ISO 28002:2011
Requirements for a supply chain resilience policy built into a management system such as ISO 28000: context and end-to-end supply chain mapping, scope and strategic weightings, top management policy with life safety first, and the full management system cycle of risk and impact assessment with recovery time criteria, prevention, mitigation, response, continuity and recovery programmes, crisis teams, warning and communication, supplier verification, exercises, audit and management review. 37 leaves read against the complete identical Russian adoption.
ISO 28002:2011 is a compliance framework from International (ISO) with 6 domains and 37 controls that map to 2 other frameworks. The largest domains are Annex A: Implementation and operation – ISO 28002:2011 (10 controls), Annex A: Checking and corrective action – ISO 28002:2011 (7 controls), Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011 (7 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Annex A: Checking and corrective action – ISO 28002:2011
| Code | Title |
|---|---|
| iso-28002-2011::A.6.1 | A.6.1 General |
| iso-28002-2011::A.6.2 | A.6.2 Monitoring and measurement |
| iso-28002-2011::A.6.3.1 | A.6.3.1 Evaluation of compliance |
| iso-28002-2011::A.6.3.2 | A.6.3.2 Exercises and testing |
| iso-28002-2011::A.6.4 | A.6.4 Nonconformity, corrective and preventive action |
| iso-28002-2011::A.6.5 | A.6.5 Control of records |
| iso-28002-2011::A.6.6 | A.6.6 Internal audit |
Annex A: Implementation and operation – ISO 28002:2011
| Code | Title |
|---|---|
| iso-28002-2011::A.5.1 | A.5.1 Resources, roles, responsibility and authority for resilience management |
| iso-28002-2011::A.5.2 | A.5.2 Competence, training and awareness |
| iso-28002-2011::A.5.3 | A.5.3 Communication and warning |
| iso-28002-2011::A.5.4 | A.5.4 Documentation |
| iso-28002-2011::A.5.5 | A.5.5 Control of documents |
| iso-28002-2011::A.5.6 | A.5.6 Operational control |
| iso-28002-2011::A.5.7.1 | A.5.7.1 General |
| iso-28002-2011::A.5.7.2 | A.5.7.2 Prevention, preparedness and response structure |
| iso-28002-2011::A.5.7.3 | A.5.7.3 Incident prevention, protection and mitigation |
| iso-28002-2011::A.5.7.4 | A.5.7.4 Incident response |
Annex A: Management review – ISO 28002:2011
| Code | Title |
|---|---|
| iso-28002-2011::A.7.1 | A.7.1 General |
| iso-28002-2011::A.7.2 | A.7.2 Management review input |
| iso-28002-2011::A.7.3 | A.7.3 Management review output |
| iso-28002-2011::A.7.4 | A.7.4 Maintenance |
| iso-28002-2011::A.7.5 | A.7.5 Continual improvement |
Annex A: Planning – ISO 28002:2011
| Code | Title |
|---|---|
| iso-28002-2011::A.4.1 | A.4.1 Risk assessment and monitoring |
| iso-28002-2011::A.4.2 | A.4.2 Internal and external communication and consultation |
| iso-28002-2011::A.4.3 | A.4.3 Monitoring and review of the risk assessment process |
| iso-28002-2011::A.4.4 | A.4.4 Legal and other requirements |
| iso-28002-2011::A.4.5 | A.4.5 Resilience objectives and targets |
| iso-28002-2011::A.4.6 | A.4.6 Strategic resilience plans and programmes |
Annex A: Resilience policy and management responsibility – ISO 28002:2011
| Code | Title |
|---|---|
| iso-28002-2011::A.2 | A.2 Resilience management policy |
| iso-28002-2011::A.3 | A.3 Management responsibility |
Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011
| Code | Title |
|---|---|
| iso-28002-2011::4.1 | 4.1 General |
| iso-28002-2011::4.2.1 | 4.2.1 External and internal context |
| iso-28002-2011::4.2.2 | 4.2.2 Specific factors showing commitment to risk and resilience management |
| iso-28002-2011::4.3 | 4.3 Scope of the resilience management policy |
| iso-28002-2011::4.4 | 4.4 Provision of resources for the resilience management policy |
| iso-28002-2011::4.5 | 4.5 Resilience management policy |
| iso-28002-2011::4.6 | 4.6 Resilience policy statement |
Maps to 2 other frameworks
Coverage is not the same as your position
This page shows what ISO 28002:2011 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO 28002:2011 and who does it apply to?
ISO 28002:2011 is a compliance framework from International (ISO) with 6 domains and 37 controls. Requirements for a supply chain resilience policy built into a management system such as ISO 28000: context and end-to-end supply chain mapping, scope and strategic weightings, top management policy with life safety first, and the full management system cycle of risk and impact assessment with recovery time criteria, prevention, mitigation, response, continuity and recovery programmes, crisis teams, warning and communication, supplier verification, exercises, audit and management review. 37 leaves read against the complete identical Russian adoption. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 28002:2011 actually require?
ISO 28002:2011 has 37 controls organised across 6 domains. The largest domains are Annex A: Implementation and operation – ISO 28002:2011 (10 controls), Annex A: Checking and corrective action – ISO 28002:2011 (7 controls), Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011 (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 28002:2011 do I already cover?
ISO 28002:2011 maps to 2 other compliance frameworks. The top mapping partners are ISO 22301:2019 (97% coverage), ISO 28000:2022 (95% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO 28002:2011?
Start your ISO 28002:2011 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 28002:2011 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required