Overview

The scope of CRAMM

CRAMM is applicable to all types of information systems and networks and can be applied at all stages in the information system lifecycle, from planning and feasibility, through development and implementation to live operation. CRAMM can be used whenever it is necessary to identify the security and/or contingency requirements for an information system or network. This may include:

Application profiles

You may find it useful to read the CRAMM application profiles we've created that describe the benefits CRAMM can introduce to a range of typical projects.

The profiles cover topics such as BS7799 compliance, justifying security investment and business continuity strategies.