ISO 28000:2022
Security Management System
For organisations of any type and size establishing security management, including supply chain aspects.
ClassManagement system standard
Edition2022
What is this standard?
Specifies requirements for a security management system, including aspects relevant to the supply chain. It offers a holistic, common approach and is not industry or sector specific. It can be applied to any activity, internal or external, at all levels.
Who is it for?
All types and sizes of organisation, including commercial enterprises, government agencies and non-profits.
What triggers an assessment?
- Physical or operational security risk is being managed.
- Supply chain security is a customer or regulatory requirement.
- A common security framework is needed across a multi-site operation.
What does it not replace?
- It is not an information security management system; ISO/IEC 27001 is a separate record.
- It does not substitute for a private security service licence or public security authority.
Official source
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.