United States (ANSI-accredited standard, used internationally; adopted under DHS PS-Prep in 2010)

ASIS SPC.1-2009

77 controls. 326 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

77 controls 326 frameworks share controls with it United States (ANSI-accredited standard, used internationally; adopted under DHS PS-Prep in 2010) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
4.3.1Risk Assessment and Impact Analysis161
4.3.2Legal and Other Requirements55
4.3.3Objectives and Programs0
4.4.1Resources, Roles, Responsibility, and Authority194
4.4.2Competence, Training, and Awareness55
4.4.3Communication and Warning13
4.4.4Documentation1
4.4.5Operational Control0
4.4.6Prevention and Mitigation0
4.4.7Emergency and Incident Response141
4.4.8Business Continuity and Recovery90
4.4.9Mutual Aid and Cooperation0
4.5.1Performance Monitoring and Measurement0
4.5.2Evaluation of Compliance3
4.5.3Corrective and Preventive Action0
4.5.4Control of Records3
4.5.5Internal Audit14
4.6.1Management Review Process0
4.6.2Review Input1
4.6.3Review Output1
SPC1-4.1Resilience Management System Scope0
SPC1-4.2Resilience Policy0
SPC1-4.3.1Risk Assessment and Impact Analysis4
SPC1-4.3.2Legal and Other Requirements0
SPC1-4.3.3Objectives and Targets0
SPC1-4.3.4Resilience Programs0
SPC1-4.4.1Resources, Roles, Responsibility, and Authority0
SPC1-4.4.2Competence, Training, and Awareness0
SPC1-4.4.3Communication and Warning13
SPC1-4.4.4Documentation1
SPC1-4.4.5Control of Documents2
SPC1-4.4.6Operational Control0
SPC1-4.4.7Incident Prevention, Preparedness, and Response0
SPC1-4.4.8Business Continuity and Recovery0
SPC1-4.5.1Monitoring and Measurement2
SPC1-4.5.2Evaluation of Compliance3
SPC1-4.5.3Exercises and Testing0
SPC1-4.5.4Nonconformity, Corrective and Preventive Action10
SPC1-4.5.5Records1
SPC1-4.5.6Internal Audit14
SPC1-4.6Management Review15
SPC1-A.1Continual Improvement16
4.14.1 An OR management system established, documented, implemented, maintained and continually improved0
4.1.14.1.1 A documented scope with boundaries, requirements, critical objectives, risk scenarios and a Statement of Applicability0
4.24.2 Top management defines, documents and resources an OR management policy0
4.2.14.2.1 A policy statement meeting fifteen conditions, from life safety first to annual signed review0
4.2.24.2.2 Management commitment shown through policy, objectives, roles, an accountable appointee, communication, resources, risk criteria, audits and reviews0
4.3.14.3.1 A formal, documented risk assessment and impact analysis with recovery time objectives0
4.3.24.3.2 Procedures to identify and apply legal, regulatory and other requirements0
4.3.34.3.3 Measurable objectives and targets, and strategic programmes for prevention, mitigation, response, continuity and recovery0
4.4.14.4.1 Resources, defined roles, a management representative, an OR management team, logistics, resource objectives and expedited financial procedures0
4.4.24.4.2 Competence with records, identified training needs, awareness procedures and an embedded OR culture0
4.4.34.4.3 Communication and warning procedures, a documented decision on external communication, and regular testing0
4.4.44.4.4 Documentation of the policy, objectives, scope, main elements and required documents and records0
4.4.54.4.5 Control of documents: approval, review, revision status, availability, retention, legibility, external documents, obsolescence and integrity0
4.4.64.4.6 Operational control of operations linked to significant risks, with procedures communicated to suppliers0
4.4.74.4.7 Incident prevention, preparedness and response procedures covering the twenty needs, reviewed after incidents, with competent personnel0
4.54.5 Plans, procedures and capabilities evaluated periodically with records kept0
4.5.14.5.1 Performance metrics and monitoring procedures, including partnership and supply chain relationships and protective systems0
4.5.24.5.2 Evaluation of compliance and system performance0
4.5.2.14.5.2.1 Periodic evaluation of compliance with legal, regulatory and other requirements0
4.5.2.24.5.2.2 Exercises and testing that validate the system on realistic scenarios with formal post-exercise reports0
4.5.34.5.3 Nonconformity, corrective and preventive action procedures with changed risks prioritised0
4.5.44.5.4 Records established and protected: access, identification, storage, protection, retrieval, retention and disposal0
4.5.54.5.5 Planned internal audits by objective auditors with follow-up verification0
4.6.14.6.1 Management review at planned intervals with documented results0
4.6.24.6.2 Review inputs: audits, feedback, improvement techniques, actions, exercises, unaddressed threats, measurements, follow-ups, changes, policy adequacy and recommendations0
4.6.34.6.3 Review outputs: system improvement, updated risk assessment and plans, modified procedures and controls, resources and measurement0
4.6.44.6.4 A documented maintenance programme reviewing internal and external change against the system0
4.6.54.6.5 Continual improvement through policy, objectives, audits, event analysis, actions and review0
C4.5: Checking (evaluation)0
G4.1 and 4.2: General requirements and OR management policy0
I4.4: Implementation and operation0
M4.6: Management review0
P4.3: Planning0
STDASIS SPC.1-2009: what it is, its adoption under PS-Prep, what is held, and its supersession0
USEScope, terms and the Annex A guidance0

Tell me when ASIS SPC.1-2009 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Records retention schedule
  • Retention schedule
  • Retention schedule and disposal records
  • Records inventory
  • Document management platform export
  • Evidence repository index
  • Roles and responsibilities matrix
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ASIS SPC.1-2009, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition