Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Javascript is currently disabled for your browser. For an optimal search experience, please enable javascript.

Advanced Search

Basic Search

Content Type

Topics

Publication Date

Douglas Gray
June 2016 - Podcast Intelligence Preparation for Operational Resilience

Topics: Cyber Risk and Resilience Management

Authors: Douglas Gray, Lisa R. Young

In this podcast, Douglas Gray, a member of the CERT Cyber Risk Management team, discusses how to operationalize intelligence products to build operational resilience of organizational assets and services using IPOR.

May 2016 - Technical Note Applying the Goal-Question-Indicator-Metric (GQIM) Method to Perform Military Situational Analysis

Topics: Cyber Risk and Resilience Management

Authors: Douglas Gray

This report describes how to use the goal-question-indicator-metric method in tandem with the military METT-TC method (mission, enemy, time, terrain, troops available, and civil-military considerations).

December 2015 - Special Report Intelligence Preparation for Operational Resilience (IPOR)

Topics: Cyber Risk and Resilience Management

Authors: Douglas Gray

The author describes Intelligence Preparation for Operational Resilience (IPOR), a framework for preparing intelligence that complements commonly used intelligence frameworks such as Intelligence Preparation of the Battlefield (IPB).

September 2015 - Technical Report Improving Federal Cybersecurity Governance Through Data-Driven Decision Making and Execution

Topics: Cybersecurity Engineering

Authors: Douglas Gray, Brian D. Wisniewski, Julia H. Allen, Constantine Cois (Heinz College, Carnegie Mellon University), Anne Connell, Erik Ebel (Veris Group), William Gulley (Veris Group), Michael Riley (Veris Group), Robert W. Stoddard, Marie Vaughn (Veris Group)

This technical report focuses on cybersecurity at the indirect, strategic level. It discusses how cybersecurity decision makers at the tactical or implementation level can establish a supportive contextual environment to help enable their success.