ANSI/ASIS WVPI AA-2020 Workplace Violence and Active Assailant
Clause 11: Post-incident management – ANSI/ASIS WVPI AA-2020 Workplace Violence and Active Assailant

ANSI/ASIS WVPI AA-2020 Workplace Violence and Active Assailant 11.1: 11.1 General elements of a post-incident recovery plan

A post-incident recovery plan for workplace violence should consider: priority response protocols covering life safety and the immediate needs of those directly affected (medical care, stakeholder concerns), preserving evidence for the coming investigation, and protecting threatened core assets; crisis containment, gathering the facts quickly and fully, securing affected areas to protect information and the investigation, separating witnesses and anticipating other safety steps; continued threat assessment for renewed conflict, copycat attacks or a planned follow-on attack, and checking whether security or other gaps allowed the attack, with prompt steps to close them; coordination between the Threat Management Team and any crisis management team to assess ongoing threats, protect core assets, fully resolve the incident and resume business; notifications to managers elsewhere under a pre-set plan, to employees with accurate and timely information through briefed internal communicators, to next of kin or partners after serious injury or death in consultation with police, to regulators promptly using a maintained list of required agencies and numbers, and to the news media in coordination with the incident management team through a briefed spokesperson who knows what may be released and when victims' names may be given, together with ongoing communication with all affected stakeholders; mobilizing resources such as extra security, insurance and risk services and qualified temporary staff, using the principles of the ASIS organizational and supply chain resilience standard; mental health services for those affected; a liaison for cooperation and communication with police where a crime is known or suspected; prompt legal review of possible claims and advice across post-incident operations; a family representative program with trained, multidisciplinary representatives; protection of core assets such as reputation, brand, trust, operations and property; and advance thought on business operations, including orderly shutdown, continuation or cessation, product recall and management of employees.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 2 controls

ISO 45003:2021 · 1 control

  • 8.2 8.2 Emergency preparedness and response

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.