Understanding Minimum Viability
In considering how to improve their cyber resilience, agency leadership should conduct careful business continuity and disaster recovery planning that identifies and prioritizes key processes that must be maintained for the agency’s continuing operation. The result of this assessment is the minimum viable organization, a concept that describes how long the agency can operate without specific processes and identifies options that may be available to fulfill these needs.
Agencies looking to understand their minimum viability should start with the mission. The size and mission of agencies can vary significantly, and their approaches to cyber resilience will reflect that.
Some systems are very different, such as weapons systems in the military that are not used by other agencies, but other essential systems such as payroll are present across the government. Agencies that have achieved a high level of cyber resilience will be able to bring these systems back online quickly and trust their data.
Agencies must focus their investments in cyber resilience on the steps that enable them to maintain minimum viability. Getting these critical functions back on track is essential to enabling rapid recovery from a cybersecurity incident.