ISO 28004-3:2014
Security management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 3: Additional specific guidance for adopting ISO 28000 for use by medium and small businesses (other than marine ports)
Security management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 3: Additional specific guidance for adopting ISO 28000 for use by medium and small businesses (other than marine ports)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 15
- Дата публикации:
- 4 февраля 2014 г.
- Издание:
- ISO IS 28004 edition 1 version 1
- ICS:
- 03.100.01
ISO 28004-3:2014 has been developed to supplement ISO 28004-1 by providing additional guidance to medium and small businesses (other than marine ports) that wish to adopt ISO 28000. The additional guidance in ISO 28004-3:2014, while amplifying the general guidance provided in the main body of ISO 28004-1, does not conflict with the general guidance, nor does it amend ISO 28000.
Abstract
Overview
ISO 28004-3:2014 provides practical guidance for medium and small businesses (excluding marine ports) that want to adopt ISO 28000 for supply chain security. It supplements the general guidance in ISO 28004-1 and clarifies how smaller organisations can scope, implement and demonstrate a security management system without altering ISO 28000 itself. The document is particularly focused on making ISO 28000 adoption more accessible and pragmatic for SMEs.
Key topics and requirements
- Scope and applicability: Guidance to help organisations decide which parts of their operation are within the supply chain security management system (manufacturing, warehousing, transport, custody changes, documentation handling, routes, etc.).
- Stepwise implementation:
- Step 1 – Preparatory work: define scope, consider corporate objectives, customer needs, and regulatory expectations.
- Step 2 – Security Management Policy: produce a senior-management-endorsed policy that is meaningful, sized appropriately, and committed to continual improvement.
- Step 3 – Security assessment: conduct documented threat and risk assessments comparing current controls against known threat scenarios.
- Documentation and evidence: the standard stresses recording assessor qualifications, methodologies (definitions of likelihood/consequence), threat scenarios, scope, reviewed procedures, assumptions, photographic/diagrammatic evidence, countermeasure needs and dates.
- Operational requirements: set objectives, implement processes/equipment, train personnel, execute plans, monitor performance, run exercises/tests, investigate incidents and update plans.
- Conformance & certification guidance: additional guidance on audits, demonstrating conformance to ISO 28000, and working with third‑party certification bodies appropriate for SMEs.
Practical applications and users
ISO 28004-3:2014 is aimed at SMEs and mid-sized organisations in the supply chain who need a scalable, documented approach to securing goods and information. Typical users include:
- Freight forwarders, trucking companies and logistics providers
- Warehousing and distribution centres
- Manufacturers and assemblers linked to complex supply chains
- Third-party logistics (3PL) providers and customs brokers
- Compliance officers, security managers and quality managers seeking certification or customer assurance
Benefits include clearer scoping for SMEs, documented risk-based decision-making, improved incident preparedness, reduced cargo loss risk, and a structured path to demonstrate conformity with ISO 28000 to customers and regulators.
Related standards
- ISO 28000:2007 - Specification for security management systems for the supply chain (normative reference)
- ISO 28004-1:2007 - General principles for implementing ISO 28000
- Other parts of ISO 28004 (Part 2 and Part 4) provide additional sector-specific guidance
Keywords: ISO 28004-3:2014, ISO 28000, supply chain security, SMEs, security management system, risk assessment, certification, supply chain integrity.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 28004-3:2014
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 28000:2007
ОтменёнSpecification for security management systems for the supply chain
ISO 28004-4:2014
ДействующийSecurity management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 4: A…
Overview ISO 28004-4:2014 - Security management systems for the supply chain - Part 4 provides additional guidance for organizations implementing ISO 28000 when their management objective is also to…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…