ISO 28000

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search

ISO 28000:2022, Security and resilience – Security management systems – Requirements, is a management system standard published by International Organization for Standardization that specifies requirements of a security management system particularly dealing with security assurance in the supply chain.[1]

The standard was originally developed by ISO/TC 8 on "Ships and maritime technology" and published in 2007.[2] In 2015 the responsibility for the ISO 28000 series was transferred to ISO/TC 292 on "Security and resilience", who in 2019 decided to start a revision. A justification study for the revision was accepted by ISO TMB (Technical Management Board).[3] The revised version of ISO 28000 was published on March 15, 2022.

Scope and contents[edit]

Similar to other management system standards by ISO, the requirements specified in ISO 28000 are generic and intended to be applicable to all organizations, regardless of type, size, and industry. However, the extent of applicability of the requirements depends on the organization's environment and complexity.

ISO 28000:2022 is divided into 10 main clauses and has adopted the high-level structure and standardized text set out by Annex L.

The standard is divided as follows:

  1. Scope
  2. Normative references
  3. Terms and definitions
  4. Context
  5. Leadership
  6. Planning
  7. Support
  8. Operation
  9. Performance evaluation
  10. Improvement

ISO 28000:2007 was developed to codify operations of security within the broader supply chain management system. The PDCA management systems structure was adopted in developing ISO 28000:2007 to bring the elements of this standard in congruence with related standards such as ISO 9001:2000 and ISO 14001:2004.[4][5]

ISO 28000:2007 includes the following main clauses:[6]

  1. Scope
  2. Normative references
  3. Terms and definitions
  4. Security management system elements
  • General requirements
  • Security management policy
  • Security risk assessment and planning
  • Implementation and operation
  • Checking and corrective action
  • Management review and continual improvement

Annex A Correspondence between ISO 28000:2007, ISO 14001:2004 and ISO 9001:2000


Adopting the ISO 28000 has broad strategic, organisational and operational benefits that are realized throughout supply chains and business practices.[7]

Benefits include, but are not limited to:

  • Integrated enterprise resilience
  • Systematised management practices
  • Enhanced credibility and brand recognition
  • Aligned terminology and conceptual usage
  • Improved supply chain performance
  • Benchmarking against internationally recognisable criteria
  • Greater compliance processes

Improved risk management integration[edit]

The development of an international standard addressing security risk management improves the broader interface with existing enterprise risk management in a common integrated platform. This integrated approach to risk management is often employed to better coordinate cross functional risk management mechanisms, improve performance measurement, ensure continual improvement and reducing misalignment of risk management objectives between silos.[8]


ISO 28000:2007 was developed such that organizations of varying scale could apply the standard to supply chains of various degrees of complexity.

The general rational for an organization to adopt ISO 28000:2007 pertains to:

  • developing a security management system,
  • internal compliance with objectives of a security management policy,
  • external compliance with best practice benchmarks,
  • ISO accreditation.

ISO 28000:2007 is a certifiable standard.[9] In 2016, the countries with the highest number of certificates were India (425), Japan (299), Spain (231), US (223) and UK (197).[3]


ISO 28000 was originally developed as a Publicly Available Specification by ISO technical committee ISO/TC 8 on Ships and marine technology [2] and published in 2005. In 2007, ISO/PAS 28000:2005 was withdrawn and replaced by a full ISO standard under the title ISO 28000:2007. In 2014, ISO 28000:2007 was reviewed and confirmed.[10]
In 2015, ISO/TC 292 Security and resilience took over the responsibility of the standard and decided later in 2019 to initiate a revision of the standard.[11]

Year Description
2005 ISO/PAS 28000
2007 ISO 28000 (1st edition)
2022 ISO 28000 (2nd edition)

Related standards[edit]

ISO 28000 is the first of a series of ISO security management standards including:[12]

  • ISO 28001:2007 Security management systems for the supply chain – Best practices for implementing supply chain security, assessments and plans – Requirements and guidance
  • ISO 28002:2011 Security management systems for the supply chain – Development of resilience in the supply chain – Requirements with guidance for use
  • ISO 28003:2007 Security management systems for the supply chain – Requirements for bodies providing audit and certification of supply chain security management systems
  • ISO 28004 Security management systems for the supply chain – Guidelines for the implementation of ISO 28000
    • ISO 28004-1:2007 Part 1: General principles
    • ISO 28004-2:2014 Part 2: Guidelines for adopting ISO 28000 for use in medium and small seaport operations[13]
    • ISO 28004-3:2014 Part 3: Additional specific guidance for adopting ISO 28000 for use by medium and small businesses (other than marine ports)
    • ISO 28004-4:2014 Part 4: Additional specific guidance on implementing ISO 28000 if compliance with ISO 28001 is a management objective
  • ISO 28005 Security management systems for the supply chain – Electronic port clearance (EPC)

See also[edit]


  1. ^ "Iso 28000:2022".
  2. ^ a b "ISO/TC 8 - Ships and marine technology". ISO.
  3. ^ a b "Isotc292".
  4. ^ ISO 28004: 2007 Guidelines for implementation of ISO 28000
  5. ^ Siegal, M. Standards Changing the World of Security Professionals. ASIS International: Virtual Seminar. 2008
  6. ^ "Archived copy". Archived from the original on 2015-02-17. Retrieved 2015-02-17.{{cite web}}: CS1 maint: archived copy as title (link)
  7. ^ "".
  8. ^ "".
  9. ^ ISO 28000: 2007 Specifications for security risk management systems for the supply chain [1]
  10. ^ ISO 28000:2007 Specification for security management systems for the supply chain
  11. ^ "ISOTC292".
  12. ^ "ISO 28000:2007". SRI. Retrieved 2020-07-27.
  13. ^ "ISO 28004-2:2014". ISO.