Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Douglas Gray
June 2016 - Podcast Intelligence Preparation for Operational Resilience

Topics: Cyber Risk and Resilience Management

In this podcast, Douglas Gray, a member of the CERT Cyber Risk Management team, discusses how to operationalize intelligence products to build operational resilience of organizational assets and services using IPOR.

May 2016 - Technical Note Applying the Goal-Question-Indicator-Metric (GQIM) Method to Perform Military Situational Analysis

Topics: Cyber Risk and Resilience Management

Authors: Douglas Gray

This report describes how to use the goal-question-indicator-metric method in tandem with the military METT-TC method (mission, enemy, time, terrain, troops available, and civil-military considerations).

December 2015 - Special Report Intelligence Preparation for Operational Resilience (IPOR)

Topics: Cyber Risk and Resilience Management

Authors: Douglas Gray

The author describes Intelligence Preparation for Operational Resilience (IPOR), a framework for preparing intelligence that complements commonly used intelligence frameworks such as Intelligence Preparation of the Battlefield (IPB).

September 2015 - Technical Report Improving Federal Cybersecurity Governance Through Data-Driven Decision Making and Execution

Topics: Cybersecurity Engineering

This technical report focuses on cybersecurity at the indirect, strategic level. It discusses how cybersecurity decision makers at the tactical or implementation level can establish a supportive contextual environment to help enable their success.