ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection B.9: B.9 Security policies and procedures

The organization should keep procedures for protecting assets that are concise and accessible to those who carry them out, using flow charts, diagrams, tables and action lists alongside text. Top management should agree each procedure's purpose and scope and those responsible should understand it; critical interdependencies and links with other procedures, including links to police, emergency responders and local government, should be stated. Procedures should explain the proactive architectural, administrative, design, operational and technological steps that avoid risks, remove them or make them less likely (unforeseen threats and hazards included) and soften their consequences. A single procedure with sections per incident type or separate procedures per type are both acceptable. Each should state at least: purpose and scope; assets to protect from malicious or disruptive events; objectives and measures of success; implementation steps and how often the procedure runs; roles, responsibilities and authorities; communication requirements; internal and external interdependencies; resource, competence and training needs; information flow and documentation; and how it is reviewed and revised. Each procedure should have a named owner and a stated person responsible for review, amendment and update, with review, amendment, update and distribution controlled.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.4.6 4.4.6 Operational control of operations linked to significant risks, with procedures communicated to suppliers

ISO 27002:2022 · 1 control

  • 5.37 Documented operating procedures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.