ISO 28003:2007
Security management systems for the supply chain — Requirements for bodies providing audit and certification of supply chain security management systems
Security management systems for the supply chain — Requirements for bodies providing audit and certification of supply chain security management systems
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 43
- Дата публикации:
- 2 августа 2007 г.
- Издание:
- ISO IS 28003 edition 1 version 1
- ICS:
- 03.100.01
ISO 28003:2007 contains principles and requirements for bodies providing the audit and certification of supply chain security management systems according to management system specifications and standards such as ISO 28000. It defines the minimum requirements of a certification body and its associated auditors, recognizing the unique need for confidentiality when auditing and certifying/registering a client organization. Requirements for supply chain security management systems can originate from a number of sources, and ISO 28003:2007 has been developed to assist in the certification of supply chain security management systems that fulfil the requirements of ISO 28000, Specification for security management systems for the supply chain, and other supply chain security management system International Standards. The contents of ISO 28003:2007 may also be used to support certification of supply chain security management systems that are based on other specified supply chain security management system requirements. ISO 28003:2007 provides harmonized guidance for the accreditation of certification bodies applying for ISO 28000 (or other specified supply chain security management system requirements) certification/registration; defines the rules applicable for the audit and certification of a supply chain security management system complying with the supply chain security management system standard's requirements (or other sets of specified supply chain security management system requirements); provides the customers with the necessary information and confidence about the way certification of their suppliers has been granted.
Abstract
Overview
ISO 28003:2007 - "Security management systems for the supply chain - Requirements for bodies providing audit and certification of supply chain security management systems" sets out the principles and minimum requirements for certification bodies and their auditors when auditing and certifying supply chain security management systems (e.g., systems based on ISO 28000). It is intended to ensure certification is carried out in a competent, consistent and confidential manner and to support national and international recognition of such certifications.
Key topics and requirements
ISO 28003 addresses the full conformity-assessment lifecycle and organizational arrangements for bodies that certify supply chain security management systems. Major technical topics include:
- Principles for certification bodies: impartiality, competence, responsibility, openness and confidentiality - recognizing the unique confidentiality needs of security audits.
- General and structural requirements: legal/contractual matters, management of impartiality, liability, organizational structure and governance (including committees to safeguard impartiality).
- Resource and personnel requirements: competence of management, auditor qualifications, use of external auditors and experts, personnel records and outsourcing.
- Information and documentation: public information, certification documents, directories of certified clients, permitted references and use of marks, confidentiality and information exchange with clients.
- Process requirements: rules for initial audits and certification, surveillance, recertification, special audits, suspension/withdrawal of certification, appeals and complaints, and record-keeping.
- Management system requirements: options for certification bodies to demonstrate their own management systems (including alignment with ISO 9001 where applicable).
- Normative annexes: guidance on auditor time estimation (Annex A), multi-site auditing criteria (Annex B), auditor education/work/training durations (Annex C) and auditor competence requirements (Annex D).
Applications and users
ISO 28003 is used to:
- Guide certification bodies and registrars in establishing and operating supply chain security certification programs.
- Support accreditation bodies and peer assessors in evaluating and recognizing certification providers.
- Help auditors and technical experts understand required competencies and audit processes for supply chain security.
- Provide assurance to organizations, their customers, regulators and industry consortia that a certified supply chain security management system conforms to specified requirements.
- Facilitate international trade by harmonizing certification practices for supply chain security.
Typical users: certification/registrar organizations, accreditation bodies, security auditors, supply chain managers, logistics providers, and regulators.
Related standards
- ISO 28000 - Specification for security management systems for the supply chain
- ISO/IEC 17021 - Requirements for bodies providing audit and certification of management systems (ISO 28003 encompasses and adapts these requirements for supply chain security)
- ISO/IEC 17000, ISO 19011 - Vocabulary, principles and auditing guidance relevant to certification activities
Keywords: ISO 28003, supply chain security, certification bodies, ISO 28000, audit and certification, accreditation, auditor competence, confidentiality, conformity assessment.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 28003:2007
Похожие стандарты
Стандарты, упомянутые в описании
ISO 28004-4:2014
ДействующийSecurity management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 4: A…
Overview ISO 28004-4:2014 - Security management systems for the supply chain - Part 4 provides additional guidance for organizations implementing ISO 28000 when their management objective is also to…
BS ISO 28003:2007
ДействующийSecurity management systems for the supply chain. Requirements for bodies providing audit and certification o…
ISO/TS 54001:2019
ДействующийQuality management systems — Particular requirements for the application of ISO 9001:2015 for electoral organ…
Overview ISO/TS 54001:2019 - Quality management systems - Particular requirements for the application of ISO 9001:2015 for electoral organizations at all levels of government - provides sector-specif…