Skip to content

Commit c5a78d9

Browse files
authored
Refactor Default Mission Impact Values into reusable include file (#1016)
2 parents 96fd1af + 0a25ccd commit c5a78d9

File tree

4 files changed

+10
-5
lines changed

4 files changed

+10
-5
lines changed
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
!!! tip "Default Mission Impact Values"
2+
3+
Similarly, with [*Mission Impact*](/reference/decision_points/mission_impact.md), the deployer should assume that the software is in use at the
4+
organization for a reason, and that it supports essential functions unless they have evidence otherwise.
5+
With a total lack of information, assume [*support crippled*](/reference/decision_points/mission_impact.md) as a default.

docs/howto/bootstrap/collect.md

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -106,11 +106,7 @@ we can suggest something like defaults for some decision points.
106106

107107
{% include-markdown "../../_includes/default_safety_values.md" %}
108108

109-
!!! tip "Default Mission Impact Values"
110-
111-
Similarly, with [*Mission Impact*](../../reference/decision_points/mission_impact.md), the deployer should assume that the software is in use at the
112-
organization for a reason, and that it supports essential functions unless they have evidence otherwise.
113-
With a total lack of information, assume [*support crippled*](../../reference/decision_points/mission_impact.md) as a default.
109+
{% include-markdown "../../_includes/default_mission_impact_values.md" %}
114110

115111
!!! example "Using Defaults"
116112

docs/howto/gathering_info/mission_impact.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,5 @@ At a minimum, understanding mission impact should include gathering information
1212
There are various sources of guidance on how to gather this information; see for example the FEMA guidance in [Continuity Directive 2](https://www.fema.gov/sites/default/files/2020-07/Federal_Continuity_Directive-2_June132017.pdf) or [OCTAVE FORTE](https://insights.sei.cmu.edu/insider-threat/2018/06/octave-forte-and-fair-connect-cyber-risk-practitioners-with-the-boardroom.html).
1313
This is part of risk management more broadly.
1414
It should require the vulnerability management team to interact with more senior management to understand mission priorities and other aspects of risk mitigation.
15+
16+
{% include-markdown "../../_includes/default_mission_impact_values.md" %}

docs/reference/decision_points/mission_impact.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,8 @@ print(example_block(LATEST))
1111

1212
See this [HowTo](../../howto/gathering_info/mission_impact.md) for advice on gathering information about the Mission Impact decision point.
1313

14+
{% include-markdown "../../_includes/default_mission_impact_values.md" %}
15+
1416
!!! tip "See also"
1517

1618
Mission Impact combines with [Safety Impact](./safety_impact.md) to inform

0 commit comments

Comments
 (0)