ISO 28002:2011
Annex A: Implementation and operation – ISO 28002:2011

ISO 28002:2011 A.5.2: A.5.2 Competence, training and awareness

Anyone whose tasks could prevent, cause, respond to, mitigate or affect significant hazards, threats and risks is competent through education, training or experience, with records kept. The organization identifies competence and training needs tied to its hazards, threats, risks and resilience policy, inside the organization and along its supply chain, and meets them by training or other action, keeping records. Procedures make everyone who works for the organization or acts in its name aware of: the significant hazards, threats and risks of their work and the benefit of better performance; procedures for preventing and containing incidents, limiting harm, protecting themselves, evacuating, responding, keeping going and getting back to normal; the importance of meeting the resilience policy and the supply chain security management system; their own roles in achieving conformity; the potential consequences of departing from procedures; and what they gain from doing their own work better. The organization builds and promotes a resilience culture that becomes part of its core values and governance across the chain, and makes supply chain partners and stakeholders aware of the policy and their role in resilience plans. Annex B adds contractor competence evidence, training of all staff in their incident duties (evacuation, shelter in place, accounting for staff, alternate sites, media enquiries), crisis and response team training at least once a year and on joining, and familiarising outside responders with relevant plan sections.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 2 controls

ISO 28000:2022 · 2 controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Implementation and operation – ISO 28002:2011

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.