ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection A.7.2: A.7.2 Documented performance criteria and operational control procedures

The organization should keep documented performance criteria and procedures for situations where lacking them could cause drift from what the PAP policy, objectives and targets set out, covering, as relevant, how PPS are designed, bought, installed, run, maintained, assessed and replaced, and should assess the risks of revised or new arrangements before introducing them. Operational control procedures should define: purpose and scope; objectives and measures of success; implementation steps, phasing and sequence; roles, responsibilities and authorities; technology requirements, including maintenance and calibration; communication requirements and procedures; internal and external interdependencies and interactions; resource needs; and information flow and documentation. The procedures should make sure that: demand signals are reflected in capacity planning; contingencies and redundancies give protection in depth; supplier responses are validated (for example recovery times for a site, process or product); there is feedback on whether earlier controls are changing through design, engineering or process changes or outsourcing decisions; planned changes are controlled and unplanned ones reviewed and acted on; and procedures are reviewed periodically, with the PPS revised and documented where needed.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.4.6 4.4.6 Operational control of operations linked to significant risks, with procedures communicated to suppliers

ISO 27002:2022 · 1 control

  • 5.37 Documented operating procedures

ISO 28000:2022 · 1 control

  • 8.1 Operational planning and control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.