ASIS SPC.1-2009 - Organizational Resilience Standard
4.1 and 4.2: General requirements and OR management policy – ASIS SPC.1-2009 - Organizational Resilience Standard

ASIS SPC.1-2009 - Organizational Resilience Standard 4.2.2: 4.2.2 Management commitment shown through policy, objectives, roles, an accountable appointee, communication, resources, risk criteria, audits and reviews

Management must show its commitment by setting the policy; seeing that objectives and plans exist; settling roles, duties and competences; naming one or more people with the authority and competence to answer for the management system; making clear why meeting objectives, following the policy, honouring legal duties and improving continually matter; supplying enough resources; deciding the criteria for accepting risk and what levels are acceptable; seeing that internal audits take place; holding management reviews; and showing it is committed to continual improvement.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 5.1 5.1 Top management shows leadership of the physical asset protection programme

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 4.1 and 4.2: General requirements and OR management policy – ASIS SPC.1-2009 - Organizational Resilience Standard

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.