ASIS SPC.1-2009 - Organizational Resilience Standard
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Act
Top management reviews the RMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness.
- Review minutes
- Inputs package
- Actions register
- Review skipped during turnover
- No documented outputs
Continually improve the effectiveness of the resilience management system through policy, objectives, audit results, and corrective actions.
- Improvement register
- Trend analysis
- No improvement metric tracked
Check
Monitor and measure the performance of resilience activities and controls on a regular basis.
- KPI reports
- Performance dashboards
- Measurement procedure
- No leading indicators
- Measurement infrequent
Periodically evaluate compliance with applicable legal and other requirements.
- Compliance review records
- Findings log
- No formal review cadence
Conduct exercises and tests to validate the resilience management system at planned intervals.
- Exercise schedule
- Scenarios
- After-action reports
- Improvement actions
- Tabletop only, no functional test
- No cross-functional exercise
Identify nonconformities and implement corrective and preventive actions to address root causes.
- NC log
- Root cause analyses
- CAPA tracker
- No verification of effectiveness
- Repeat NCs
Establish and maintain records to demonstrate conformity with RMS requirements.
- Records retention schedule
- Records inventory
- No retention schedule
Conduct internal audits at planned intervals to determine whether the RMS conforms to requirements and is effectively implemented.
- Audit program
- Audit reports
- Auditor competence records
- No independence
- Audit scope too narrow
Checking and Corrective Action
Organisation shall establish procedures to monitor and measure OR management system performance on a regular basis.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Audit findings without closure dates
Organisation shall periodically evaluate compliance with applicable legal and other requirements.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Internal audit programme and findings log
- Management review meeting minutes with actions
- CAPA register with root cause and verification
- Improvement programme tracker
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Audit findings without closure dates
- Management review skipped one or more cycles
- Root cause analysis is symptomatic only
Organisation shall establish procedures for taking corrective and preventive action to address nonconformities.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- CAPA register with root cause and verification
- Improvement programme tracker
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Root cause analysis is symptomatic only
- Effectiveness checks not performed
- Evidence is point in time rather than ongoing
Organisation shall maintain records to demonstrate conformity to the OR management system requirements.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- CAPA register with root cause and verification
- Improvement programme tracker
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Root cause analysis is symptomatic only
- Effectiveness checks not performed
- Evidence is point in time rather than ongoing
Organisation shall conduct internal audits at planned intervals to confirm the OR management system is effectively maintained.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Internal audit programme and findings log
- Management review meeting minutes with actions
- CAPA register with root cause and verification
- Improvement programme tracker
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Audit findings without closure dates
- Management review skipped one or more cycles
- Root cause analysis is symptomatic only
Context
Define the scope of the organizational resilience management system including boundaries, locations, and activities.
- RMS scope document
- Site/asset inventory
- Exclusion justification
- Scope omits third-party sites
- No documented boundary rationale
Implementation and Operation
Organisation shall ensure availability of resources and define roles, responsibilities, and authorities for resilience management.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
Personnel performing tasks that impact resilience shall be competent based on appropriate education, training, or experience.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Training completion records by role
- Phishing simulation results
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Role based training not delivered to high risk teams
- Training metrics not reported to leadership
- Evidence is point in time rather than ongoing
Organisation shall establish procedures for internal and external communication and early warning during incidents.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Organisation shall establish and maintain documentation for the OR management system including policy, objectives, and procedures.
- Signed and dated policy set with version history
- Annual review and approval records
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Policies past their review date
- No evidence policies were communicated to staff
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
Organisation shall identify operations and activities associated with identified risks and implement controls to manage them.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process maps with defined controls and owners
- Change control records
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Operational controls not linked to risks
- Change records missing rollback evidence
- Evidence is point in time rather than ongoing
Incident Prevention, Preparedness, and Response
Organisation shall establish procedures to prevent or mitigate the consequences of disruptive incidents.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
Organisation shall establish and maintain procedures for responding to emergencies, crises, and disruptive incidents.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
Organisation shall establish procedures for continuity and recovery of critical functions during and after disruptive events.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
Organisation shall establish arrangements for mutual aid and cooperation with external entities during incidents.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Process owner attestation
- Tooling configuration export
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Evidence is point in time rather than ongoing
Leadership
Top management establishes a documented resilience policy appropriate to the organization's risk environment.
- Signed resilience policy
- Board approval minutes
- Distribution log
- Policy not refreshed annually
- No CEO endorsement
Management Review
Top management shall review the OR management system at planned intervals to ensure its continuing suitability and effectiveness.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
Management review shall include results of audits, evaluations of compliance, stakeholder communications, and incident performance.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
Management review outputs shall include decisions and actions related to improvements to the OR management system.
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
Operation
Identify and plan operations associated with significant risks to ensure they are carried out under controlled conditions.
- SOPs
- Control matrix
- Records of execution
- No control mapped to top risks
Establish procedures to prevent, prepare for, and respond to incidents and emergencies.
- IR plan
- Emergency procedures
- Exercise reports
- After-action reviews
- Plans not exercised
- No lessons-learned process
Develop and implement plans for continuity of priority activities and recovery of operations after disruption.
- BCP
- Recovery plans
- Strategy options
- Validation results
- RTOs misaligned with BIA
- No alternate site test
Planning
Conduct risk assessment and business impact analysis to identify likelihood and consequences of disruptive events.
- Risk register
- BIA report
- Threat scenarios
- RTO/RPO matrix
- BIA not refreshed after material change
- No quantitative consequence rating
Identify and access applicable legal, regulatory, and other requirements related to resilience.
- Legal obligations register
- Jurisdictional mapping
- Review log
- No owner assigned
- Stale register
Establish measurable resilience objectives and targets at relevant functions and levels.
- Objectives register
- KPI dashboard
- Target tracking
- Objectives not measurable
- No link to risks
Establish programs to achieve resilience objectives covering prevention, mitigation, response, continuity, and recovery.
- Program charters
- Resource allocation
- Timelines
- Programs lack assigned owner
- No timeline tracking
Policy and Planning
Organisation shall identify and assess risks and impacts from potential internal and external events affecting critical operations.
- Risk register with likelihood, impact, and treatment plans
- Risk assessment methodology document
- Signed and dated policy set with version history
- Annual review and approval records
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Risk register not refreshed on a defined cadence
- Inherent vs residual risk scoring not documented
- Policies past their review date
- No evidence policies were communicated to staff
- Recovery objectives not tested end to end
Organisation shall identify and have access to applicable legal and other requirements related to resilience management.
- Signed and dated policy set with version history
- Annual review and approval records
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Scope statement signed by management
- Stakeholder and interested party register
- Policies past their review date
- No evidence policies were communicated to staff
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Scope boundaries unclear for cloud services
Organisation shall establish documented resilience objectives and programs at relevant functions and levels.
- Signed and dated policy set with version history
- Annual review and approval records
- BCP and DR plan with documented RTO and RPO
- Backup restore test reports
- Consent capture and withdrawal logs
- Data subject request workflow and SLA tracker
- Policies past their review date
- No evidence policies were communicated to staff
- Recovery objectives not tested end to end
- Backups not verified for integrity
- Consent records lack timestamp or version
Support
Define and document roles, responsibilities, accountabilities and authorities for resilience activities.
- RACI matrix
- Job descriptions
- Authority delegations
- Role overlap
- No deputy named
Ensure personnel are competent through education, training, or experience and maintain awareness records.
- Training matrix
- Completion records
- Competency assessments
- No competency baseline
- Gaps in records
Establish procedures for internal and external communication including warnings and alerts during disruptions.
- Comms plan
- Warning protocols
- Contact tree
- Test logs
- Untested call tree
- Stakeholder list outdated
Maintain documentation of the resilience management system in any media form.
- RMS manual
- Document index
- Version log
- Multiple versions in circulation
Control RMS documents to ensure they are approved, current, identifiable, and available where needed.
- Document control procedure
- Approval records
- Distribution list
- No retention schedule
- Obsolete docs not removed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.