ISO 28004-4:2014
Security management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 4: Additional specific guidance on implementing ISO 28000 if compliance with ISO 28001 is a management objective
Security management systems for the supply chain — Guidelines for the implementation of ISO 28000 — Part 4: Additional specific guidance on implementing ISO 28000 if compliance with ISO 28001 is a management objective
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 6
- Дата публикации:
- 3 февраля 2014 г.
- Издание:
- ISO IS 28004 edition 1 version 1
- ICS:
- 03.100.01
ISO 28004-4:2014 provides additional guidance for organizations adopting ISO 28000 that also wish to incorporate the Best Practices identified in ISO 28001 as a management objective on their international supply chains. The Best Practices in ISO 28001 both help organizations establish and document levels of security within an international supply chain and facilitate validation in national Authorized Economic Operator (AEO) programmes that are designed in accordance with the World Customs Organization (WCO) Framework of Standards. ISO 28004-4:2014 is not designed as a standalone document. The main body of ISO 28004-1 provides significant guidance pertaining to required inputs, processes, outputs and other elements required by ISO 28000. ISO 28004-4:2014 provides additional specific guidance on implementing ISO 28000 if compliance with ISO 28001 is a management objective.
Abstract
Overview
ISO 28004-4:2014 - Security management systems for the supply chain - Part 4 provides additional guidance for organizations implementing ISO 28000 when their management objective is also to adopt the Best Practices in ISO 28001. It is a supplemental document (not standalone) that explains how ISO 28001’s supply chain security best practices plug into an ISO 28000 security management system and how this combination supports validation against national Authorized Economic Operator (AEO) programmes based on the World Customs Organization (WCO) SAFE Framework.
Keywords: ISO 28004-4:2014, ISO 28000, ISO 28001, supply chain security, AEO, WCO SAFE Framework
Key topics and requirements
- Relationship to other standards: Clarifies that ISO 28004-4:2014 supplements ISO 28004‑1 and maps ISO 28001 requirements into ISO 28000 processes (inputs, processes, outputs).
- Synergy with WCO AEO: Clause-based charts (Clause 5) show how ISO 28000/28001 address AEO requirements, making the standard useful for organizations seeking AEO recognition.
- Technical topic areas covered:
- Education, training and awareness (personnel competence and training)
- Information exchange, access and confidentiality (document/data control)
- Cargo, conveyance and premises security (operational controls and security plans)
- Personnel and trading partner security (screening, partner declarations)
- Crisis management and incident recovery (emergency preparedness and incident reporting)
- Measurement, analysis and continual improvement (risk assessment, monitoring and audit)
- Practical integration guidance: Clause 6 provides where ISO 28001 elements fit into ISO 28000 (e.g., security risk assessments, security plan development, incident reporting).
- Limitations noted: Some AEO-specific functions (customs record-keeping, demonstrated compliance, financial viability, governmental consultations) remain government responsibilities and are not addressed by ISO standards.
Practical applications and users
- Organizations that will benefit:
- Logistics providers, freight forwarders, carriers and port/terminal operators
- Supply chain/security managers and compliance teams pursuing AEO validation
- Companies aiming to document and improve international supply chain security using ISO 28000 plus ISO 28001 best practices
- Security consultants and auditors advising on ISO-based security management systems
- How it’s used:
- To align internal security policies and plans with internationally recognized AEO expectations
- To map ISO 28001 best practices into ISO 28000 processes for implementation and certification readiness
- To support training, incident response procedures and partner security declarations in multinational operations
Related standards
- ISO 28000 - Specification for security management systems for the supply chain
- ISO 28001 - Best practices for implementing supply chain security, assessments and plans
- ISO 28004‑1 - Guidelines for implementation of ISO 28000 (general principles)
- ISO 20858 - Maritime port facility security assessments and plan development
- WCO SAFE Framework - Authorized Economic Operator program guidance
Using ISO 28004-4:2014 helps organizations operationalize ISO 28001 best practices within an ISO 28000 security management framework and improves readiness for AEO validation and international supply chain security compliance.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 28004-4:2014
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 20858:2007
ДействующийShips and marine technology. Maritime port facility security assessments and security plan development.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…