security standards and guidelines development



Similar documents
Facility Security Design

Business Continuity Standards A Primer

Facility Security Design

Risk, Threat, and Vulnerability Assessment

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

Is Business Continuity Certification Right for Your Organization?

BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012

Business Continuity Trends, Requirements and Expectations in Brian Zawada (MBCP) Director of Consulting Services Avalution Consulting

On the New Voluntary Corporate Preparedness Accreditation and Certification Program

Internal Auditing: Assurance, Insight, and Objectivity

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

Physical Security: Introductory Applications and Technology

Business Continuity Management

Security Documents and Project Management Process

Shell s Health, Safety and Environment (HSE) management system (see Figure 11-1) provides the framework for managing all aspects of the development.

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

eet Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry Power and Utilities Fact Sheet

Organizational Security Track FAQ

Loss Control Webcast. Disaster Recovery Planning we re not in Kansas anymore

Business Continuity Management Policy

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

Fraud Risk Management

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance

Facility Security Design

Executive Summary. The United States Security Industry. Size and Scope, Insights, Trends, and Data

APC. ASIS Assets Protection Course. ASIS Assets Protection Course PAID. Distinctive Education. ASIS Delivers NOVEMBER 2015 APRIL 2016 MAY 2016

AS9100 B to C Revision

Boston University s Metropolitan College

Company Management System. Business Continuity in SIA

BUSINESS CONTINUITY POLICY

Temple university. Auditing a business continuity management BCM. November, 2015

Business Continuity Management Framework

Chapter 1: An Overview of Emergency Preparedness and Business Continuity

Physical Security: Introductory Applications and Technology

Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM

Business Continuity / Disaster Recovery Context

Reputation. Further excellence. business continuity. risk management. Data security

FREQUENTLY ASKED QUESTIONS

Business Continuity Policy

Physical Security: Introductory Applications and Technology

ISO 9001 and the Supply Chain

Business Continuity Management Planning Methodology

Beyond disaster recovery: becoming a resilient business.

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO AUDITS, CERTIFICATION AND TRAINING

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June

I S O I E C I N F O R M A T I O N S E C U R I T Y A U D I T T O O L

Business Continuity and Disaster Recovery Planning 3/16/2011. Lee Goldstein CPCP, MBCI President Business Contingency Group

API Q2 Specification for Quality Management System Requirements for Service Supply Organizations for the Petroleum and Natural Gas Industries

Il nuovo standard ISO sulla Business Continuity Scenari ed opportunità

BS BUSINESS CONTINUITY MANAGEMENT

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy

Governance, Risk and Compliance Update & Hot Topics Pittsburgh Chapter IIA December 3, 2012

Practice Guide BUSINESS CONTINUITY MANAGEMENT

National Cyber Security Policy -2013

Essex Clinical Commissioning Groups. Business Continuity Management System. Scope and Policy

Safety Through Accountability and Recognition Achieving a World Class Culture

Risk Based Internal Auditing & Enterprise Risk

SHARED ASSESSMENTS PROGRAM STANDARD INFORMATION GATHERING (SIG) QUESTIONNAIRE 2014 MAPPING TO OCC GUIDANCE ( ) ON THIRD PARTY RELATIONSHIPS

Risk mitigation for business resilience White paper. A comprehensive, best-practices approach to business resilience and risk mitigation.

Business Continuity Planning (800)

An Alternative Method for Maintaining ISO 9001/2/3 Certification / Registration

WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy

Using Strategic Risk Management to Gain Assurance and Communicate More Effectively

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

The Information Security Management System According ISO The Value for Services

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

Business Resilience and Risk Management

Business Continuity Management

ISO 22301:2012 Societal Security Appendix B Business Continuity Management Systems Requirements 347

Risk Management. Policy

Committed to Environment, Health, & Safety

Using the GPGs to Solve Business Continuity Problems

Intel Business Continuity Practices

Moving from BS to ISO The new international standard for business continuity management systems. Transition Guide

Business continuity management policy

FFIEC Cybersecurity Assessment Tool

Table of Contents... 1

Information Security Management Systems. Chief Operating Officer, Director of Strategy and Business Development, Chief Information Security Officer

Risk Management & Business Continuity Manual

Using the Cloud for Business Resilience

Transcription:

ASIS INTERNATIONAL The worldwide leader in security standards and guidelines development

> ASIS Standards and Guidelines bring together volunteers and seek out views of persons who have an interest in the topic covered. Committees are open and balanced to ensure content relevancy, credibility, and broad acceptance. ASIS is an ANSI Accredited Standards Developer. > PUBLISHED STANDARDS n Auditing Management Systems for Risk, Resilience, Security and Continuity Management n Business Continuity Management Systems* n Chief Security Officer (Revision) n Conformity Assessment and Auditing Management Systems for Quality of Private Security Company Operations n Management System for Quality of Private Security Company Operations* n Maturity Model for the Phased Implementation of a Quality Assurance Management System for Private Security Providers n Organizational Resilience* n Organizational Resilience Maturity Model n Physical Asset Protection* n Quality Assurance and Security Management for Private Security Companies Operating at Sea Guidance n Supply Chain Risk Management: A Compilation of Best Practices n Workplace Violence Prevention and Intervention* *Also available in Spanish In addition, ASIS has a robust library of industry guidelines, which offers a collection of suggested practices.

> PRIVATE SECURITY SERVICE PROVIDERS STANDARDS These standards for private security service providers assure quality of service, manage risks, and protect human rights in areas where the rule of law has been suspended due to acts of war or natural disasters. Published Management System for Quality of Private Security Company Operations Requirements with Guidance (PSC.1) Now being developed as an ISO Standard Establishes a mechanism for private security service providers and their clients to provide demonstrable commitment, conformance, and accountability to the principles outlined in the International Code of Conduct for Private Security Service Providers and the Montreux Document. Conformity Assessment and Auditing Management Systems for Quality of Private Security Company Operations (PSC.2) Provides requirements for bodies providing auditing and third party certification of private security service providers working for any client in conditions where governance and the rule of law have been undermined by conflict or disaster. Maturity Model for the Phased Implementation of a Quality Assurance Management System for Private Security Providers (PSC.3) Provides guidance for the implementation of the PSC.1 Standard in six phases, ranging from no process in place for quality assurance management to going beyond the core requirements of the PSC.1 Standard. Quality Assurance and Security Management for Private Security Companies Operating at Sea Guidance (PSC.4) Provides guidance for implementing the PSC.1 Standard (and related ISO security management system standards) in the maritime environment consistent with respect for human rights, contractual, and legal obligations. ASIS Members Get your one free download of each Standard and Guideline at www.asisonline.org/standards Hard copies are also available for purchase in the online store.

> RESILIENCE STANDARDS These standards address the risks of disruptive events. Using a balance of adaptive, proactive, and reactive strategies, these standards offer a holistic, businessfriendly approach to risk and resilience management. Published Organizational Resilience with Guidance for Use (SPC.1) Adopted by Department of Homeland Security Private Sector Preparedness Program (PS-Prep) Provides a framework for businesses to assess the risks of disruptive events; develop a proactive strategy for prevention, response and recovery; establish performance criteria, and evaluate opportunities for improvement. Auditing Management Systems for Risk, Resilience, Security, and Continuity Management (SPC.2) Emphasizes the importance of audits as a management tool for monitoring and verifying the effective implementation of an organization s policy. Refers to the systematic, objective activities performed to evaluate management system performance for security, preparedness, and continuity management. Organizational Resilience Maturity Model (SPC.4) Provides guidance for the implementation of the SPC.1 Standard in six phases, ranging from an unplanned approach to managing events to going beyond the requirements of the standard and creating a holistic environment for resilience management.

> STANDARDS UNDER DEVELOPMENT Investigations (INV) Focuses on managing an investigation program as well as conducting individual investigations. It will help investigators conduct inquiries using a systematic approach, in an organized and well-documented manner, as well as help to reduce the risks that may be encountered during an investigation, thereby mitigating the impact to an organization s reputation and possible legal ramifications. Risk Assessment (RA) Being developed jointly with RIMS, it will describe a process for establishing a risk assessment program, as well as the conduct of individual risk assessments. Resilience in the Supply Chain (SPC.3) Expands the scope of the SPC.1 Standard to include resilience in the supply chain. Provides auditable criteria to prevent, prepare for, respond to, and recover from a disruptive event. Community Resilience (SPC.5) Provides guidance to facilitate capacity sharing to enhance resilience through public-private partnerships between individuals, organizations, and communities. Using the Plan-Do-Check-Act model, it will address community risk and resilience management through capacity identification, assessment, and sharing in order to help communities better prevent, prepare for, respond to, and recover from disruptions. Get Involved Have an idea for a new project proposal? Looking to serve on a committee? Learn more at www.asisonline.org/standards or email standards@asisonline.org

About ASIS International ASIS International (ASIS) is the preeminent organization for security professionals, with more than 38,000 members worldwide. Founded in 1955, ASIS is dedicated to increasing the effectiveness and productivity of security professionals by developing educational programs and materials that address broad security interests, such as the ASIS Annual Seminar and Exhibits, as well as specific security topics. ASIS also advocates the role and value of the security management profession to business, the media, government entities, and the public. By providing members and the security community with access to a full range of programs and services, and by publishing the industry s number one magazine Security Management ASIS leads the way for advanced and improved security performance. 1625 Prince Street Alexandria, VA 22314-2882 USA +1.703.519.6200 Fax: +1.703.519.6299 www.asisonline.org 08/14