Cramm
   HOME

TheInfoList



OR:

{{More citations needed, date=September 2022 CRAMM (CCTA Risk Analysis and Management Method) is a risk management methodology, currently on its fifth version, CRAMM Version 5.0.


History

CRAMM was created in 1987 by the
Central Computer and Telecommunications Agency The Central Computer and Telecommunications Agency (CCTA) was a UK government agency providing computer and telecoms support to government departments. History Formation In 1957, the UK government formed the Technical Support Unit (TSU) of ...
(CCTA), now renamed into
Cabinet Office The Cabinet Office is a department of His Majesty's Government responsible for supporting the prime minister and Cabinet. It is composed of various units that support Cabinet committees and which co-ordinate the delivery of government objecti ...
, of the United Kingdom government.


Methodology

CRAMM comprises three stages, each supported by objective questionnaires and guidelines. The first two stages identify and analyze the risks to the system. The third stage recommends how these risks should be managed. The three stages of CRAMM are as follows:


Stage 1

The establishment of the objectives for security by: * Defining the boundary for the study for Risk Assessment * Identifying and valuing the physical assets that form part of the system; * Determining the 'value' of the data held by interviewing users about the potential business impacts that could arise from unavailability, destruction, disclosure or modification; * Identifying and valuing the software assets that form part of the system.


Stage 2

The assessment of the risks to the proposed system and the requirements for security by: * Identifying and assessing the type and level of threats that may affect the system; * Assessing the extent of the system's vulnerabilities to the identified threats; * Combining threat and vulnerability assessments with asset values to calculate measures of risks.


Stage 3

Identification and selection of countermeasures that are commensurate with the measures of risks calculated in Stage 2. CRAMM contains a very large countermeasure library consisting of over 3,000 detailed countermeasures organised into over seventy logical groupings.


Deployment

CRAMM is in use by
NATO The North Atlantic Treaty Organization (NATO, ; french: Organisation du traité de l'Atlantique nord, ), also called the North Atlantic Alliance, is an intergovernmental military alliance between 30 member states – 28 European and two No ...
, the Dutch armed forces, and corporations working actively on security, like
Unisys Unisys Corporation is an American multinational information technology (IT) services and consulting company headquartered in Blue Bell, Pennsylvania. It provides digital workplace solutions, cloud, applications, and infrastructure solutions, e ...
. CRAMM is offered in English and Dutch versions.


References


GAMMASS
Risk analysis methodologies