ISO 28000 - Supply Chain Security - Guidelines for auditors on information security controls
Order Security Manual Template Download sample Version History
ISO 28000:2007 is necessary for support of an organization implementing and managing a Supply Chain Security Management System (SCSMS)
ISO 28000 - Supply Chain Security - With companies that have a high reliance on just-in-time delivery, aging infrastructure and increased natural and human-made threats, Supply Chain Security has become a very important item for them, especially when viewed in relation with Business Continuity Management, Risk Management and Security Management.
ISO 28000 Definition
"This International Standard (ISO 28000) specifies the requirements for a security management system, including those aspects critical to the security assurance of the supply chain. Security management is linked to many other aspects of business management. Aspects include all activities controlled or influenced by organizations that impact on supply chain security. These other aspects should be considered directly, where and when they have an impact on security management, including transporting goods along the supply chain".
The business environment is constantly changing - along with threats to a company's survival. Organizations need to be ahead of the game, and an excellent defense can be built around an audit of the controls used to support information security. ISO 28000:2007 applies to all sizes of organizations, from small to multinational, in manufacturing, service, storage, or transportation at any stage of the production or supply chain that wishes to:
- establish, implement, maintain and improve a security management system;
- assure conformance with stated security management policy;
- demonstrate such conformance to others;
- seek certification/registration of its security management system by an Accredited third-party Certification Body; or
- make a self-determination and self-declaration of conformance with ISO 28000:2007.
ISO 28000 was developed by the ISO Technical Committee TC8 "Ships and Maritime Technology". It is based on the ISO format adopted by ISO 14001:2004 because of its risk-based approach to management standards. The ISO 28000 series of standards consists of:
- ISO 28000:2007 - The Security Management Standard (SMS) requirements standard, a specification for an SMS against which organizations can certify compliance.
- ISO 28001:2007 - Provides requirements and guidance for organizations in international supply chains.
- Assists in meeting the applicable authorized economic operator (AEO) criteria outlined in the World Customs Organization Framework of Standards and conforming to national supply chain security programs.
- ISO 28002:2011 - Development of resilience in the supply chain - Requirements with guidance for use.
- ISO 28003:2007 - Requirements for bodies providing audit and certification of supply chain security management systems
- ISO 28004:2007 - provides generic advice on the application of ISO 28000:2007.
- ISO/AWI 28005 - ( Under development) Electronic port clearance (EPC) -- Part 1: Message structures.
- ISO/AWI 28005 - Electronic port clearance (EPC) -- Part 2: Core data elements
Order Security Manual Template Download Sample
The Security Manual Template can be acquired as a stand alone item (Standard) or in the Premium or Gold sets:
Order DRP BCP Security Bundle Download Sample