ISO 28002:2011
Annex A: Implementation and operation – ISO 28002:2011

ISO 28002:2011 A.5.6: A.5.6 Operational control

The organization identifies the operations and activities needed to achieve its resilience policy, control activities with significant risk, meet legal requirements, reach its objectives, deliver its programmes and give the required level of supply chain resilience. For operations tied to significant risks it keeps adaptive and proactive plans and procedures so they run under conditions that minimise risk: procedures for the identified hazards, threats and risks in its activities, functions, goods and services, shared with the supply chain and contractors; documented procedures for situations in which the lack of a written procedure might cause a departure from policy, objectives and targets; assessment of risks at the pre-control and post-control stages of supply chain activity, with a procedure to reduce the likelihood and severity of disruption; requirements for goods and services that affect resilience, passed to suppliers; and stated operating criteria. Procedures include controls for design, installation, operation and restoration of resilience-related equipment, logistics flows and instruments. Before new or revised arrangements that could affect resilience (new structure or roles, revised policy or programmes, new processes, new infrastructure, equipment, hardware or software, new contractors, suppliers, partners or staff) the organization considers the associated risks. Operational procedures deal with keeping people safe, healthy and resilient and with shielding property and the environment; name owners of risks, treatments and controls, internal and external; make sure demand signals feed capacity planning; verify supplier claims such as plant, process or product recovery times; suit the supply chain resilience objectives; and give feedback on whether risk strategies change with normal development, process change or supplier decisions.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 28000:2022 · 2 controls

  • 8.2 Identification of processes and activities
  • 8.4 Controls

ISO 22301:2019 · 1 control

  • 8.1 Operational planning and control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Implementation and operation – ISO 28002:2011

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.