Skip to content
Menu
menu

Security and Resilience in Organizations and their Supply Chains

ATTENTION: This page is intended to be viewed online and may not be printed or copied.

ASIS Commission on Standards and Guidelines

Charles Baley, Farmers Insurance Group, Inc.
Cynthia P. Conlon, CPP, Conlon Consulting Corporation
William Daly, Control Risks Security Consulting
Lisa DuBrock, Radian Compliance LLC
Eugene Ferraro, CPP, PCI, ForensicPathways, Inc.
Bernard Greenawalt, CPP, Securitas Security Services USA, Inc., Vice Chair
Robert Jones, Socrates Ltd
Glen Kitteringham, CPP, Kitteringham Security Group Inc.
Michael Knoke, CPP, Express Scripts, Inc., Chair
Bryan Leadbetter, CPP, Arconic.
Jose Miguel Sobron, United Nations
Roger Warwick, CPP, Pyramid International Temi Group
Allison Wylde, Cardiff University

At the time it approved this document, the ORM.1 Standards Committee, which is responsible for the development of this Standard, had the following members:

Committee Members

Committee Chairman: Marc H. Siegel, Ph.D., M. Siegel Associates
Commission Liaison: Lisa DuBrock, Radian Compliance
Committee Secretariat: Aivelis Opicka, ASIS International

Colin Ackroyd, Colin Ackroyd and Associates
Mark Baker, CPP, Macatoma Security Inc.
Mark Beaudry, CPP
John Bennett, Hospital Network Ventures, LLC
Dennis Blass, CPP, PSP, Children’s of Alabama
Bruce Braes, CPP, CSyP, Optimal Risk Management
Hart Brown, HUB International
Herbert Calderon, CPP, PCI, PSP, Gloria Group
Werner Cooreman, CPP, PSP, Solvay
Britt Corra, Microsoft
Steven Dawson, Owens Corning
David Dodge, CPP, PCI, Temi Group, South Africa
Larry Dodson, CPP, University of Kansas
Jack Dowling, CPP, PSP, J. D. Security Consultants
James Drymiller, CPP
Eduard Emde, CPP, ESA European Space Agency
Thomas Frank, CPP, AbbVie
Shaun Fynes, CPP, PCI, PSP, Government Security Office (B.C.)
Francis Gallagher, PSP, Good Harbor Techmark
Jeffrey Gambrell, CPP, Absolute Software
Tareq Ghosheh, PalSafe
Robert Grieman, CPP, Securitas Security Services, USA
Andrew Griffiths, PCI, CEVA Logistics Uk Limited
Carlos Guzman, CPP, Security 101
Michael Heath, Diamond Security & Investigative Services
Christian Huenke, GENCO, A FedEx Company
Calvin Jaeger
Ben Jakubovic, CPP, PSP, CYBRA Corporation
Eduardo Jimenez-Granados, Procter & Gamble
UWE Klapproth, Euroclear SA/NV
Mukesh Lakhanpal, CPP, PSP, G4S Secure Solutions India
James Leflar, CPP, Zantech IT Services at the Federal Protective Service
Alessandro Lega, CPP
Victoria Leighton, Pierce College COE HSEM
Jeffrey LeMoine, CPP, General Mills
Rachelle Loyear
Ronald Martin, CPP, Open Security Exchange
Raida Mashal, JRMC (Jordan Risk Management Center for Training)
James McGuffey, CPP, PCI, PSP, A.C.E. Security Consultants
Murray Mills, CPP
William Minear, CPP, State of West Virginia
Dan Moe
Juan Munoz, CPP
Francisco Muñoz, CPP, Occidental Petroleum Corporation
Deyanira Murga, Executive Protection Institute
Normadene Murphy, BASF
Matthew Neely, CPP, SecureState
Vicki Nichols, Lockheed Martin
Peter Page, CPP, Al-Tayer Group
Juan Paredes, Socrates LTD.
Michael Payne, CPP, iJET International
Warren Petty, CPP, Wells Fargo
Russ Phillips, Coca-Cola Refreshments
Jose Piscione, CPP, PSP, Westcorp Argentina SA
Werner Preining, CPP, Interpool Security
Brandi Priest, Strategic Sustainable Solutionary Services Consulting
Stanley Ragen, CPP
Ronald Ronacher, PSP, Arup
Rick Saunders, Dynamis, Inc.
Ed Schlichtenmyer, StormGeo
Nancy Slotnick, Setracon
Jeffrey Slotnick, CPP, PSP, Setracon
Malcolm Smith, CPP
Jose-Miguel Sobron
Thomas Stephens, PCI, Rochester Research Associates, LLC
J. Kelly Stewart, Newcastle Consulting
Eduard Stor
Jason Teliszczak, CPP, JT Environmental Consulting
Rajeev Thykatt
Yoriko Tobishima, InterRisk Research Institute & Consulting, Inc.
Irvin Varkonyi, Supply Chain Ops Prep Edu.
Richard Widup, CPP, Mead Johnson Nutrition
Robert Wiest, CPP, CGI Group Inc.
William Wills, CPP, Briggs and Stratton Corporation
Allison Wylde, Regent's University London
Richard Zijdemans, Medtronic

Working Group Members

Working Group Chairman: Marc H. Siegel, Ph.D., M. Siegel Associates

Colin Ackroyd, Colin Ackroyd and Associates
Mark Beaudry, CPP
Dennis Blass, CPP, PSP, Children’s of Alabama
Britt Corra, Microsoft
Thomas Frank, CPP, AbbVie
Shaun Fynes, CPP, PCI, PSP, Government Security Office (B.C.)
Robert Grieman, CPP, Securitas Security Services, USA
Andrew Griffiths, PCI, CEVA Logistics Uk Limited
Calvin Jaeger
James Leflar, CPP, Zantech IT Services at the Federal Protective Service
Alessandro Lega, CPP
William Minear, CPP, State of West Virginia
Dan Moe
Normadene Murphy, BASF
Michael Payne, CPP, iJET International
Russ Phillips, Coca-Cola Refreshments
Werner Preining, CPP, Interpool Security
Ronald Ronacher, PSP, Arup
Ed Schlichtenmyer, StormGeo
Jose-Miguel Sobron
Thomas Stephens, PCI, Rochester Research Associates, LLC
Jason Teliszczak, CPP, JT Environmental Consulting
Rajeev Thykatt
Robert Wiest, CPP, CGI Group Inc.
William Wills, CPP, Briggs and Stratton Corporation
Allison Wylde, Regent's University London
Richard Zijdemans, Medtronic

Next: Introduction


Table of Contents

ORM Standard Home

ASIS Commission on Standards and Guidelines
  • Committee Members
Introduction
  • Scope
  • Normative References
  • Terms and Definitions
General Principles
  • Leadership and Vision
  • Governance
  • Factual Basis for Decision Making
  • Outcomes Oriented
  • Needs Oriented Taking Human and Cultural Factors into Account
  • Overall Organizational Risk and Business Management Strategy
  • Systems Approach
  • Adaptablility and Flexibility
  • Managing Uncertainty
  • Cultual Change and Communication

Establishing the Framework

  • General
  • Context of the Organization
  • Needs and Requirements
  • Defining Risk Criteria
  • Scope of the Management System
Leadership
  • General
  • Management Commitment
  • Policy
  • Organizational Roles, Responsibilities, and Authorities for the ORMS
Planning
  • Legal and Other Requirements
  • Risk Assessment
  • Objectives and Plans to Achieve them
  • Actions to Achieve Risk and Business Management Objectives

Structural Requirements

  • General 
  • Organizational Structure
  • Financial and Administrative Procedures
  • Insurance
  • Outsourcing
  • Documented Information

Operation and Implementation

  • Operational Control
  • Resources, Roles, Responsibilities, and Authority
  • Competence, Training, and Awareness
  • Communication
  • Prevention and Management of Undesirable or Disruptive Events

Performance Evaluation

  • General
  • Monitoring and Measurement
  • Evaluation of Compliance
  • Exercises and Testing
  • Internal Audit
  • Management Review

Continual Improvement

  • General
  • Nonconformities, Corrective and Preventative Action
  • Change Management
  • Opportunities for Improvement

Annex B: Examples of Incident Prevention, Preparedness, and Response

Annex C: Examples of Risk Treatment Procedures that Enhance Resilience of the Organization 

Annex D: Business Impact Analysis

Annex E: An Integrated Management Systems Approach

Annex F: Qualifiers to Application

Annex G: Bibliography

Annex H: References

arrow_upward