Page 385

The University of SydneyPage 46SSE-CMM Architecture Description–Base practices have the following characteristics:–Applied across the life cycle of the enterprise–Do not overlap with other base practice–Represent a “best practice” of the security community–Applicable using multiple methods in multiple business contexts–Do not specify a particular implementation method or tool–Generic practices are activities which are applicable to all processes –management, measurement, and institutionalisation–Generic practices are grouped into logical areas called “common features”–Common features are organisedinto five “capability levels”