Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  



























Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 Scope and contents  





2 Benefits  





3 Improved risk management integration  





4 Application  





5 History  





6 Related standards  





7 See also  





8 References  














ISO 28000






Deutsch
Tiếng Vit
 

Edit links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 


















From Wikipedia, the free encyclopedia
 


ISO 28000:2022, Security and resilience – Security management systems – Requirements, is a management system standard published by International Organization for Standardization (ISO) that specifies requirements for a security management system including aspects relevant to the supply chain.[1]

The standard was originally developed by ISO/TC 8 on "Ships and maritime technology" and published in 2007.[2] In 2015 the responsibility for the ISO 28000 series was transferred to ISO/TC 292 on "Security and resilience", who in 2019 decided to start a revision. A justification study for the revision was accepted by ISO TMB (Technical Management Board).[3] The revised version of ISO 28000 was published on March 15, 2022.

Scope and contents[edit]

Similar to other management system standards by ISO, the requirements specified in ISO 28000 are generic and intended to be applicable to all organizations, regardless of type, size, and industry. However, the extent of applicability of the requirements depends on the organization's environment and complexity.

ISO 28000:2022 is divided into 10 main clauses and has adopted the harmonized structure and standardized text set out by Annex SL.

The standard is divided as follows:

  1. Scope
  2. Normative references
  3. Terms and definitions
  4. Context of the organization
  5. Leadership
  6. Planning
  7. Support
  8. Operation
  9. Performance evaluation
  10. Improvement

ISO 28000:2007 was developed to standardize security within the broader supply chain management system. In the revision the PDCA management systems structure was adopted in expanding ISO 28000 to bring the elements of this standard in congruence with related standards such as ISO 9001:2000, ISO 14001:2004 and in particular ISO 22301:2018. Also the limitations of security within the supply chain were eliminated so that now it is clear that it can be used throughout all aspects of security of the organization.

Benefits[edit]

Implementing ISO 28000 has broad strategic, organisational and operational benefits that are realized throughout the organization.

Benefits include, but are not limited to:

Improved risk management integration[edit]

The international standard addresses specifically the assessment and treatment of security-related risks (risks that relate to the security of the organization and its interested parties) and in this context refers to ISO 31000. This improves the broader interface with existing enterprise risk management in a common integrated platform. This integrated approach to risk management is recommended by ISO 31000 to better coordinate cross functional risk management mechanisms, improve performance measurement, ensure continual improvement and prevent silo thinking within the organization.

Application[edit]

ISO 28000:2007 was initially developed so that organizations of varying scale could apply the standard to their supply chains of various degrees of complexity. Now, after the revision, ISO 28000:2022 can be applied beyond the supply chain to all aspects of the organization.

The general rational for an organization to adopt ISO 28000:2022 pertains to:

ISO 28000:2022 is a certifiable standard.[4] In 2016, the countries with the highest number of certificates were India (425), Japan (299), Spain (231), US (223) and UK (197).[3]

History[edit]

ISO 28000 was originally developed as a Publicly Available Specification by ISO technical committee ISO/TC 8 on Ships and marine technology [2] and published in 2005. In 2007, ISO/PAS 28000:2005 was withdrawn and replaced by a full ISO standard under the title ISO 28000:2007. In 2014, ISO 28000:2007 was reviewed and confirmed.[5]
In 2015, ISO/TC 292 Security and resilience took over the responsibility of the standard and decided later in 2019 to initiate a revision of the standard.[6] In March 2022 the revised second edition of the standard was published.[7]

Year Description
2005 ISO/PAS 28000
2007 ISO 28000 (1st edition)
2022 ISO 28000 (2nd edition)

Related standards[edit]

ISO 28000 is the first of a series of ISO security management standards including:[8]

See also[edit]

References[edit]

  1. ^ "Iso 28000:2022". 4 May 2022.
  • ^ a b "ISO/TC 8 - Ships and marine technology". ISO. 17 November 2020.
  • ^ a b "Isotc292".
  • ^ ISO 28000: 2022 Security and resilience -- Security management systems - Requirements [1]
  • ^ https://www.iso.org/standard/44641.html ISO 28000:2007 Specification for security management systems for the supply chain
  • ^ "ISOTC292". www.isotc292online.org.
  • ^ "ISOTC292". www.isotc292online.org.
  • ^ "ISO 28000:2007". SRI. Retrieved 2020-07-27.
  • ^ "ISO 28004-2:2014". ISO.

  • Retrieved from "https://en.wikipedia.org/w/index.php?title=ISO_28000&oldid=1168080037"

    Categories: 
    ISO standards
    Supply chain management
    ISO publicly available specifications
    Hidden categories: 
    Articles with short description
    Short description matches Wikidata
    Use Oxford spelling from December 2011
     



    This page was last edited on 31 July 2023, at 17:31 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki