4.3.1 | Risk Assessment and Impact Analysis | 161 |
4.3.2 | Legal and Other Requirements | 55 |
4.3.3 | Objectives and Programs | 0 |
4.4.1 | Resources, Roles, Responsibility, and Authority | 194 |
4.4.2 | Competence, Training, and Awareness | 55 |
4.4.3 | Communication and Warning | 13 |
4.4.4 | Documentation | 1 |
4.4.5 | Operational Control | 0 |
4.4.6 | Prevention and Mitigation | 0 |
4.4.7 | Emergency and Incident Response | 141 |
4.4.8 | Business Continuity and Recovery | 90 |
4.4.9 | Mutual Aid and Cooperation | 0 |
4.5.1 | Performance Monitoring and Measurement | 0 |
4.5.2 | Evaluation of Compliance | 3 |
4.5.3 | Corrective and Preventive Action | 0 |
4.5.4 | Control of Records | 3 |
4.5.5 | Internal Audit | 14 |
4.6.1 | Management Review Process | 0 |
4.6.2 | Review Input | 1 |
4.6.3 | Review Output | 1 |
SPC1-4.1 | Resilience Management System Scope | 0 |
SPC1-4.2 | Resilience Policy | 0 |
SPC1-4.3.1 | Risk Assessment and Impact Analysis | 4 |
SPC1-4.3.2 | Legal and Other Requirements | 0 |
SPC1-4.3.3 | Objectives and Targets | 0 |
SPC1-4.3.4 | Resilience Programs | 0 |
SPC1-4.4.1 | Resources, Roles, Responsibility, and Authority | 0 |
SPC1-4.4.2 | Competence, Training, and Awareness | 0 |
SPC1-4.4.3 | Communication and Warning | 13 |
SPC1-4.4.4 | Documentation | 1 |
SPC1-4.4.5 | Control of Documents | 2 |
SPC1-4.4.6 | Operational Control | 0 |
SPC1-4.4.7 | Incident Prevention, Preparedness, and Response | 0 |
SPC1-4.4.8 | Business Continuity and Recovery | 0 |
SPC1-4.5.1 | Monitoring and Measurement | 2 |
SPC1-4.5.2 | Evaluation of Compliance | 3 |
SPC1-4.5.3 | Exercises and Testing | 0 |
SPC1-4.5.4 | Nonconformity, Corrective and Preventive Action | 10 |
SPC1-4.5.5 | Records | 1 |
SPC1-4.5.6 | Internal Audit | 14 |
SPC1-4.6 | Management Review | 15 |
SPC1-A.1 | Continual Improvement | 16 |
4.1 | 4.1 An OR management system established, documented, implemented, maintained and continually improved | 0 |
4.1.1 | 4.1.1 A documented scope with boundaries, requirements, critical objectives, risk scenarios and a Statement of Applicability | 0 |
4.2 | 4.2 Top management defines, documents and resources an OR management policy | 0 |
4.2.1 | 4.2.1 A policy statement meeting fifteen conditions, from life safety first to annual signed review | 0 |
4.2.2 | 4.2.2 Management commitment shown through policy, objectives, roles, an accountable appointee, communication, resources, risk criteria, audits and reviews | 0 |
4.3.1 | 4.3.1 A formal, documented risk assessment and impact analysis with recovery time objectives | 0 |
4.3.2 | 4.3.2 Procedures to identify and apply legal, regulatory and other requirements | 0 |
4.3.3 | 4.3.3 Measurable objectives and targets, and strategic programmes for prevention, mitigation, response, continuity and recovery | 0 |
4.4.1 | 4.4.1 Resources, defined roles, a management representative, an OR management team, logistics, resource objectives and expedited financial procedures | 0 |
4.4.2 | 4.4.2 Competence with records, identified training needs, awareness procedures and an embedded OR culture | 0 |
4.4.3 | 4.4.3 Communication and warning procedures, a documented decision on external communication, and regular testing | 0 |
4.4.4 | 4.4.4 Documentation of the policy, objectives, scope, main elements and required documents and records | 0 |
4.4.5 | 4.4.5 Control of documents: approval, review, revision status, availability, retention, legibility, external documents, obsolescence and integrity | 0 |
4.4.6 | 4.4.6 Operational control of operations linked to significant risks, with procedures communicated to suppliers | 0 |
4.4.7 | 4.4.7 Incident prevention, preparedness and response procedures covering the twenty needs, reviewed after incidents, with competent personnel | 0 |
4.5 | 4.5 Plans, procedures and capabilities evaluated periodically with records kept | 0 |
4.5.1 | 4.5.1 Performance metrics and monitoring procedures, including partnership and supply chain relationships and protective systems | 0 |
4.5.2 | 4.5.2 Evaluation of compliance and system performance | 0 |
4.5.2.1 | 4.5.2.1 Periodic evaluation of compliance with legal, regulatory and other requirements | 0 |
4.5.2.2 | 4.5.2.2 Exercises and testing that validate the system on realistic scenarios with formal post-exercise reports | 0 |
4.5.3 | 4.5.3 Nonconformity, corrective and preventive action procedures with changed risks prioritised | 0 |
4.5.4 | 4.5.4 Records established and protected: access, identification, storage, protection, retrieval, retention and disposal | 0 |
4.5.5 | 4.5.5 Planned internal audits by objective auditors with follow-up verification | 0 |
4.6.1 | 4.6.1 Management review at planned intervals with documented results | 0 |
4.6.2 | 4.6.2 Review inputs: audits, feedback, improvement techniques, actions, exercises, unaddressed threats, measurements, follow-ups, changes, policy adequacy and recommendations | 0 |
4.6.3 | 4.6.3 Review outputs: system improvement, updated risk assessment and plans, modified procedures and controls, resources and measurement | 0 |
4.6.4 | 4.6.4 A documented maintenance programme reviewing internal and external change against the system | 0 |
4.6.5 | 4.6.5 Continual improvement through policy, objectives, audits, event analysis, actions and review | 0 |
C | 4.5: Checking (evaluation) | 0 |
G | 4.1 and 4.2: General requirements and OR management policy | 0 |
I | 4.4: Implementation and operation | 0 |
M | 4.6: Management review | 0 |
P | 4.3: Planning | 0 |
STD | ASIS SPC.1-2009: what it is, its adoption under PS-Prep, what is held, and its supersession | 0 |
USE | Scope, terms and the Annex A guidance | 0 |