Overview
ISO 28001:2007 - Security management systems for the supply chain - provides requirements and guidance for organizations in international supply chains to develop, implement and document supply chain security processes. It helps organizations establish a minimum, verifiable level of security for part(s) of a supply chain, produce security assessments and security plans, and train personnel. ISO 28001 supports compliance with World Customs Organization (WCO) SAFE Framework objectives and can assist organizations pursuing Authorized Economic Operator (AEO) recognition.
Key topics and requirements
- Scope definition: Define and document the portion of the international supply chain covered (Statement of Coverage).
- Security assessment: Conduct formal assessments to identify threat scenarios, vulnerabilities and the potential consequences for people, assets and operations.
- Countermeasures: Prioritize and develop countermeasures where vulnerabilities are unacceptable; plan mitigation to reduce likelihood and/or consequences.
- Security plan: Produce and implement a documented Security Plan describing measures and responsibilities for the defined scope.
- Execution and monitoring: Put the plan into operation, monitor effectiveness and update based on incidents or changes.
- Incident response and documentation: Specify actions after security incidents and retain records that permit verification and audits.
- Training: Establish a training programme to ensure security personnel can perform assigned duties.
- Protection of security information: Manage confidentiality and controlled sharing of sensitive security data.
- Annex guidance: Informative annexes illustrate security process models, a risk-assessment methodology and guidance on obtaining advice or certification.
Practical applications
ISO 28001 is practical for organizations that operate across borders and want to manage supply chain security systematically:
- Manufacturers, importers, exporters, freight forwarders, carriers, port/terminal operators, warehouses and distributors.
- Companies seeking AEO status or to align with national supply chain security programmes.
- Internal audit, compliance and security teams establishing documented security processes and verifiable controls.
- Third-party certification bodies and government agencies assessing an organization’s security baseline.
Benefits include improved risk-based decision making, clearer documentation for audits and validations, better coordination with business partners, and strengthened resilience of trade operations.
Related standards
- World Customs Organization (WCO) SAFE Framework of Standards - alignment with AEO concepts.
- ISO 20858 (maritime port facility security assessments and plans) - normative reference.
- SOLAS (International Convention for the Safety of Life at Sea) - referenced in context of maritime security.
Keywords: ISO 28001, supply chain security, security assessment, security plan, AEO, WCO Framework, countermeasures, supply chain risk management, documentation requirements.