
500 PART THREE CERT-RMM PROCESS AREAS
Refer to the Organizational Training and Awareness process area for information
about training staff for resilience roles and responsibilities.
Refer to the Human Resource Management process area for information about acquir-
ing staff to fulfill roles and responsibilities.
2. Fund the process.
Elaboration:
In the case of incident management and control, funding must extend to sup-
porting the incident life cycle and consideration must be given to unknown fund-
ing requirements related to incident management that are relative to the type and
extent of incident and the impact on the organization. Extending consideration
to these unpredictable needs provides the organization a level of control over
unplanned and potentially unconstrained costs.
Refer to the Financial Resource Management process area for information about
budgeting for, funding, and accounting for incident management and control.
3. Provide necessary tools, techniques, and methods to perform the process.
Elaboration:
• owners and custodians of high-value assets that support the accomplishment of
operational resilience management objectives
• internal and external auditors responsible for reporting to appropriate committees
on process effectiveness
These are examples of tools, techniques, and methods to support the incident
management and control process:
• methods, techniques, and tools for
– event identification, detection (refer to IMC:SG2), and reporting
– analyzing events and incidents, including determining when one or more
events should be declared an incident
– collecting, documenting, and preserving evidence for events and incidents
– recovering from events
• methods and tools for event and incident logging and tracking
• methods for triaging events
• root-cause analysis techniques and tools, such as cause-and-effect diagrams,
interrelationship diagrams, and causal factor tree analysis
• incident databases and knowledgebases, including predetermined response and
recovery actions for specific types of incidents
• methods and techniques for responding to events
• communications methods for reporting and escalating incidents
• methods for conducting post-incident reviews and ensuring lessons learned are
reflected in process activities