Back to Frameworks

ISO 28002:2011

International (ISO)
v2011 (first edition)
6 domains
37 controls

Requirements for a supply chain resilience policy built into a management system such as ISO 28000: context and end-to-end supply chain mapping, scope and strategic weightings, top management policy with life safety first, and the full management system cycle of risk and impact assessment with recovery time criteria, prevention, mitigation, response, continuity and recovery programmes, crisis teams, warning and communication, supplier verification, exercises, audit and management review. 37 leaves read against the complete identical Russian adoption.

Verified

ISO 28002:2011 is a compliance framework from International (ISO) with 6 domains and 37 controls that map to 2 other frameworks. The largest domains are Annex A: Implementation and operation – ISO 28002:2011 (10 controls), Annex A: Checking and corrective action – ISO 28002:2011 (7 controls), Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011 (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Annex A: Checking and corrective action – ISO 28002:2011

7 controls
Controls in the Annex A: Checking and corrective action – ISO 28002:2011 domain of ISO 28002:2011 — 7 controls
CodeTitle
iso-28002-2011::A.6.1A.6.1 General
iso-28002-2011::A.6.2A.6.2 Monitoring and measurement
iso-28002-2011::A.6.3.1A.6.3.1 Evaluation of compliance
iso-28002-2011::A.6.3.2A.6.3.2 Exercises and testing
iso-28002-2011::A.6.4A.6.4 Nonconformity, corrective and preventive action
iso-28002-2011::A.6.5A.6.5 Control of records
iso-28002-2011::A.6.6A.6.6 Internal audit

Annex A: Implementation and operation – ISO 28002:2011

10 controls
Controls in the Annex A: Implementation and operation – ISO 28002:2011 domain of ISO 28002:2011 — 10 controls
CodeTitle
iso-28002-2011::A.5.1A.5.1 Resources, roles, responsibility and authority for resilience management
iso-28002-2011::A.5.2A.5.2 Competence, training and awareness
iso-28002-2011::A.5.3A.5.3 Communication and warning
iso-28002-2011::A.5.4A.5.4 Documentation
iso-28002-2011::A.5.5A.5.5 Control of documents
iso-28002-2011::A.5.6A.5.6 Operational control
iso-28002-2011::A.5.7.1A.5.7.1 General
iso-28002-2011::A.5.7.2A.5.7.2 Prevention, preparedness and response structure
iso-28002-2011::A.5.7.3A.5.7.3 Incident prevention, protection and mitigation
iso-28002-2011::A.5.7.4A.5.7.4 Incident response

Annex A: Management review – ISO 28002:2011

5 controls
Controls in the Annex A: Management review – ISO 28002:2011 domain of ISO 28002:2011 — 5 controls
CodeTitle
iso-28002-2011::A.7.1A.7.1 General
iso-28002-2011::A.7.2A.7.2 Management review input
iso-28002-2011::A.7.3A.7.3 Management review output
iso-28002-2011::A.7.4A.7.4 Maintenance
iso-28002-2011::A.7.5A.7.5 Continual improvement

Annex A: Planning – ISO 28002:2011

6 controls
Controls in the Annex A: Planning – ISO 28002:2011 domain of ISO 28002:2011 — 6 controls
CodeTitle
iso-28002-2011::A.4.1A.4.1 Risk assessment and monitoring
iso-28002-2011::A.4.2A.4.2 Internal and external communication and consultation
iso-28002-2011::A.4.3A.4.3 Monitoring and review of the risk assessment process
iso-28002-2011::A.4.4A.4.4 Legal and other requirements
iso-28002-2011::A.4.5A.4.5 Resilience objectives and targets
iso-28002-2011::A.4.6A.4.6 Strategic resilience plans and programmes

Annex A: Resilience policy and management responsibility – ISO 28002:2011

2 controls
Controls in the Annex A: Resilience policy and management responsibility – ISO 28002:2011 domain of ISO 28002:2011 — 2 controls
CodeTitle
iso-28002-2011::A.2A.2 Resilience management policy
iso-28002-2011::A.3A.3 Management responsibility

Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011

7 controls
Controls in the Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011 domain of ISO 28002:2011 — 7 controls
CodeTitle
iso-28002-2011::4.14.1 General
iso-28002-2011::4.2.14.2.1 External and internal context
iso-28002-2011::4.2.24.2.2 Specific factors showing commitment to risk and resilience management
iso-28002-2011::4.34.3 Scope of the resilience management policy
iso-28002-2011::4.44.4 Provision of resources for the resilience management policy
iso-28002-2011::4.54.5 Resilience management policy
iso-28002-2011::4.64.6 Resilience policy statement

Maps to 2 other frameworks

37 total controls
ISO 22301:2019
36 source controls mapped|34 target controls covered
97%
ISO 28000:2022
35 source controls mapped|37 target controls covered
95%

Coverage is not the same as your position

This page shows what ISO 28002:2011 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ISO 28002:2011 and who does it apply to?

ISO 28002:2011 is a compliance framework from International (ISO) with 6 domains and 37 controls. Requirements for a supply chain resilience policy built into a management system such as ISO 28000: context and end-to-end supply chain mapping, scope and strategic weightings, top management policy with life safety first, and the full management system cycle of risk and impact assessment with recovery time criteria, prevention, mitigation, response, continuity and recovery programmes, crisis teams, warning and communication, supplier verification, exercises, audit and management review. 37 leaves read against the complete identical Russian adoption. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 28002:2011 actually require?

ISO 28002:2011 has 37 controls organised across 6 domains. The largest domains are Annex A: Implementation and operation – ISO 28002:2011 (10 controls), Annex A: Checking and corrective action – ISO 28002:2011 (7 controls), Clause 4: Requirements of the management system containing a resilience policy – ISO 28002:2011 (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 28002:2011 do I already cover?

ISO 28002:2011 maps to 2 other compliance frameworks. The top mapping partners are ISO 22301:2019 (97% coverage), ISO 28000:2022 (95% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO 28002:2011?

Start your ISO 28002:2011 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 28002:2011 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required