Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 28000

Supply Chain Security Management Systems

Management Systems Published: 2022 ✓ Certifiable

ISO 28000:2022 at a glance

Current edition
ISO 28000:2022 - Security and resilience — Security management systems — Requirements
Published
2022
Status
Published
Type of standard
Management system standard
Certifiable
Yes — organizations can be certified by an accredited body
Previous edition
ISO 28000:2007
Official ISO page
View ISO 28000:2022 on iso.org
Last verified

Overview

Certifiable requirements for a security management system; the 2022 edition broadened the scope from supply chain security to security management generally

ISO 28000:2022 specifies requirements for a security management system, including aspects relevant to the supply chain. The second edition was published in March 2022 and replaces ISO 28000:2007, which was titled Specification for security management systems for the supply chain. The change of title matters: the standard is no longer limited to supply chain and logistics contexts and can be applied by any organization that needs to manage security risk in a systematic, auditable way. Amendment 1:2024 added the harmonized text on climate action.

The 2022 edition adopts ISO's harmonized structure, which makes integration with ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and especially ISO 22301 (business continuity) straightforward. It is now part of the ISO/TC 292 security and resilience family rather than a standalone logistics standard.

The requirements follow the familiar management system pattern with security-specific content: understanding the organization's context and its security-related interested parties; leadership, security policy and roles; security risk assessment and treatment; security objectives and planning; support, competence and communication; operational planning and control; and performance evaluation and improvement.

Operationally, the standard requires the organization to identify security threats and vulnerabilities across its activities, facilities, transport, information and personnel; to design and implement proportionate security strategies, procedures and controls; to control externally provided processes and suppliers that affect security; and to prepare for and respond to security incidents, including planning, response procedures, and recovery and continuity arrangements.

Because it addresses physical, personnel, information and supply chain security together, ISO 28000 is used where risks include theft and cargo crime, smuggling and contraband, tampering and counterfeiting, sabotage, terrorism, piracy, and disruption of critical logistics nodes. It is often implemented to support customs and trade security programmes such as Authorised Economic Operator (AEO) schemes in the EU and C-TPAT in the United States: certification to ISO 28000 does not by itself grant those statuses, but the underlying controls and evidence align closely with what those programmes assess.

Accredited third-party certification is available. Related standards include ISO 28001 (best practices for implementing supply chain security, assessments and plans), ISO 28003 (requirements for bodies auditing and certifying supply chain security management systems), ISO 22301 (business continuity) and ISO 31000 (risk management).

Purpose

To specify auditable requirements for a security management system that identifies security threats and vulnerabilities, applies proportionate controls across operations and the supply chain, and prepares the organization to respond to and recover from security incidents.

Key Benefits

  • Provides an internationally recognised, certifiable framework for managing security risk
  • Applies to any organization, not only supply chain and logistics operators, since the 2022 revision
  • Addresses physical, personnel, information and supply chain security within a single system
  • Uses the harmonized structure, integrating readily with ISO 22301, ISO/IEC 27001 and ISO 9001
  • Supports customs and trade security programmes such as AEO and C-TPAT with aligned controls and evidence
  • Requires documented security risk assessment rather than generic guarding arrangements
  • Extends security requirements to suppliers, contractors and outsourced processes
  • Improves incident response and recovery planning for security events
  • Provides assurance evidence for customers, insurers and regulators
  • Amendment 1:2024 brings the standard into line with ISO's climate action requirements

Key Requirements

  • Determine the organization's context, security-related interested parties and the scope of the security management system
  • Establish a security policy consistent with the organization's purpose and risk profile
  • Assign roles, responsibilities and authorities, with demonstrated leadership and commitment from top management
  • Identify security threats, vulnerabilities and risks affecting the organization and its supply chain
  • Assess and treat security risks and determine the controls required
  • Set security objectives and plan actions, resources and timescales to achieve them
  • Provide resources, ensure competence and awareness of personnel with security responsibilities
  • Determine internal and external communication relevant to security
  • Maintain documented information required by the standard and by the system
  • Plan and control operations, including security strategies, procedures, processes and treatments
  • Control externally provided processes, products and services that affect security
  • Establish security incident preparedness, response and recovery arrangements, and test them
  • Monitor, measure, analyse and evaluate security performance
  • Conduct internal audits and management reviews at planned intervals
  • Address nonconformities and security incidents with corrective action and continual improvement
  • Consider whether climate change is a relevant issue in the organization's context (Amendment 1:2024)

Who Needs This Standard?

Organizations exposed to security risk in their operations or supply chains — logistics and freight operators, ports, terminals and airports, warehousing and distribution, manufacturers of high-value or regulated goods, customs-facing traders pursuing AEO or C-TPAT status, and critical infrastructure operators.

Where to get ISO 28000

The full text of ISO 28000 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 28000 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 28000, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Need help getting certified?

Certificates for ISO 28000 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.

Get help with ISO 28000 certification

Related Standards