
EF:GG2.GP2 PLAN THE PROCESS
Establish and maintain the plan for performing the enterprise focus process.
Subpractices
1. Define and document the plan for performing the process.
2. Define and document the process description.
3. Review the plan with relevant stakeholders and get their agreement.
4. Revise the plan as necessary.
EF:GG2.GP3 PROVIDE RESOURCES
Provide adequate resources for performing the enterprise focus process, developing the
work products, and providing the services of the process.
328 PART THREE CERT-RMM PROCESS AREAS
2. Develop and publish organizational policy for the process.
Elaboration:
The enterprise focus policy should address
• sponsorship for the process, including statements reflecting higher-level
managers’ commitment to managing resilience
• establishment of strategic objectives, plans, and critical success factors of the
organization as the foundation for the process
• the requirements for a strategic resilience plan and an operational resilience
management program
• responsibility, authority, and ownership (roles and responsibilities
1
) for
performing process activities
• proper compliance with relevant resilience-focused regulations and laws
• procedures, standards, and guidelines for
– conducting acceptable and ethical behavior, including a code of conduct and
code of ethics
– identifying the high-value services that must be resilient to ensure mission
achievement and the accomplishment of strategic objectives
– managing and monitoring performance, including clear measures for success
• management and periodic monitoring of the status of all operational resilience
management risks, which can be adjusted when needed, including capturing the
potential risks and costs associated with not investing in resilience activities
• methods for measuring adherence to policy and codes, exceptions granted, and
policy and code violations
1. Roles may include the chief risk officer, chief compliance officer, chief security and/or chief information security
officer, chief privacy officer, chief information officer, chief financial officer, general counsel, business unit execu-
tives and leaders, vice president of human resources/relations, vice president of public relations, etc.