ASIS SPC.1-2009 - Organizational Resilience Standard
4.1 and 4.2: General requirements and OR management policy – ASIS SPC.1-2009 - Organizational Resilience Standard

ASIS SPC.1-2009 - Organizational Resilience Standard 4.1.1: 4.1.1 A documented scope with boundaries, requirements, critical objectives, risk scenarios and a Statement of Applicability

The organization must fix and record what its OR management system covers: which parts of the organization fall inside it (all of it or named parts); the resilience requirements that flow from its mission, aims, duties to stakeholders and legal obligations; the objectives, assets, functions, services and products critical to its operations; the risk scenarios, from events inside or outside, that could strike them; and a coverage suited to its size, nature and complexity. The scope must safeguard the organization's integrity and its ties with suppliers, outsourcing partners, customers, shareholders and the community, and a Statement of Applicability must set, on the strength of the risk assessment and impact analysis, how much strategic weight goes to each of security, preparedness, emergency, disaster, crisis and business continuity management.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 6.2.4 6.2.4 PAPMS scope and boundaries defined and retained

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 4.1 and 4.2: General requirements and OR management policy – ASIS SPC.1-2009 - Organizational Resilience Standard

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.