DHS Adopts ASIS National Organizational Resilience Standard

The Department of Homeland Security has announced the adoption of the ASIS American National Standard for Organizational Resilience for the DHS’s Private Sector Preparedness (PS-Prep) Program.

The ANSI/ASIS SPC.1-2009 Standard, titled “Organizational Resilience: Security, Preparedness and Continuity Management Systems -- Requirements with Guidance for Use,” provides a holistic approach to cost-effectively improve any organization’s resilience and preparedness performance.

ANSI/ASIS SPC.1-2009, also known as the ASIS Organizational Resilience Standard, is the only standard that helps an organization design a balanced system to reduce the likelihood and minimize the consequences of disruptive events.

It provides a framework for businesses to assess the risks of disruptive events, develop a proactive strategy for prevention, response and recovery, establish performance criteria, and evaluate opportunities for improvement. It empowers an organization to implement an organizational resilience management system appropriate to its needs and those of its stakeholders. The standard can be used by any organization wishing to enhance its resilience and preparedness, as well as seek certification recognized by PS-Prep.

“In light of the recent events in the Gulf, the importance of resilience cannot be understated,” said ASIS International President Joseph R. (Bob) Granger, CPP. “Preparing for, responding to and recovering from a disruption is not enough. Organizations need to be able to assess the potential for a disruption and minimize the likelihood. They also need to adapt to an ever-changing environment.”

“This standard provides organizations with a flexible tool they can use to tailor their resilience and preparedness needs to meet their business needs,” Granger said. “ASIS International is proud that the DHS has selected this standard to help businesses effectively address potential disruptions.”

One of only three preparedness standards included in PS-Prep, the ASIS standard takes an enterprise-wide view of risk management, enabling an organization to develop a comprehensive strategy to prevent when possible, prepare for, mitigate, respond to, and recover from a disruptive incident. It is the only American National Standard in the PS-Prep program that is 100 percent compatible with existing ISO management system standards, enabling a cost-saving integrated application with other internationally recognized ISO management system standards.

The importance of the ANSI/ASIS SPC.1-2009 was recently validated by ISO’s decision to develop an international standard for Organizational Resilience.

The ASIS standard is applicable to all sizes and types of organizations, from public to private, small to multinational, in manufacturing, service, storage or transportation, that want to:

  • Create a balanced strategy for both likelihood and consequence reduction for incident prevention and management.
  • Establish, implement, maintain and improve an organizational resilience management system.
  • Demonstrate resiliency and continuity for supply chain and contractual agreements.
  • Assure conformance with stated organizational resilience management policy.
  • Implement a maturity model approach to cost-effectively enhance resilience performance.
  • Make a self-determination and self-declaration of conformance with ANSI/ASIS SPC.1-2009.
  • Seek certification/registration of its organizational resilience management system by an accredited third-party certification body.
  • Leverage an existing investment in other ISO management system standards (e.g. ISO 9001, ISO 14001, ISO 27001, ISO 28000) to improve security, preparedness and continuity performance.
  • Integrate plans for managing the risks of disruptive events into their enterprise-wide risk management programs, consistent with the ISO 31000 for risk management.

“By adopting the ANSI/ASIS Organizational Resilience Standard, PS-Prep offers organizations a business-friendly, globally tested and proven method based on the ISO management system standard model, to improve their resilience and preparedness performance,” said Mark Geraci, CPP, chairman of the ASIS Commission on Standards and Guidelines.

As a complement to this effort, ASIS is offering a two-and-a-half-day class on Organizational Resilience: Implementing and Auditing the ANSI/ASIS American National Standard. Attendees will learn to implement the ANSI/ASIS standard, identify necessary steps to establish and maintain an organizational resilience management system, understand the conduct of risk assessments and impact analysis to support decision making for resilience, and establish an effective internal auditing program to evaluate and improve performance.

ASIS Standards and Guidelines are developed through a consensus standards-development process which seeks to advance security and resilience practices. This process brings together volunteers and/or seeks out the views of people who have an interest in the topic covered. This standard is available through the ASIS website, http://www.asisonline.org.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection. 3

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3