ISO 28002:2011
Annex A: Planning – ISO 28002:2011

ISO 28002:2011 A.4.5: A.4.5 Resilience objectives and targets

The organization documents objectives and targets for managing risk so that disruptive incidents are prevented, avoided, contained and mitigated, and so that it can respond and recover when one occurs, stating the internal and external expectations, across the organization and its supply chain, that are critical to its mission, product and service delivery and operations. Objectives follow from the policy and the risk assessment and commit to: reducing risk by lowering likelihood and severity; raising resilience through adaptive, proactive and reactive approaches that account for financial, operational and business needs including the supply chain; meeting legal and other requirements; and continual improvement. In setting and revising them the organization weighs legal requirements, significant risks, technology options, financial, operational and business needs, and the views of stakeholders. Targets are measured qualitatively or quantitatively, derived from the objectives and: detailed enough; in line with the risk assessment and recovery time objectives; specific, measurable, achievable, relevant and time-bound where practical; made known to staff and third parties such as contractors and supply chain partners so they know their part; and reviewed and adjusted periodically.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 1 control

  • 6.2.1 Establishing business continuity objectives

ISO 28000:2022 · 1 control

  • 6.2.1 Establishing security objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Planning – ISO 28002:2011

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.