ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection A.7.6: A.7.6 Emergencies, unusual situations and disruptive events

The organization should keep procedures for preventing events, being ready for them and responding to them, so the PAP system stays intact and working when situations affect it. It should set, document and implement a command and control structure with cross-discipline, cross-functional teams holding the resources, authority, experience and competence to: establish the nature and scale of a disruptive event and trigger controls; coordinate the response across functions and disciplines (for example with risk management, IT and business continuity); run the plans, processes and procedures for activating, operating, coordinating and communicating prevention, protection, mitigation, response and recovery; keep internal and external stakeholders informed, including the media, local authorities and supply chain partners; and judge the level of response, with authority to set actions for each stage and declare the situation over. Its procedures should address: protection of tangible and intangible assets; protection of people; the best ways to mitigate and respond so an event does not grow into a crisis or disaster; who may judge that an emergency exists and declare it, and how, then activate plans, assess damage and take financial decisions for continuity; internal and external communication plans, including notifying authorities and stakeholders; actions to secure physical and information assets; post-event evaluation leading to corrective and preventive action; periodic testing of the PPS in normal and abnormal conditions; the effect on the PAP system of losing critical infrastructure (power, water, communications, transport) and other dependencies such as IT; and the steps and resources for bringing the PAP system back within its recovery time objective. Procedures should be reviewed and revised, especially after incidents that escalated or nearly did, documented and updated regularly or when things change, and incident reports should feed management review.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 28000:2022 · 2 controls

  • 8.6.1 General: security plans and the response structure
  • 8.6.2 Response structure
  • 4.4.7 4.4.7 Incident prevention, preparedness and response procedures covering the twenty needs, reviewed after incidents, with competent personnel

ISO 27002:2022 · 1 control

  • 5.29 Information security during disruption

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.