Cross-Framework Mapping

ASIS SPC.1-2009 - Organizational Resilience StandardvsANSI/ASIS PAP.1-2012 Physical Asset Protection

See exactly how ASIS SPC.1-2009 - Organizational Resilience Standard controls map to ANSI/ASIS PAP.1-2012 Physical Asset Protection. Pre-computed mappings, identified gaps, and coverage analysis.

29
Controls Mapped
40
Gaps Found
35%
Coverage

Need this as a report you can hand to an assessor? A coverage crosswalk for this pair can be built to order.

According to the TheArtOfService Compliance Knowledge Graph:

ASIS SPC.1-2009 - Organizational Resilience Standard maps to ANSI/ASIS PAP.1-2012 Physical Asset Protection with 35% coverage across 24 directly mapped controls. Analysis of 69 ASIS SPC.1-2009 - Organizational Resilience Standard controls identifies 53 compliance gaps, primarily concentrated in Superseded batch representation – ASIS SPC.1-2009 - Organizational Resilience Standard.

Source: TheArtOfService Knowledge Graph | 69 controls analysed | 849 frameworks | 314K+ cross-framework mappings

Control Mappings

Showing 20 of 29 mapped controls across 5 domains. Sign up to explore all 314K+ mappings across 849 frameworks.

4.1 and 4.2: General requirements and OR management policy – ASIS SPC.1-2009 - Organizational Resilience Standard(4 mappings)

asis-spc-1-2009-organizational-resilience-standard::4.14.1 An OR management system established, documented, implemented, maintained and continually improved
→ansi-asis-pap-1-2012-physical-asset-protection::6.16.1 A PAPMS established, run, maintained and continually improved
asis-spc-1-2009-organizational-resilience-standard::4.1.14.1.1 A documented scope with boundaries, requirements, critical objectives, risk scenarios and a Statement of Applicability
→ansi-asis-pap-1-2012-physical-asset-protection::6.2.46.2.4 PAPMS scope and boundaries defined and retained
asis-spc-1-2009-organizational-resilience-standard::4.2.14.2.1 A policy statement meeting fifteen conditions, from life safety first to annual signed review
→ansi-asis-pap-1-2012-physical-asset-protection::5.25.2 A physical asset protection policy meeting eleven conditions
asis-spc-1-2009-organizational-resilience-standard::4.2.24.2.2 Management commitment shown through policy, objectives, roles, an accountable appointee, communication, resources, risk criteria, audits and reviews
→ansi-asis-pap-1-2012-physical-asset-protection::5.15.1 Top management shows leadership of the physical asset protection programme

4.3: Planning – ASIS SPC.1-2009 - Organizational Resilience Standard(6 mappings)

asis-spc-1-2009-organizational-resilience-standard::4.3.14.3.1 A formal, documented risk assessment and impact analysis with recovery time objectives3 targets
→ansi-asis-pap-1-2012-physical-asset-protection::A.4.2A.4.2 A formal, documented risk assessment process kept up to date
→ansi-asis-pap-1-2012-physical-asset-protection::A.4.2.1A.4.2.1 A documented security survey procedure for risk identification and exposure
→ansi-asis-pap-1-2012-physical-asset-protection::B.1.2B.1.2 Security surveys by accredited professionals, with findings followed up
asis-spc-1-2009-organizational-resilience-standard::4.3.24.3.2 Procedures to identify and apply legal, regulatory and other requirements
→ansi-asis-pap-1-2012-physical-asset-protection::A.4.1A.4.1 Procedures for legal, regulatory and other requirements
asis-spc-1-2009-organizational-resilience-standard::4.3.34.3.3 Measurable objectives and targets, and strategic programmes for prevention, mitigation, response, continuity and recovery2 targets
→ansi-asis-pap-1-2012-physical-asset-protection::A.5.1A.5.1 PAP objectives and targets
→ansi-asis-pap-1-2012-physical-asset-protection::A.5.2A.5.2 PAP programmes (action plans) to achieve objectives

4.4: Implementation and operation – ASIS SPC.1-2009 - Organizational Resilience Standard(9 mappings)

asis-spc-1-2009-organizational-resilience-standard::4.4.14.4.1 Resources, defined roles, a management representative, an OR management team, logistics, resource objectives and expedited financial procedures
→ansi-asis-pap-1-2012-physical-asset-protection::A.6.1A.6.1 Roles, authority, cross-functional teams and command and control
asis-spc-1-2009-organizational-resilience-standard::4.4.24.4.2 Competence with records, identified training needs, awareness procedures and an embedded OR culture
→ansi-asis-pap-1-2012-physical-asset-protection::A.6.2A.6.2 Competence, training and awareness
asis-spc-1-2009-organizational-resilience-standard::4.4.34.4.3 Communication and warning procedures, a documented decision on external communication, and regular testing
→ansi-asis-pap-1-2012-physical-asset-protection::A.2.2A.2.2 A formal, documented communication and consultation process
asis-spc-1-2009-organizational-resilience-standard::4.4.44.4.4 Documentation of the policy, objectives, scope, main elements and required documents and records
→ansi-asis-pap-1-2012-physical-asset-protection::A.3A.3 PAPMS documentation contents
asis-spc-1-2009-organizational-resilience-standard::4.4.54.4.5 Control of documents: approval, review, revision status, availability, retention, legibility, external documents, obsolescence and integrity
→ansi-asis-pap-1-2012-physical-asset-protection::A.3.2A.3.2 Document control procedure with integrity and access protection
asis-spc-1-2009-organizational-resilience-standard::4.4.64.4.6 Operational control of operations linked to significant risks, with procedures communicated to suppliers3 targets
→ansi-asis-pap-1-2012-physical-asset-protection::A.7.1A.7.1 Countermeasure procedures and a protection in depth strategy
→ansi-asis-pap-1-2012-physical-asset-protection::A.7.2A.7.2 Documented performance criteria and operational control procedures
→ansi-asis-pap-1-2012-physical-asset-protection::B.9B.9 Security policies and procedures
asis-spc-1-2009-organizational-resilience-standard::4.4.74.4.7 Incident prevention, preparedness and response procedures covering the twenty needs, reviewed after incidents, with competent personnel
→ansi-asis-pap-1-2012-physical-asset-protection::A.7.6A.7.6 Emergencies, unusual situations and disruptive events

4.5: Checking (evaluation) – ASIS SPC.1-2009 - Organizational Resilience Standard(1 mappings)

asis-spc-1-2009-organizational-resilience-standard::4.5.14.5.1 Performance metrics and monitoring procedures, including partnership and supply chain relationships and protective systems
→ansi-asis-pap-1-2012-physical-asset-protection::A.8.1A.8.1 Monitoring and measurement of PAP performance and PPS effectiveness

+9 more mappings

Plus AI-powered gap analysis, compliance advisory, PDF exports, and cross-mapping for all 849 frameworks.

Create Free Account →

Free forever, no credit card required

Coverage crosswalk

A ASIS SPC.1-2009 - Organizational Resilience Standard to ANSI/ASIS PAP.1-2012 Physical Asset Protection crosswalk, built to order

The table above lists candidate mappings. A crosswalk answers the narrower question you are probably here for: which ANSI/ASIS PAP.1-2012 Physical Asset Protection controls your existing ASIS SPC.1-2009 - Organizational Resilience Standard work already satisfies, which are real gaps, and the reasoning behind every claim so you can check it. One pair, $299, one time.

ASIS SPC.1-2009 - Organizational Resilience Standard into ANSI/ASIS PAP.1-2012 Physical Asset Protection
Not published yet

This direction has not been through crosswalk review and sign off, so no coverage figure is published for it. Reporting an unreviewed number would be worse than reporting none. It can be built to order at the same price as a pair that is already on the shelf.

If the two frameworks turn out to have too little in common for a crosswalk to help you, we say so and refund it rather than send a number worth nothing.

ANSI/ASIS PAP.1-2012 Physical Asset Protection into ASIS SPC.1-2009 - Organizational Resilience Standard
Not published yet

This direction has not been through crosswalk review and sign off, so no coverage figure is published for it. Reporting an unreviewed number would be worse than reporting none. It can be built to order at the same price as a pair that is already on the shelf.

If the two frameworks turn out to have too little in common for a crosswalk to help you, we say so and refund it rather than send a number worth nothing.

ASIS SPC.1-2009 - Organizational Resilience Standard to ANSI/ASIS PAP.1-2012 Physical Asset Protection (built to order)
$299
per framework pair, one time
  • Every evidenced control, with the reasoning behind it
  • Every gap, with what it requires
  • Its level of review stated plainly, not a bare number

Why this page shows two different percentages. The 35% in the header counts how many ASIS SPC.1-2009 - Organizational Resilience Standard controls carry at least one candidate mapping in the graph, before any review. The crosswalk percentage counts something stricter: how many ANSI/ASIS PAP.1-2012 Physical Asset Protection controls are actually evidenced, after a pass that argued against each mapping and kept only what survived. They answer different questions and they are not meant to agree.

A crosswalk narrows the work. It does not replace an audit, and your assessor may take a different view on individual controls. Mappings between frameworks are judgements, not text printed in either standard, which is why every claim in the report shows its reasoning. Questions go to support@theartofservice.com.

Stop Paying Consultants to Read Spreadsheets

Cross-framework mappings across 849 frameworks, at a fraction of consulting costs.

$0/forever

Free

  • ✓ 849 framework browser
  • ✓ Cross-framework mappings (314K+)
  • ✓ 824 compliance assessments
  • ✓ 3 AI queries & searches per day
Get Started Free
Recommended
$149/month

Professional

  • ✓ Unlimited AI Compliance Advisory
  • ✓ Unlimited full-text search
  • ✓ Framework self-assessment
  • ✓ PDF, Excel & CSV exports
Start 7-Day Free Trial →

What are the key differences between ASIS SPC.1-2009 - Organizational Resilience Standard and ANSI/ASIS PAP.1-2012 Physical Asset Protection?

ASIS SPC.1-2009 - Organizational Resilience Standard has 69 controls across its framework, while ANSI/ASIS PAP.1-2012 Physical Asset Protection covers 74 controls. Direct mapping analysis identifies 24 overlapping controls (35% coverage). The frameworks diverge most significantly in Superseded batch representation – ASIS SPC.1-2009 - Organizational Resilience Standard, where 42 ASIS SPC.1-2009 - Organizational Resilience Standard controls have no direct ANSI/ASIS PAP.1-2012 Physical Asset Protection equivalent.

How many controls map between ASIS SPC.1-2009 - Organizational Resilience Standard and ANSI/ASIS PAP.1-2012 Physical Asset Protection?

Of 69 total ASIS SPC.1-2009 - Organizational Resilience Standard controls, 24 map directly to ANSI/ASIS PAP.1-2012 Physical Asset Protection controls, representing 35% coverage. The remaining 53 controls represent compliance gaps requiring additional documentation or compensating controls to satisfy both frameworks simultaneously.

What are the compliance gaps when mapping ASIS SPC.1-2009 - Organizational Resilience Standard to ANSI/ASIS PAP.1-2012 Physical Asset Protection?

53 ASIS SPC.1-2009 - Organizational Resilience Standard controls have no direct equivalent in ANSI/ASIS PAP.1-2012 Physical Asset Protection. The highest concentration of gaps is in Superseded batch representation – ASIS SPC.1-2009 - Organizational Resilience Standard with 42 unmapped controls. These gaps represent areas where additional controls, policies, or documentation must be created to achieve compliance with both frameworks.

Which control domains have the most gaps between ASIS SPC.1-2009 - Organizational Resilience Standard and ANSI/ASIS PAP.1-2012 Physical Asset Protection?

The domain with the highest gap count is Superseded batch representation – ASIS SPC.1-2009 - Organizational Resilience Standard (42 gaps). Export the full domain-by-domain gap breakdown via the Professional tier to generate a prioritised remediation roadmap.

This platform provides educational compliance tools, not legal, regulatory, or professional compliance advice. Cross-framework mappings are AI-assisted interpretations and do not reproduce or replace official standards. Framework names and trademarks belong to their respective owners. Consult qualified professionals for your specific compliance requirements. See our Terms of Service.