ISO 28000
ISO 28000 is an international standard that helps organizations set up a management system for handling security concerns related to their supply chains. It provides a structured framework for identifying and managing security risks, but it focuses on security rather than covering every type of supply chain risk. An organization can build its practices around this standard, and in some cases seek certification against it.
ISO 28000 is a high-level, requirements-based management system standard that specifies criteria for establishing, implementing, and maintaining a security management system, including aspects critical to the security assurance of the supply chain. The current edition, ISO 28000:2022 (published under the "Security and resilience" family and superseding ISO 28000:2007), is intended to be applicable to organizations of varying types and sizes. Its scope centers on security management as it relates to supply chain operations; it does not by itself address the full spectrum of supply chain risk domains such as financial, operational, geopolitical, or ESG risk except where these intersect with security assurance. As a management system standard, conformity may be independently certified, but certification attests to conformity with the standard's requirements at a point in time and does not by itself guarantee the absence of security incidents or extend visibility across all tiers of a supply chain.
Why it matters
Supply chain security spans a wide range of threats, from physical tampering and cargo theft to unauthorized access and disruption of logistical flows, that individual, ad hoc controls often address inconsistently. ISO 28000 matters because it gives organizations a structured, requirements-based management system for security assurance across supply chain operations, allowing them to move from fragmented practices to a repeatable framework for identifying, managing, and reviewing security risks. As a high-level management system standard, it is designed to be applicable to organizations of varying types and sizes, which makes it a common reference point when parties across a supply chain need a shared vocabulary for security expectations.
It is important to be clear about what ISO 28000 is and is not. Its scope centers on security management as it relates to the supply chain; it does not by itself cover the full spectrum of supply chain risk domains such as financial, operational, geopolitical, or ESG risk, except where those intersect with security assurance. Organizations that treat conformity with ISO 28000 as evidence of broad supply chain resilience or risk coverage may overstate what the standard delivers.
Equally important, certification against ISO 28000 attests to conformity with the standard's requirements at a point in time. It does not guarantee the absence of security incidents, nor does it by itself extend visibility across all tiers of a supply chain. Risk professionals relying on a supplier's certification should treat it as one input into due diligence rather than as independent assurance that security controls remain effective over time or that deeper tiers of the supply chain are equally governed.
Who it's relevant to
Inside ISO 28000
Common questions
Answers to the questions practitioners most commonly ask about ISO 28000.
