ISO 28002:2011
Annex A: Implementation and operation – ISO 28002:2011

ISO 28002:2011 A.5.4: A.5.4 Documentation

The resilience documentation includes the policy, objectives and targets; a description of the scope; a description of the main elements and how they are built into the relevant documents; the documents and records this standard requires; and those the organization finds necessary to plan and control processes linked to significant risks. The organization judges how sensitive the information is and protects it from unauthorised access. Annex B says the level of detail depends on size, complexity and staff competence, and that a procedure is documented where failure would harm people, assets or the environment, where compliance must be shown, or where consistency matters.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 1 control

ISO 28000:2022 · 1 control

  • 7.5.1 General: the documented information of the system

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Implementation and operation – ISO 28002:2011

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.