Overview
ISO 28004-3:2014 provides practical guidance for medium and small businesses (excluding marine ports) that want to adopt ISO 28000 for supply chain security. It supplements the general guidance in ISO 28004-1 and clarifies how smaller organisations can scope, implement and demonstrate a security management system without altering ISO 28000 itself. The document is particularly focused on making ISO 28000 adoption more accessible and pragmatic for SMEs.
Key topics and requirements
- Scope and applicability: Guidance to help organisations decide which parts of their operation are within the supply chain security management system (manufacturing, warehousing, transport, custody changes, documentation handling, routes, etc.).
- Stepwise implementation:
- Step 1 – Preparatory work: define scope, consider corporate objectives, customer needs, and regulatory expectations.
- Step 2 – Security Management Policy: produce a senior-management-endorsed policy that is meaningful, sized appropriately, and committed to continual improvement.
- Step 3 – Security assessment: conduct documented threat and risk assessments comparing current controls against known threat scenarios.
- Documentation and evidence: the standard stresses recording assessor qualifications, methodologies (definitions of likelihood/consequence), threat scenarios, scope, reviewed procedures, assumptions, photographic/diagrammatic evidence, countermeasure needs and dates.
- Operational requirements: set objectives, implement processes/equipment, train personnel, execute plans, monitor performance, run exercises/tests, investigate incidents and update plans.
- Conformance & certification guidance: additional guidance on audits, demonstrating conformance to ISO 28000, and working with third‑party certification bodies appropriate for SMEs.
Practical applications and users
ISO 28004-3:2014 is aimed at SMEs and mid-sized organisations in the supply chain who need a scalable, documented approach to securing goods and information. Typical users include:
- Freight forwarders, trucking companies and logistics providers
- Warehousing and distribution centres
- Manufacturers and assemblers linked to complex supply chains
- Third-party logistics (3PL) providers and customs brokers
- Compliance officers, security managers and quality managers seeking certification or customer assurance
Benefits include clearer scoping for SMEs, documented risk-based decision-making, improved incident preparedness, reduced cargo loss risk, and a structured path to demonstrate conformity with ISO 28000 to customers and regulators.
Related standards
- ISO 28000:2007 - Specification for security management systems for the supply chain (normative reference)
- ISO 28004-1:2007 - General principles for implementing ISO 28000
- Other parts of ISO 28004 (Part 2 and Part 4) provide additional sector-specific guidance
Keywords: ISO 28004-3:2014, ISO 28000, supply chain security, SMEs, security management system, risk assessment, certification, supply chain integrity.