CERT
 
Publications CatalogHistorical Documents
 


Practicing strong computer security is a nonnegotiable requirement for organizations doing business today. However, building security into an existing corporate culture is a complex undertaking. Our work in governance, insider threat, security management, and systems engineering provides general principles, specific starting points, as well as fully optimized methodologies for business leaders who want to launch an enterprise-wide security effort or make sure their existing security program is as good as it can be.

Governance

Governing for Enterprise Security (GES) describes ideas and methods organizations need to achieve and sustain a culture of security. GES builds upon corporate, enterprise, and information technology (IT) governance.

documentCERT's Podcast Series: Security for Business Leaders
documentGoverning for Enterprise Security: Overview (pdf) | Technical Note (pdf)
documentInformation Security as an Institutional Priority (pdf)
offsiteBuild Security In: Governance & Management

Governance Research Area
Includes our history of work, reports, related podcasts, and presentations.

Insider Threat

CERT's insider threat research is a collaborative effort to convey the big picture of the insider threat problem: the complex interactions, degree of risk, and unintended consequences of combinations of countermeasures (or lack thereof) over time.

document Insider Threat Study:
Computer System Sabotage in Critical Infrastructure Sectors (pdf) | Executive Summary (html)
document Insider Threat Study:
Illicit Cyber Activity in the Banking and Finance Sector (pdf)
offsite The MERIT Project
document Preliminary System Dynamics Maps of the Insider Cyber-threat Problem (pdf)
document 2005 E-Crime Watch Survey: Summary of Findings

Insider Threat Research Area
Includes our history of work, reports, related podcasts, and presentations.

Security and Resiliency Engineering

Security and Resiliency Engineering
Resiliency engineering is the process by which an organization designs, develops, implements, and manages the protection and sustainability of business-critical services, related business processes, and associated assets. The CERT® Resiliency Engineering Framework is the foundational process description of the capabilities required to manage operational resiliency and to focus security and business continuity activities on achieving organizationally driven objectives. The framework helps organizations build in, manage, and sustain resiliency rather than react to changing operational risk environments

OCTAVE
OCTAVE is an information security evaluation that considers your organization and its missions.