ASIS SPC.1-2009 - Organizational Resilience Standard
ASIS SPC.1-2009 (Organizational Resilience: Security, Preparedness, and Continuity Management Systems - Requirements with Guidance for Use) is an American National Standard that establishes requirements for a management system to enhance organizational resilience. Published by ASIS International, it integrates security management, emergency management, and business continuity into a unified resilience management system. Certifiable standard used primarily in North America.
ASIS SPC.1-2009 - Organizational Resilience Standard is a compliance framework from United States (ASIS/ANSI) with 12 domains and 42 controls that map to 319 other frameworks. The largest domains are Check (6 controls), Checking and Corrective Action (5 controls), Implementation and Operation (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Act
Check
| Code | Title |
|---|---|
| SPC1-4.5.1 | Monitoring and Measurement |
| SPC1-4.5.2 | Evaluation of Compliance |
| SPC1-4.5.3 | Exercises and Testing |
| SPC1-4.5.4 | Nonconformity, Corrective and Preventive Action |
| SPC1-4.5.5 | Records |
| SPC1-4.5.6 | Internal Audit |
Checking and Corrective Action
Context
| Code | Title |
|---|---|
| SPC1-4.1 | Resilience Management System Scope |
Implementation and Operation
Incident Prevention, Preparedness, and Response
Leadership
| Code | Title |
|---|---|
| SPC1-4.2 | Resilience Policy |
Management Review
Operation
| Code | Title |
|---|---|
| SPC1-4.4.6 | Operational Control |
| SPC1-4.4.7 | Incident Prevention, Preparedness, and Response |
| SPC1-4.4.8 | Business Continuity and Recovery |
Planning
| Code | Title |
|---|---|
| SPC1-4.3.1 | Risk Assessment and Impact Analysis |
| SPC1-4.3.2 | Legal and Other Requirements |
| SPC1-4.3.3 | Objectives and Targets |
| SPC1-4.3.4 | Resilience Programs |
Policy and Planning
Support
| Code | Title |
|---|---|
| SPC1-4.4.1 | Resources, Roles, Responsibility, and Authority |
| SPC1-4.4.2 | Competence, Training, and Awareness |
| SPC1-4.4.3 | Communication and Warning |
| SPC1-4.4.4 | Documentation |
| SPC1-4.4.5 | Control of Documents |
Your Compliance Coverage
If you comply with ASIS SPC.1-2009 - Organizational Resilience Standard, you already cover:
ISO 13485:2016
29%
12 controls mapped
Compare →ISO 22301:2019
21%
9 controls mapped
Compare →ISO 14001:2015
21%
9 controls mapped
Compare →+ 316 more: ISO 45001:2018 (19%), ISO 27701:2019 (19%)
See all 319 mapped frameworks ↓Maps to 319 other frameworks
What is ASIS SPC.1-2009 - Organizational Resilience Standard and who does it apply to?
ASIS SPC.1-2009 - Organizational Resilience Standard is a compliance framework from United States (ASIS/ANSI) with 12 domains and 42 controls. ASIS SPC.1-2009 (Organizational Resilience: Security, Preparedness, and Continuity Management Systems - Requirements with Guidance for Use) is an American National Standard that establishes requirements for a management system to enhance organizational resilience. Published by ASIS International, it integrates security management, emergency management, and business continuity into a unified resilience management system. Certifiable standard used primarily in North America. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ASIS SPC.1-2009 - Organizational Resilience Standard actually require?
ASIS SPC.1-2009 - Organizational Resilience Standard has 42 controls organised across 12 domains. The largest domains are Check (6 controls), Checking and Corrective Action (5 controls), Implementation and Operation (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ASIS SPC.1-2009 - Organizational Resilience Standard do I already cover?
ASIS SPC.1-2009 - Organizational Resilience Standard maps to 319 other compliance frameworks. The top mapping partners are ISO 13485:2016 (29% coverage), ISO 22301:2019 (21% coverage), ISO 14001:2015 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ASIS SPC.1-2009 - Organizational Resilience Standard?
Start your ASIS SPC.1-2009 - Organizational Resilience Standard compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASIS SPC.1-2009 - Organizational Resilience Standard requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required