ISO 28000:2022
Security and resilience — Security management systems — Requirements
Security and resilience — Security management systems — Requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 15 марта 2022 г.
- Издание:
- ISO IS 28000 edition 2 version 1
- ICS:
- 03.100.01
This document specifies requirements for a security management system, including aspects relevant to the supply chain. This document is applicable to all types and sizes of organizations (e.g. commercial enterprises, government or other public agencies and non-profit organizations) which intend to establish, implement, maintain and improve a security management system. It provides a holistic and common approach and is not industry or sector specific. This document can be used throughout the life of the organization and can be applied to any activity, internal or external, at all levels.
Abstract
Overview
ISO 28000:2022 - Security and resilience - Security management systems - Requirements specifies requirements for a security management system (SMS) with a strong emphasis on supply chain security. Applicable to organizations of all types and sizes (commercial, government, public agencies, non-profits), the standard describes a holistic, non‑sector‑specific approach to establish, implement, maintain and continually improve an SMS across all activities and levels. It applies the Plan‑Do‑Check‑Act (PDCA) model to align security objectives with business goals and to support integration with other management systems.
Key topics and requirements
ISO 28000:2022 structures SMS requirements across core management system clauses (Clauses 4–10). Major technical topics include:
- Context and interested parties: understanding organizational context, supply‑chain dependencies and legal/regulatory obligations.
- Leadership and policy: top management commitment, security policy, roles and responsibilities.
- Risk-based planning: identifying and assessing security‑related risks, determining opportunities and planning treatments.
- Security objectives: setting measurable objectives and planning to achieve them.
- Support and resources: competence, awareness, communication and documented information (control of records and procedures).
- Operation and controls: operational planning, process identification, risk assessment/treatment, selection and implementation of controls, and development of security strategies and plans (including response, warning/communication and recovery).
- Performance evaluation: monitoring, measurement, internal audit and management review.
- Improvement: continual improvement, nonconformity handling and corrective action.
Notable 2022 updates: added guidance for alignment with ISO 31000 principles (Clause 4) and enhanced recommendations in Clause 8 for consistency with ISO 22301 (security strategies, procedures and security plans).
Practical applications and who uses it
ISO 28000:2022 is used to:
- Build or strengthen an organization’s security management framework.
- Integrate security with existing management systems (quality, business continuity, information security, etc.).
- Improve supply chain security by setting expectations for suppliers and partners.
- Prepare structured security plans, incident response and recovery measures.
Typical users:
- Security managers and directors, supply chain and logistics professionals, risk and compliance officers, C-suite leaders, and auditors implementing or evaluating an SMS.
Conformity to the standard can be verified through internal or external auditing, supporting accountability and continuous improvement.
Related standards
- ISO 31000 (risk management) - principles and coordination
- ISO 22301 (business continuity) - operational consistency and plans
- ISO/IEC 27001 (information security), ISO 9001, ISO 14001 - for integrated management system implementations
Keywords: ISO 28000:2022, security management systems, supply chain security, security risk management, PDCA, security policy, security plans.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 28000:2022
Похожие стандарты
Стандарты, упомянутые в описании
ISO 31000:2018
ДействующийRisk management — Guidelines
Overview ISO 31000:2018 - Risk management - Guidelines provides a unified, organization‑wide approach to managing risk. It offers adaptable guidance that can be customized to any organization, sector…
BS EN ISO 22313:2020
ДействующийSecurity and resilience. Business continuity management systems. Guidance on the use of ISO 22301.
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO/TS 54001:2019
ДействующийQuality management systems — Particular requirements for the application of ISO 9001:2015 for electoral organ…
Overview ISO/TS 54001:2019 - Quality management systems - Particular requirements for the application of ISO 9001:2015 for electoral organizations at all levels of government - provides sector-specif…