Challenge
An intelligence community customer depended on dozens of mission-critical systems but had no consistent way to compare how resilient they were. Information about where systems were deployed, how they were connected, how well they were secured, and whether their continuity plans actually worked lived in different places and different formats. Leadership could not easily see which systems carried the most risk, or why.
Our Approach
CEdge’s lead resilience engineer, working in a Top Secret/SCI environment, designed a repeatable assessment method and then applied it system by system.
Four dimensions of resilience
Every system was assessed on the same four questions:
- Geographic deployment: is the system deployed in more than one location?
- Transport infrastructure: can it reach the network over more than one path?
- Cyber posture: what is its authorization status, which security overlays apply, and what open plans of action exist?
- Continuity planning: is the system’s continuity of operations plan accurate, and has it been validated?
Closing information gaps
For each system we found the gaps in reportable resilience information and sent requests for information to the system owner. We then prepared a formal assessment in a standard posture summary and report format, and briefed leadership on a regular schedule.
Making the results usable
We documented the method so other teams could repeat it. We also reworked the standard assessment outputs to add detail, clearer sections, and color coding that made findings quick to read. Separately, we analyzed the enterprise transport network and produced a graphic showing the multiple network paths that support mission-critical systems.
Results
- A documented, repeatable method for resilience assessment that did not exist in this form before, retained by the customer as a best practice
- Dozens of mission-critical systems assessed on the same four dimensions, so results can be compared across the portfolio
- A clear view of enterprise transport paths, used by leadership when making enterprise risk decisions
- Standard, readable reports that make gaps and next steps obvious to non-specialists