The organization identifies the operations and activities needed to achieve its resilience policy, control activities with significant risk, meet legal requirements, reach its objectives, deliver its programmes and give the required level of supply chain resilience. For operations tied to significant risks it keeps adaptive and proactive plans and procedures so they run under conditions that minimise risk: procedures for the identified hazards, threats and risks in its activities, functions, goods and services, shared with the supply chain and contractors; documented procedures for situations in which the lack of a written procedure might cause a departure from policy, objectives and targets; assessment of risks at the pre-control and post-control stages of supply chain activity, with a procedure to reduce the likelihood and severity of disruption; requirements for goods and services that affect resilience, passed to suppliers; and stated operating criteria. Procedures include controls for design, installation, operation and restoration of resilience-related equipment, logistics flows and instruments. Before new or revised arrangements that could affect resilience (new structure or roles, revised policy or programmes, new processes, new infrastructure, equipment, hardware or software, new contractors, suppliers, partners or staff) the organization considers the associated risks. Operational procedures deal with keeping people safe, healthy and resilient and with shielding property and the environment; name owners of risks, treatments and controls, internal and external; make sure demand signals feed capacity planning; verify supplier claims such as plant, process or product recovery times; suit the supply chain resilience objectives; and give feedback on whether risk strategies change with normal development, process change or supplier decisions.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.