ISO 28000:2022 · security management system
Supply chain security also means physical security.
Theft, tampering, smuggling, sabotage – ISO 28000 addresses the risks that arise while goods are in transit and pass through other people’s hands.
ISO 28000 describes a security management system tailored to supply chains. The 2022 edition follows the Annex SL structure and therefore runs alongside ISO 9001 or ISO 27001. It considers threats along the entire chain, including transport, handling and storage at third parties.
For companies with high-value, hazardous or regulated goods it closes a gap: information security covers data, quality management covers conformity – but who has access to the goods between the gate and the customer is answered by neither.
Where the risks sit
- Transfer points where goods stand unattended.
- Transport subcontractors engaged by your forwarder whom you have never seen.
- Storage at third parties without documented access control.
- Returns, where the chain runs backwards.
What the standard requires
- Context
- Determine security-relevant threats along the chain.
- Risk assessment
- Assess where goods are exposed and derive measures.
- Govern partners
- Set and verify requirements for transport, storage and handling partners.
- Incidents
- Record and investigate security incidents and feed them back into assessment.
- Exercise and improve
- Test effectiveness rather than describing it.
How SCRM covers it
Partners in the chain
Forwarder, warehouse operator and their subcontractors as separate records.
Requirements per class
Security conditions graded by value and exposure of the goods.
Incident history
Spot patterns: same route, same transfer point, repeatedly.
Evidence with expiry
Partner certificates and confirmations, with reminders.
Frequently asked
How does ISO 28000 relate to AEO status?
They overlap heavily. A system run to ISO 28000 covers many authorised economic operator requirements but does not replace the customs authorisation.
Do we need it alongside ISO 27001?
ISO 27001 protects information, ISO 28000 the physical chain. For high-value or regulated goods they complement each other.
Is certification necessary?
Only where customers or insurers require it. The structure is a useful framework without a certificate.