ISO 28000:2022 — Security Management Systems
Security and resilience — security management systems for the supply chain. ISO 28000:2022 (second edition) replaces ISO 28001:2007 with a comprehensive PDCA-based security management system framework, aligned with ISO 31000 (risk) and ISO 22301 (business continuity).
ISO 28000:2022 is the second edition of the international standard for security management systems, prepared by Technical Committee ISO/TC 292 (Security and resilience), published March 2022. It cancels and replaces ISO 28000:2007 (also known as ISO 28001:2007 — Supply Chain Security). The 2022 edition maintains existing requirements while adding recommendations aligned with ISO 31000 (risk management) in Clause 4, and recommendations for better consistency with ISO 22301 (business continuity) in Clause 8 — including security strategies, procedures, processes and treatments, security plans with response structure, warning and communication, and recovery. It applies the Plan-Do-Check-Act (PDCA) model to the organisation's security management system.
Logistics companies, freight forwarders, customs brokers, exporters, importers, port operators, and supply chain participants requiring documented security management practices for international trade.
- Demonstrates supply chain security practices to customs and trade authorities
- Supports AEO (Authorised Economic Operator) status applications
- Reduces risk of cargo theft, tampering, and smuggling
- Required by some shipping lines and logistics clients
- Structured approach to supply chain threat and risk assessment
- Improves supply chain transparency and traceability