ISO 28002:2011
Annex A: Planning – ISO 28002:2011

ISO 28002:2011 A.4.6: A.4.6 Strategic resilience plans and programmes

The organization runs one or more strategic programmes to reach its objectives and targets, optimised and prioritised by likelihood and severity of supply chain disruption, each stating responsibility and resources by function and level; the activities, functions, legal and contractual obligations, supply chain, stakeholder needs, mutual aid agreements and context considered; and the means, timelines and resources for achieving the objectives. It keeps strategic plans and programmes for prevention and protection (avoiding, removing, deterring or preventing incidents, including moving people and assets out of harm's way), mitigation (limiting impact), response (the first reaction to protect people and property, possibly led by management), continuity (processes, controls and resources that keep critical business objectives met) and recovery (restoring processes, resources and capabilities to meet operating needs within the time set in the objectives). Programmes are checked for new risks they may create, reviewed periodically for effectiveness and amended where needed. Annex B adds that programmes cover the full life cycle from supply chain commitments and design to decommissioning, and address isolation of people and property at risk, protective systems, cyber security, and redundancy of key staff, systems, equipment, information and materials, including from partners.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 1 control

  • 8.3.2 Identification of strategies and solutions

ISO 28000:2022 · 1 control

  • 8.5.1 Identification and selection of strategies and treatments

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Planning – ISO 28002:2011

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.