ASIS SPC.1-2009 — Organizational Resilience Standard
ASIS SPC.1-2009 (Organizational Resilience: Security, Preparedness, and Continuity Management Systems — Requirements with Guidance for Use) is an American National Standard that establishes requirements for a management system to enhance organizational resilience. Published by ASIS International, it integrates security management, emergency management, and business continuity into a unified resilience management system. Certifiable standard used primarily in North America.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Checking and Corrective Action
| Code | Title |
|---|---|
| 4.5.1 | Performance Monitoring and Measurement |
| 4.5.2 | Evaluation of Compliance |
| 4.5.3 | Corrective and Preventive Action |
| 4.5.4 | Control of Records |
| 4.5.5 | Internal Audit |
Implementation and Operation
| Code | Title |
|---|---|
| 4.4.1 | Resources, Roles, Responsibility, and Authority |
| 4.4.2 | Competence, Training, and Awareness |
| 4.4.3 | Communication and Warning |
| 4.4.4 | Documentation |
| 4.4.5 | Operational Control |
Incident Prevention, Preparedness, and Response
| Code | Title |
|---|---|
| 4.4.6 | Prevention and Mitigation |
| 4.4.7 | Emergency and Incident Response |
| 4.4.8 | Business Continuity and Recovery |
| 4.4.9 | Mutual Aid and Cooperation |
Management Review
| Code | Title |
|---|---|
| 4.6.1 | Management Review Process |
| 4.6.2 | Review Input |
| 4.6.3 | Review Output |
Management System
Social performance management system requirements
Policy and Planning
| Code | Title |
|---|---|
| 4.1 | External Standards |
| 4.2 | Building Fabric and Facilities |
| 4.3.1 | Risk Assessment and Impact Analysis |
| 4.3.2 | Legal and Other Requirements |
| 4.3.3 | Objectives and Programs |
Maps to 607 other frameworks
Frequently Asked Questions
What is ASIS SPC.1-2009 — Organizational Resilience Standard?
ASIS SPC.1-2009 — Organizational Resilience Standard is a compliance framework from United States (ASIS/ANSI) with 6 domains and 22 controls. ASIS SPC.1-2009 (Organizational Resilience: Security, Preparedness, and Continuity Management Systems — Requirements with Guidance for Use) is an American National Standard that establishes requirements for a management system to enhance organizational resilience. Published by ASIS International, it integrates security management, emergency management, and business continuity into a unified resilience management system. Certifiable standard used primarily in North America. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ASIS SPC.1-2009 — Organizational Resilience Standard have?
ASIS SPC.1-2009 — Organizational Resilience Standard has 22 controls organised across 6 domains. The largest domains are Checking and Corrective Action (5 controls), Implementation and Operation (5 controls), Policy and Planning (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ASIS SPC.1-2009 — Organizational Resilience Standard map to?
ASIS SPC.1-2009 — Organizational Resilience Standard maps to 607 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements (27% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (27% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (27% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ASIS SPC.1-2009 — Organizational Resilience Standard compliance?
Start your ASIS SPC.1-2009 — Organizational Resilience Standard compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASIS SPC.1-2009 — Organizational Resilience Standard requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required