ISO 28004-2:2014
Security management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 2: Guidelines for adopting ISO 28000 for use in medium and small seaport operations
Security management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 2: Guidelines for adopting ISO 28000 for use in medium and small seaport operations
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 22
- Дата публикации:
- 3 февраля 2014 г.
- Издание:
- ISO IS 28004 edition 1 version 1
- ICS:
- 03.100.01
ISO 28004-2:2014 identifies supply chain risk and threat scenarios, procedures for conducting risks/threat assessments, and evaluation criteria for measuring conformance and effectiveness of the documented security plans in accordance with ISO 28000 and the ISO 28004 series implementation guidelines. An output of this effort will be a level of confidence rating system based on the quality of the security management plans and procedures implemented by the seaport to safeguard the security and ensure continuity of operations of the supply chain cargo being processed by the seaport. The rating system will be used as a means of identifying a measurable level of confidence (on a scale of 1 to 5) that the seaport security operations are in conformance with ISO 28000 for protecting the integrity of the supply chain.
Abstract
Overview - ISO 28004-2:2014 (Seaport security guidance)
ISO 28004-2:2014, part of the ISO 28004 series, provides practical guidance for adopting ISO 28000 in medium and small seaport operations. It helps seaports identify supply chain risk and threat scenarios, define procedures for conducting security risk/threat assessments, and establish evaluation criteria to measure conformance and effectiveness of documented security plans. The standard introduces a level-of-confidence rating system (1–5) to quantify how well a seaport’s security management plans align with ISO 28000 for protecting supply chain integrity and ensuring continuity of operations.
Key topics and technical requirements
- Risk and threat identification - structured guidance on typical seaport risks including accidents, criminal activity, fire, labour and stakeholder financial risks, equipment failures, political/government change, terrorist threats and weather-related events.
- Risk assessment procedures - requirements to establish and maintain procedures for ongoing identification, analysis and mitigation of security threats appropriate to the nature and scale of port operations.
- Security plan content - expectations for documented security management plans covering system design, installation, validation, maintenance, staffing, training and continuity/disaster recovery provisions.
- Evaluation criteria and rating process - methods and measurable criteria for assessing the quality and effectiveness of seaport security plans, culminating in a 1–5 confidence rating to indicate conformance with ISO 28000.
- Integration with regulatory frameworks - alignment with the ISPS Code and legal/statutory requirements; consideration of external dependencies (suppliers, communications systems, policy changes).
- Operational guidance - recommended stakeholder roles, responsibilities and processes for keeping security documentation current and personnel trained.
Practical applications - who uses this standard
- Port authorities and terminal operators seeking to implement ISO 28000-aligned security management systems tailored for medium and small seaports.
- Security managers and planners who need structured risk assessment methods and measurable evaluation criteria.
- Consultants and auditors performing self-evaluations or gap analyses before pursuing certification. Note: ISO 28004-2 supports self-evaluation; third-party certification processes are covered by related standards.
- Regulators and stakeholders who require a consistent approach to measuring seaport supply chain security and operational continuity.
Related standards
- ISO 28000 (Supply chain security management systems)
- ISO 28004-1 (General principles)
- ISO 20858 (Port facility security evaluation / ISPS professional interpretation)
- ISO 28001, ISO 28002, ISO 28003 (related supply chain resilience, AEO and conformity assessment guidance)
Keywords: ISO 28004-2:2014, ISO 28000, seaport security, supply chain security, risk assessment, medium and small seaports, security management systems, ISPS Code, security plan evaluation.
Технические детали
- Технический комитет
- ISO/TC 8 - Ships and marine technology
- SKU
- ISO 28004-2:2014
Похожие стандарты
Стандарты, упомянутые в описании
ISO 28004-4:2014
ДействующийSecurity management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 4: A…
Overview ISO 28004-4:2014 - Security management systems for the supply chain - Part 4 provides additional guidance for organizations implementing ISO 28000 when their management objective is also to…