Overview
ISO 28004-1:2007 - Security management systems for the supply chain: Guidelines for the implementation of ISO 28000 (Part 1: General principles) provides practical, non‑prescriptive guidance to help organizations understand and implement ISO 28000:2007. It explains the underlying principles of a supply chain security management system (SMS) and describes the intent, typical inputs, processes and typical outputs for each ISO 28000 requirement. This document clarifies scope, roles, and processes without adding new mandatory requirements.
Key topics and requirements
- Security management system elements - guidance aligned with ISO 28000 structure: policy, planning, implementation, checking and corrective action, management review and continual improvement.
- Security management policy - expectations for top‑management authorization, consistency with other organizational policies, commitment to continual improvement and legal compliance, and communication to stakeholders.
- Risk assessment and planning - principles for identifying security threats, assessing risks, setting objectives, targets and programmes based on the supply chain context (upstream/downstream).
- Implementation and operation - operational controls, responsibilities and competence, documentation, communication, records, and emergency preparedness.
- Checking and corrective action - monitoring, measurement, audit, non‑conformance handling, corrective and preventive action.
- Management review & continual improvement - how top management should review SMS performance and drive ongoing enhancements.
- Integration guidance - mapping between ISO 28000, ISO 9001 (quality) and ISO 14001 (environment) to facilitate integrated management systems (see informative Annex A).
Practical applications and users
Who uses ISO 28004-1:2007:
- Supply chain security managers, logistics providers, freight forwarders, port and terminal operators
- Manufacturers, distributors and transport operators looking to implement ISO 28000
- Compliance officers, risk managers and consultants supporting certification or self‑declaration
- Third‑party certification bodies and auditors seeking implementation context
Typical uses:
- Designing and documenting a risk‑based security management system for supply chain operations
- Defining SMS scope, controlling outsourced processes and aligning security policy with corporate objectives
- Establishing monitoring, audit and corrective action practices to demonstrate continual improvement
- Integrating security management with quality and environmental management systems
Related standards
ISO 28004-1:2007 is a practical companion to ISO 28000 for organizations that want clear, risk‑based guidance to plan, implement and improve supply chain security systems.