Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 28000 mandatory documents explained

ISO 28000 Mandatory Documents: The Complete Clause-by-Clause List

ISO 28000 mandatory documents are the documented information ISO 28000:2022 requires a security management system to maintain and the records it requires it to retain, and the list is short: the standard follows the harmonized structure’s rule of naming a small set and leaving the rest to the organisation under clause 7.5. There is no security manual in it, no prescribed procedure format and no control catalogue. What it does name divides into the documents that describe the system — scope, security policy, objectives, the processes and activities identified under 8.2 — and the records that prove it operates: the risk assessment and treatment under 8.3, the controls under 8.4, the procedures under 8.5, the security plans under 8.6, competence, monitoring results, audits, management review and corrective action. This guide lists the ISO 28000 mandatory documents clause by clause, explains what each has to contain to survive a certification audit or a customs validation, separates the security-specific documents from the shared core, and names the second tier that no clause requires and every auditor asks for.

ISO 28000 mandatory documents: maintain the system, retain the evidence
Maintained: scope, security policy, objectives, processes and activities (8.2), risk assessment and treatment (8.3), controls (8.4), procedures (8.5), security plans (8.6) · Retained: competence, monitoring, audit, review, nonconformity records.

How ISO 28000 uses the term documented information

ISO 28000:2022 uses the harmonized structure’s single term, documented information, for documents and records alike; where the text says maintain, it means a living controlled document, and where it says retain, it means a record kept as evidence. Clause 7.5 requires the documented information the standard specifies plus whatever the organisation determines is necessary for the effectiveness of the security management system — and for a security system that second half is large, because clause 8.4 controls are only auditable through the procedures, logs and registers that show them operating. Our guide to ISO 28000:2022 covers the edition; this post covers what it makes you write down.

The ISO 28000 mandatory documents, clause by clause

Clause (ISO 28000:2022) Documented information Maintain or retain What the auditor tests
4.3 Scope The scope of the security management system: sites, activities, supply chain segments, exclusions with justification Maintain Scope matches the operation; subcontracted legs and yards are in or justified out
5.2 Security policy The security policy Maintain Commitments, framework for objectives, communicated, available to interested parties
6.2 Security objectives The objectives and plans to achieve them Maintain Measurable; owned; monitored — incident rates, seal discrepancies, audit closure
7.2 Competence Evidence of competence Retain Security roles, drivers, inspectors, guards; training records by function
7.5 Documented information Control of documented information Maintain Current versions in use; obsolete procedures withdrawn from the gatehouse
8.1 Operational planning and control Documented information to the extent necessary for confidence processes are carried out as planned, including outsourced processes Maintain and retain Subcontracted transport and security services controlled
8.2 Identification of processes and activities The processes and activities within scope and where security applies Maintain The list matches what happens — including night operations and workarounds
8.3 Risk assessment and treatment The risk assessment: threats, vulnerabilities, consequences, evaluation, treatment decisions, residual risk Maintain and retain Traceable to controls; reviewed annually and on change
8.4 Controls The controls determined and implemented Maintain Each control cites a risk; each risk rated for treatment has a control
8.5 Security strategies, procedures, processes and treatments The procedures by which controls operate Maintain Seal control, access control, conveyance inspection, cargo staging, incident reporting, partner screening
8.6 Security plans Security plans for the incidents the assessment says are credible Maintain Roles, triggers, first actions, escalation, authorities; accessible at 2 a.m.
9.1 Monitoring, measurement, analysis and evaluation Evidence of the results Retain Incident and near-miss data, seal audits, gate logs, KPI trends
9.2 Internal audit The audit programme and results Retain Programme by risk; independent auditor; findings closed
9.3 Management review Evidence of the results Retain Inputs including residual risk; decisions recorded
10 Improvement Nonconformities, actions and results Retain Root cause; effectiveness verified

The clause headings are the 2022 edition’s; the requirements for what to document under 8.2 to 8.6 are the clauses’ own, and the 2022 foreword records that recommendations were added in clause 8 “for better consistency with ISO 22301”, which is why the sequence — identify, assess, control, procedure, plan — mirrors the continuity standard. Confirm wording against your copy before building the register. Our guide to ISO 22301 mandatory documents shows the sister list.

The security-specific ISO 28000 mandatory documents

  1. The process and activity register (8.2). The document most systems skip and the reason so many protect an idealised operation. It lists what is actually done — receiving, staging, sealing, subcontracted legs, returns, night shifts — and where security applies. Auditors walk it against the yard.
  2. The risk assessment and treatment (8.3). The load-bearing document. Threats with intent, vulnerabilities at handovers, consequences including customs status, scores, treatments, residual risk accepted by name. Our guide to the supply chain security risk assessment covers the method.
  3. The control register (8.4). Each control with owner, verification method and the risk row it treats. A control without a risk is a cost; a risk without a control is a finding.
  4. The procedures (8.5). Seal control including ISO 17712 high-security seals, seal verification and audits; conveyance and container inspection; cargo staging and release; access control, visitor identification and logs; business partner screening; incident reporting and escalation; cybersecurity. These are also the documents a C-TPAT validator or AEO auditor reads, which is why the register should cross-reference their criteria.
  5. The security plans (8.6). Not a control list: a plan is what a supervisor follows when a seal is broken, a trailer is missing or an unauthorised person is on site.

Beyond the ISO 28000 mandatory documents: what auditors still expect

Not named by a clause Why it is asked for Where it lives
Interested-party and requirements register 4.2: customers’ security clauses, customs criteria, insurers’ conditions, regulators Context file
Supply chain map with handovers The 8.2 and 8.3 evidence in a form a validator can follow Risk assessment
Seal inventory and audit records The procedure under 8.5 is only evidenced by the log Operations
Gate, visitor and access logs 8.4 controls operating Sites
Conveyance inspection checklists 8.5 procedures operating Transport
Business partner screening records 8.1 outsourced processes; C-TPAT and AEO partner criteria Procurement
Incident and near-miss log 9.1 data; feeds the next risk assessment Security
Security manual Not required; useful only as an index to where each clause is met Optional

Building the documented-information register

  1. One row per clause requirement with document name, owner, location, review date, retention period.
  2. Mark maintain versus retain so version control applies to the first and retention to the second.
  3. Add the organisation’s own documented information under 7.5: the procedures, checklists, logs and registers above.
  4. Add a customs column — the C-TPAT criterion or AEO requirement each document evidences — so one register serves the certification audit and the validation. Our guide to ISO 28000 vs C-TPAT maps the overlap.
  5. Retire anything citing ISO 28000:2007, which was retitled, restructured and withdrawn in 2022.

Frequently asked questions

How many ISO 28000 mandatory documents are there?
Fifteen clause-level requirements in the table above: the maintained documents (scope, policy, objectives, processes and activities, risk assessment, controls, procedures, security plans, document control) and the retained records (competence, monitoring, audit, review, corrective action). The register, not the count, is what the audit tests.

Does ISO 28000 require a security manual?
No. Clause 7.5 requires the documented information the standard specifies plus whatever the organisation determines is necessary. A manual is optional.

Which documents are unique to ISO 28000?
The process and activity register (8.2), the security risk assessment and treatment (8.3), the control register (8.4), the security procedures (8.5) and the security plans (8.6). The rest is harmonized core text shared with ISO 9001, ISO 22301 and ISO 27001.

Do the same documents serve C-TPAT or AEO?
Largely. The procedures, risk assessment, partner screening records, seal and access logs and training records are what a CBP validator or customs auditor reads. Add a column to the register mapping each document to the criterion it evidences.

What if our documents cite ISO 28000:2007?
Rebuild against the 2022 text rather than renumbering. The standard was retitled, widened to security management generally and restructured on the harmonized structure; old clause references no longer map.

Where this leaves you

Build the register from the fifteen clause requirements, mark each maintained or retained, and put the effort into the five security-specific documents — processes and activities, risk assessment, controls, procedures, plans — because that is where the ISO 28000 mandatory documents differ from every other management system and where the certification auditor and the customs validator will both look.

References

More on supply chain security

Every document in the register — SMS manual and policy, scope, objectives, process and activity register, risk assessment and treatment workbook, control register, the procedure set and the security plan templates — is drafted in the ISO 28000 Supply Chain Security Toolkit (29 templates), or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.