ISO 28002:2011
Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011

ISO 28002:2011 4.3: 4.3 Scope of the resilience management policy

The organization defines and documents the objectives and scope of its resilience management policy, naming the particular internal and external context factors. In doing so it: sets the boundaries covered, which may be the whole organization, one or more units, or components of one or more end-to-end product or service flows in the supply chain; derives resilience management requirements from what the organization exists to do, its goals, and the duties it owes inside and outside, stakeholder and legal duties among them; considers critical objectives, assets, activities, functions, goods and services; identifies risks from internal and external disruptions that could harm operations and functions, in terms of likely impact; and sizes the scope to the scale, nature and complexity of its operations with continual improvement in view. The scope must allow the organization to protect and keep whole itself and its supply chain, including relationships with stakeholders, key suppliers, outsourcing partners and others (supply chain partners, customers, shareholders, the local community). Based on its risk assessment, it also gives strategic weightings to security, preparedness, mitigation, crisis, emergency, business continuity and disaster recovery management (see 4.4).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 1 control

  • 4.3.2 Scope of the business continuity management system

ISO 28000:2022 · 1 control

  • 4.3 Determining the scope of the security management system

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.