CERT
 
Publications Catalog Historical Documents Authorized Users of "CERT" CERT Training Courses Incident Handling Certification Virtual Training Environment CERT Coordination Center CERT Contact Information CERT Statistics FIRST conference 2008 sponsor
 


Incident Management Capability Metrics

The CERT CSIRT Development Team has introduced a method to evaluate and improve an organization's capability for managing computer security incidents. This method uses a set of incident management best practices defined in a set of metrics called the Incident Management Capability Metrics. These metrics provide organizations a baseline against which they can benchmark their current incident management processes or services.

The metrics questions explore different aspects of incident management activities. These questions are grouped into four basic functional categories:

  • Protect
  • Detect
  • Respond
  • Sustain

Indicators included with the metrics questions are used by an evaluator or practitioner to determine whether a function or service is being adequately performed.

The results from an evaluation using the metrics will help an organization determine the maturity of its incident management capability regardless of organization type or sector (commercial, academic, government, etc.).

The goal of this incident management capability evaluation is to help organizations assemble the right set of people, processes, and technology that enables them to protect and sustain their critical data, assets, and systems, and to conduct appropriate response and coordination actions for handling events and incidents when they occur.

The Incident Management Capability Metrics can be used to

  • evaluate an existing capability
  • identify areas for process improvement in an existing capability
  • help determine the services and functions needed to create an incident management capability

The CSIRT Development Team has also published the Incident Management Mission Diagnostic Method, a risk-based approach for determining the potential for success of an organization's incident management capability.



[top]
Copyright 2002 Carnegie Mellon University
CERT® and CERT Coordination Center® are registered in the U.S. Patent and Trademark office.

Disclaimers and copyright information

Last updated April 1, 2008