Skip to content

PM-9 #19

@gregelin

Description

@gregelin

BLUF

Team needs to produce a memo or other document that is the organization's official statement describing how the organization systematically manages cyber risk.

Effort

Initially developing the document is a one time activity performed by executives. The document is disseminated to everyone, especially managers and cyber. The document needs to be updated on defined schedule.

Good

The clearer the prioritization of risk, the easier the rest of org will make good trade-offs and direct resources to priorities.

Bad

A bad document is general and pushes prioritization downstream leading to security viewing all risks as equal.

Story

Story for development team to know location of document and read it

Examples

DoD is compliant because of memo DoDI 8510.01 stating how DoD uses NIST RMF as strategy.
You need a memo declaring what you will use as a strategy.
artifact is the memo.

CDM

  • essential to be at URL
  • essential to be located < 1 min
  • better if can be read in 10 min
  • better to be in opencontrol format
  • better if independent memo or clearly labeled section and linkable of memo
  • best if scheduled review

Make document public. Separate proprietary info to separate doc and make available enterprise wide.

Roles

  • Executive - Update and communicate strategy
  • Middle Managers - Communicate, implement, instrument adherence, mentor, and communicate problems
  • Front Line - use/apply strategy, improve strategy, measure adherence
  • Auditors - verify strategy; verify implementation
  • System - inherit strategy, embody strategy, share relevant data

Reference

RISK MANAGEMENT STRATEGY

The organization:
a. Develops a comprehensive strategy to manage risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of information systems;
b. Implements the risk management strategy consistently across the organization; and
c. Reviews and updates the risk management strategy [Assignment: organization-defined frequency] or as required, to address organizational changes.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions