ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection A.5.1: A.5.1 PAP objectives and targets

The organization should set and record objectives and targets, put them into effect and keep them current, so as to build physical asset protection across the organization and its supply chain, whether by avoiding, accepting or removing risk sources or by reducing likelihood or consequence. In setting and reviewing them it should take account of legal, regulatory and other requirements, its financial, operational and business needs, what its people and technology can do, and what interested parties think. Objectives should flow from the policy and the risk assessment and give the basis for choosing controls, weighing asset value, cost and benefit and the level of residual risk that can be tolerated; they should establish the cost and benefit of control options, rank control options and countermeasure needs, open chances to keep or lift performance, and be kept under review and updated as the risk picture changes. Targets should be set at a suitable level of detail, be specific, measurable, achievable, relevant and time-bound where practical, be made known to everyone concerned, whether employees, other staff or third parties such as contractors and supply chain partners, so each knows their own obligations, and be reassessed and amended when needed to stay consistent with the objectives.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.3.3 4.3.3 Measurable objectives and targets, and strategic programmes for prevention, mitigation, response, continuity and recovery

ISO 28000:2022 · 1 control

  • 6.2.1 Establishing security objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.