ASIS SPC.1-2009 - Organizational Resilience Standard
ASIS SPC.1-2009 (Organizational Resilience: Security, Preparedness, and Continuity Management Systems - Requirements with Guidance for Use) is an American National Standard that establishes requirements for a management system to enhance organizational resilience. Published by ASIS International, it integrates security management, emergency management, and business continuity into a unified resilience management system. Certifiable standard used primarily in North America.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Act
| Code | Title |
|---|---|
| SPC1-4.6 | Management Review |
| SPC1-A.1 | Continual Improvement |
Check
| Code | Title |
|---|---|
| SPC1-4.5.1 | Monitoring and Measurement |
| SPC1-4.5.2 | Evaluation of Compliance |
| SPC1-4.5.3 | Exercises and Testing |
| SPC1-4.5.4 | Nonconformity, Corrective and Preventive Action |
| SPC1-4.5.5 | Records |
| SPC1-4.5.6 | Internal Audit |
Checking and Corrective Action
| Code | Title |
|---|---|
| 4.5.1 | Performance Monitoring and Measurement |
| 4.5.2 | Evaluation of Compliance |
| 4.5.3 | Corrective and Preventive Action |
| 4.5.4 | Control of Records |
| 4.5.5 | Internal Audit |
Context
| Code | Title |
|---|---|
| SPC1-4.1 | Resilience Management System Scope |
Implementation and Operation
| Code | Title |
|---|---|
| 4.4.1 | Resources, Roles, Responsibility, and Authority |
| 4.4.2 | Competence, Training, and Awareness |
| 4.4.3 | Communication and Warning |
| 4.4.4 | Documentation |
| 4.4.5 | Operational Control |
Incident Prevention, Preparedness, and Response
| Code | Title |
|---|---|
| 4.4.6 | Prevention and Mitigation |
| 4.4.7 | Emergency and Incident Response |
| 4.4.8 | Business Continuity and Recovery |
| 4.4.9 | Mutual Aid and Cooperation |
Leadership
| Code | Title |
|---|---|
| SPC1-4.2 | Resilience Policy |
Management Review
| Code | Title |
|---|---|
| 4.6.1 | Management Review Process |
| 4.6.2 | Review Input |
| 4.6.3 | Review Output |
Operation
| Code | Title |
|---|---|
| SPC1-4.4.6 | Operational Control |
| SPC1-4.4.7 | Incident Prevention, Preparedness, and Response |
| SPC1-4.4.8 | Business Continuity and Recovery |
Planning
| Code | Title |
|---|---|
| SPC1-4.3.1 | Risk Assessment and Impact Analysis |
| SPC1-4.3.2 | Legal and Other Requirements |
| SPC1-4.3.3 | Objectives and Targets |
| SPC1-4.3.4 | Resilience Programs |
Policy and Planning
| Code | Title |
|---|---|
| 4.3.1 | Risk Assessment and Impact Analysis |
| 4.3.2 | Legal and Other Requirements |
| 4.3.3 | Objectives and Programs |
Support
| Code | Title |
|---|---|
| SPC1-4.4.1 | Resources, Roles, Responsibility, and Authority |
| SPC1-4.4.2 | Competence, Training, and Awareness |
| SPC1-4.4.3 | Communication and Warning |
| SPC1-4.4.4 | Documentation |
| SPC1-4.4.5 | Control of Documents |
Your Compliance Coverage
If you comply with ASIS SPC.1-2009 - Organizational Resilience Standard, you already cover:
ISO 50001:2018 - Energy Management Systems
29%
12 controls mapped
Compare →ISO 13485:2016
29%
12 controls mapped
Compare →ISO/IEC 42001:2023
21%
9 controls mapped
Compare →+ 311 more: ISO 22301:2019 (21%), ISO 14001:2015 (21%)
See all 314 mapped frameworks ↓Maps to 314 other frameworks
Frequently Asked Questions
What is ASIS SPC.1-2009 - Organizational Resilience Standard?
ASIS SPC.1-2009 - Organizational Resilience Standard is a compliance framework from United States (ASIS/ANSI) with 12 domains and 42 controls. ASIS SPC.1-2009 (Organizational Resilience: Security, Preparedness, and Continuity Management Systems - Requirements with Guidance for Use) is an American National Standard that establishes requirements for a management system to enhance organizational resilience. Published by ASIS International, it integrates security management, emergency management, and business continuity into a unified resilience management system. Certifiable standard used primarily in North America. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ASIS SPC.1-2009 - Organizational Resilience Standard have?
ASIS SPC.1-2009 - Organizational Resilience Standard has 42 controls organised across 12 domains. The largest domains are Check (6 controls), Checking and Corrective Action (5 controls), Implementation and Operation (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ASIS SPC.1-2009 - Organizational Resilience Standard map to?
ASIS SPC.1-2009 - Organizational Resilience Standard maps to 314 other compliance frameworks. The top mapping partners are ISO 50001:2018 - Energy Management Systems (29% coverage), ISO 13485:2016 (29% coverage), ISO/IEC 42001:2023 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ASIS SPC.1-2009 - Organizational Resilience Standard compliance?
Start your ASIS SPC.1-2009 - Organizational Resilience Standard compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASIS SPC.1-2009 - Organizational Resilience Standard requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required