|
![]() ![]() |
Incident Management Capability MetricsThe CERT CSIRT Development Team has introduced a method to evaluate and improve an organization's capability for managing computer security incidents. This method uses a set of incident management best practices defined in a set of metrics called the Incident Management Capability Metrics. These metrics provide organizations a baseline against which they can benchmark their current incident management processes or services. The metrics questions explore different aspects of incident management activities. These questions are grouped into four basic functional categories:
Indicators included with the metrics questions are used by an evaluator or practitioner to determine whether a function or service is being adequately performed. The results from an evaluation using the metrics will help an organization determine the maturity of its incident management capability regardless of organization type or sector (commercial, academic, government, etc.). The goal of this incident management capability evaluation is to help organizations assemble the right set of people, processes, and technology that enables them to protect and sustain their critical data, assets, and systems, and to conduct appropriate response and coordination actions for handling events and incidents when they occur. The Incident Management Capability Metrics can be used to
The CSIRT Development Team has also published the Incident Management Mission Diagnostic Method, a risk-based approach for determining the potential for success of an organization's incident management capability. [top] Copyright 2002 Carnegie Mellon University CERT® and CERT Coordination Center® are registered in the U.S. Patent and Trademark office. Disclaimers and copyright information Last updated April 1, 2008 |







