ISO 28001:2007
Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance
Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 23 октября 2007 г.
- Издание:
- ISO IS 28001 edition 1 version 1
- ICS:
- 03.100.01
ISO 28001:2007 provides requirements and guidance for organizations in international supply chains to develop and implement supply chain security processes; establish and document a minimum level of security within a supply chain(s) or segment of a supply chain; assist in meeting the applicable authorized economic operator (AEO) criteria set forth in the World Customs Organization Framework of Standards and conforming national supply chain security programmes. In addition, ISO 28001:2007 establishes certain documentation requirements that would permit verification. Users of ISO 28001:2007 will define the portion of an international supply chain within which they have established security; conduct security assessments on that portion of the supply chain and develop adequate countermeasures; develop and implement a supply chain security plan; train security personnel in their security related duties.
Abstract
Overview
ISO 28001:2007 - Security management systems for the supply chain - provides requirements and guidance for organizations in international supply chains to develop, implement and document supply chain security processes. It helps organizations establish a minimum, verifiable level of security for part(s) of a supply chain, produce security assessments and security plans, and train personnel. ISO 28001 supports compliance with World Customs Organization (WCO) SAFE Framework objectives and can assist organizations pursuing Authorized Economic Operator (AEO) recognition.
Key topics and requirements
- Scope definition: Define and document the portion of the international supply chain covered (Statement of Coverage).
- Security assessment: Conduct formal assessments to identify threat scenarios, vulnerabilities and the potential consequences for people, assets and operations.
- Countermeasures: Prioritize and develop countermeasures where vulnerabilities are unacceptable; plan mitigation to reduce likelihood and/or consequences.
- Security plan: Produce and implement a documented Security Plan describing measures and responsibilities for the defined scope.
- Execution and monitoring: Put the plan into operation, monitor effectiveness and update based on incidents or changes.
- Incident response and documentation: Specify actions after security incidents and retain records that permit verification and audits.
- Training: Establish a training programme to ensure security personnel can perform assigned duties.
- Protection of security information: Manage confidentiality and controlled sharing of sensitive security data.
- Annex guidance: Informative annexes illustrate security process models, a risk-assessment methodology and guidance on obtaining advice or certification.
Practical applications
ISO 28001 is practical for organizations that operate across borders and want to manage supply chain security systematically:
- Manufacturers, importers, exporters, freight forwarders, carriers, port/terminal operators, warehouses and distributors.
- Companies seeking AEO status or to align with national supply chain security programmes.
- Internal audit, compliance and security teams establishing documented security processes and verifiable controls.
- Third-party certification bodies and government agencies assessing an organization’s security baseline.
Benefits include improved risk-based decision making, clearer documentation for audits and validations, better coordination with business partners, and strengthened resilience of trade operations.
Related standards
- World Customs Organization (WCO) SAFE Framework of Standards - alignment with AEO concepts.
- ISO 20858 (maritime port facility security assessments and plans) - normative reference.
- SOLAS (International Convention for the Safety of Life at Sea) - referenced in context of maritime security.
Keywords: ISO 28001, supply chain security, security assessment, security plan, AEO, WCO Framework, countermeasures, supply chain risk management, documentation requirements.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 28001:2007
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 28004-4:2014
ДействующийSecurity management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 4: A…
Overview ISO 28004-4:2014 - Security management systems for the supply chain - Part 4 provides additional guidance for organizations implementing ISO 28000 when their management objective is also to…
BS ISO 20858:2007
ДействующийShips and marine technology. Maritime port facility security assessments and security plan development.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…