ISO 28002:2011
Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011

ISO 28002:2011 4.6: 4.6 Resilience policy statement

When the standard is applied inside an existing management system, a policy statement is written that fits the nature and scale of the threats, hazards, risks and their possible impacts on the organization's activities, functions, goods, services and supply chain. The policy: puts the safety of employees and the public first; commits to continual improvement; commits to improving organizational structure, resilience and supply chain continuity; commits to adaptive and proactive risk mitigation; commits to meeting applicable legal and other requirements; defines and documents the risk tolerance for the scope, stating where in the management system resilience is handled; gives a framework for setting and reviewing resilience objectives and targets; and states exclusions and limits. It also names the person responsible for the policy with contact details, says how the policy is documented, implemented and maintained, is communicated to staff and those acting on the organization's behalf, and is available to stakeholders. The organization may publish a non-confidential version; the policy is reviewed at planned intervals and after significant change, and formally approved by top management.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 1 control

  • 5.2.1 Establishing the business continuity policy

ISO 28000:2022 · 1 control

  • 5.2.2 Security policy requirements

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.