When the standard is applied inside an existing management system, a policy statement is written that fits the nature and scale of the threats, hazards, risks and their possible impacts on the organization's activities, functions, goods, services and supply chain. The policy: puts the safety of employees and the public first; commits to continual improvement; commits to improving organizational structure, resilience and supply chain continuity; commits to adaptive and proactive risk mitigation; commits to meeting applicable legal and other requirements; defines and documents the risk tolerance for the scope, stating where in the management system resilience is handled; gives a framework for setting and reviewing resilience objectives and targets; and states exclusions and limits. It also names the person responsible for the policy with contact details, says how the policy is documented, implemented and maintained, is communicated to staff and those acting on the organization's behalf, and is available to stakeholders. The organization may publish a non-confidential version; the policy is reviewed at planned intervals and after significant change, and formally approved by top management.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.