Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 28000:2022 security management systems

ISO 28000: A Clear Guide to the 2022 Security Standard

ISO 28000 stopped being a supply chain standard in 2022. The second edition retitled it Security and resilience — Security management systems — Requirements, widened it to security management for any organization, and rebuilt it on the harmonized management system structure. Documentation written to the 2007 edition describes a standard that no longer exists in that form.

This guide covers what the current edition requires, the clause 8 requirements that carry the technical work, and what to do if your system was built on the older text.

ISO 28000 clause 8: the operation requirements of the 2022 edition
Clause 8 is where the security management system stops being generic.

What ISO 28000 is now

The 2022 edition is a requirements standard for a security management system, certifiable, and structured like every other modern management system standard: context, leadership, planning, support, operation, performance evaluation and improvement. That structure is what makes it integrable — an organization already running ISO 9001, ISO 22301 or ISO 27001 recognizes seven-eighths of the document.

The scope change matters commercially. The original standard was framed around the supply chain, and it is still the natural fit for logistics, ports, warehousing and freight. The current text applies to security management generally, which is why it now appears in tenders from organizations with no shipping operation at all.

Clause 8: where the work is

Clause Requirement What it produces
8.1 Operational planning and control The processes that deliver security, planned and controlled
8.2 Identification of processes and activities What you actually do, and where security applies to it
8.3 Risk assessment and treatment Security risks assessed and treatment decided
8.4 Controls The measures selected, and why
8.5 Security strategies, procedures, processes and treatments How the controls are delivered in practice
8.6 Security plans The documented plans that people follow when it matters

Two of these repay particular attention. Clause 8.2 — identification of processes and activities — is the one organizations skip, and it is the reason so many security management systems protect an idealized version of the operation rather than the real one. The activities you actually perform, including the informal workarounds, are the subject of the system.

And clause 8.6 asks for security plans as artifacts. A control list is not a plan. The plan is what a supervisor reads at 2 a.m. when a seal is broken or a driver does not arrive.

What a security risk assessment covers here

The risks in scope are deliberate acts as well as accidental ones: theft, diversion, tampering, unauthorized access, sabotage, smuggling and the insider variants of each. That framing differs from a safety or continuity assessment, where the hazard has no intent, and it changes the analysis — an adversary adapts to your controls in a way that weather does not.

Practical consequences worth building in:

  • Assess the whole chain you influence, not just your own site. Handover points — gate, yard, transfer, subcontracted leg — are where custody is lost and where most incidents originate.
  • Treat people as both control and risk. Screening, supervision and separation of duties are security controls; concentration of access in one trusted role is a security risk.
  • Record the residual position. Security controls rarely eliminate a determined threat; what the system needs is an explicit decision about what remains and who accepted it.

Where ISO 28000 sits against neighbouring standards

Three comparisons come up in tenders:

  • ISO 27001 protects information; ISO 28000 protects goods, people, sites and operations. They overlap on access control and supplier assurance and answer different questions.
  • ISO 22301 is about continuing when something stops; ISO 28000 is about preventing deliberate interference. A serious security incident is usually a continuity event too, which is why the two systems share incident and exercise machinery.
  • TISAX is the automotive sector’s answer to repeated supplier audits, with its own catalogue and exchange mechanism rather than an ISO certificate. Our guide to supply chain security assurance routes compares the two directly, and the TISAX audit checklist covers that path.

Frequently asked questions

Is ISO 28000 still a supply chain standard?
It began as one and remains the natural fit for logistics and freight, but the 2022 edition is written as a security management system standard for any organization.

Is it certifiable?
Yes. It is a requirements standard and organizations certify to it through accredited bodies.

Can we integrate it with our existing management system?
Yes, and you should. It uses the harmonized structure, so context, leadership, support, performance evaluation and improvement can be shared with ISO 9001, ISO 22301 or ISO 27001, leaving clause 8 as the security-specific work.

What if our documentation cites the 2007 edition?
Rebuild against the current text rather than editing. The retitle and restructure mean clause references from the old edition do not map cleanly, and an auditor reading old clause numbers will treat the system as unmaintained.

Does it require particular controls?
No fixed catalogue. Clause 8.4 requires controls to be determined and implemented; the selection follows your risk assessment, which is what makes the assessment the load-bearing document.

Where this leaves you

Build an ISO 28000 system from the operation you actually run: identify the processes and activities honestly, assess deliberate-act risk across the handover points you influence, select controls from that assessment, and write security plans somebody can follow under pressure. Integrate the shared clauses with whatever management system you already certify, and if your documents still cite the 2007 edition, rewrite rather than renumber — the standard changed name, scope and structure, and the paperwork should say so.

References

  • ISO 28000:2022 — Security and resilience, security management systems, requirements.
  • ISO 22301:2019 — the continuity standard ISO 28000 is most often integrated with.

More on security and resilience

Security risk assessments, control records and security plans are in the ISO 28000 Supply Chain Security Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.