Monday, February 1, 2016

CS5L CMM standards and defense metric build



CSP build: Defense metric build through OASIS

  • Defenses (may span more than 1 layout)
  • Defense Sectors
    • Installation and configuration
    • maintenance and management
    • policies and procedures 



Base defense metric: CS5L standard defense metric

  • NIST standard - Top level 
  • ISO27K standard - Maps to defenses
  • Defense metric - Inherits above


add VAA metric: specific to VAA Value Added Auditor

add industry metric: industry - compliance metric

  • Legal - client dependant
  • Investors - client dependant
  • Distribution - PCI
  • Manufacturing - SCADA
  • Retail outlets - PCI and HIPAA (if pharmacy)
  • Internet companies
  • Financial - PCI
  • Insurance - PCI
  • Healthcare - HIPAA
  • Utility power - SCADA
  • Telecommunications - PCI

Each industry inherits compliance metric

add client metric: risk and compliance specific added by VAA

Weighted: all metric builds are weighted by risk exposure
 

Thursday, January 14, 2016

CS5L CMM Cyber-ID and Score

CS5L CMM Cyber-ID and Score


Cyber-ID

The Cyber-ID is issued much the same as a Federal ID, except that it separated from the Company information and never exposed.  The Cyber-ID is used to track the companies CMM, Capability Maturity Model.

Score

The Score is derived from the CMM.  It is a five digit number representing the weighted score for each Layout.  Eg:   2 4 3 4 2