methodologies such as ISO 27000, COBIT, ITIL, or CMMI.
商品描述(中文翻譯)
**描述**
**CERT® 韌性管理模型 (CERT-RMM)** 是一種創新且具變革性的方式,用於在複雜且風險不斷演變的環境中管理操作韌性。CERT-RMM 提煉了多年研究的最佳實踐,以管理人員、資訊、技術和設施的安全性和生存能力。它將這些最佳實踐整合成一個統一的、以能力為中心的成熟度模型,涵蓋安全性、業務持續性和 IT 操作。通過使用 CERT-RMM,組織可以擺脫以孤島為驅動的操作風險管理方法,並對齊以實現戰略韌性管理目標。
本書不僅介紹了 CERT-RMM,還完整呈現了該模型。它首先為所有專業人士提供必要的背景,無論他們是否曾經使用過流程改進模型。接下來,它解釋了 CERT-RMM 的通用目標和實踐,並討論了使用該模型的各種方法。多位貢獻者的短文展示了 CERT-RMM 如何應用於不同目的或用於改善現有計劃。最後,本書提供了對 CERT-RMM 中所有 26 個流程領域的完整基線理解。
第一部分總結了流程改進方法在管理韌性方面的價值,解釋了 CERT-RMM 的慣例和核心原則,描述了模型的架構,並展示了它如何支持與您的目標緊密相關的關係。
第二部分專注於使用 CERT-RMM 建立在複雜環境中持續操作韌性管理流程的基礎,這些環境中風險迅速出現和變化。
第三部分詳細介紹了所有 26 個 CERT-RMM 流程領域,從資產定義到脆弱性解決。對於每個流程,提供了目標和實踐的完整描述,並附有現實的例子。
第四部分包含附錄,包括針對性改進路線圖、術語表和其他參考材料。
本書對於任何希望提高高價值服務的任務保證的人都將具有價值,包括大型企業或組織單位的領導者、安全或業務持續性專家、大型 IT 操作的管理者,以及使用 ISO 27000、COBIT、ITIL 或 CMMI 等方法論的人士。