ISO 28002:2011
Annex A: Implementation and operation – ISO 28002:2011

ISO 28002:2011 A.5.1: A.5.1 Resources, roles, responsibility and authority for resilience management

Roles, responsibilities and authority are defined, documented and communicated so resilience is managed effectively. Top management appoints a management representative who, whatever other duties they hold, is responsible for: making sure the policy is set up, implemented, communicated and maintained to this standard; identifying and watching the needs and expectations of supply chain partners and stakeholders and acting to manage them; making sure resources are available; and reporting on the policy's performance to top management for review and improvement. The organization establishes: resilience, crisis management and response teams with defined roles, authority and resources to handle incident prevention, preparedness, response and recovery; logistics capability and procedures for finding, obtaining, storing, distributing, servicing and testing, and keeping account of, the services, staff, resources, materials and facilities that are made or given to back the system; resource management objectives covering staff, equipment and training, facilities and funds, insurance and liability, expertise, materials, and by when each must be on hand, drawn from its own and its partners' resources so response times can be met; and procedures for stakeholder assistance and communication, strategic alliances and mutual aid. Financial and administrative procedures support the policy before, during and after an incident, allowing funding decisions to be made quickly within set authority levels and accounting rules. Annex B describes the crisis management team's span (people, IT, facilities, security, legal, communications, media, production, warehousing) and response teams for damage assessment, site restoration, payroll, HR, IT and administration.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 28000:2022 · 2 controls

  • 5.3 Roles, responsibilities and authorities
  • 8.5.2 Resource requirements

ISO 22301:2019 · 1 control

  • 5.3 Roles, responsibilities and authorities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Implementation and operation – ISO 28002:2011

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.