ISO 28000:2022, including Amendment 1: Climate action changes
Security Management System
ISO 28000 (2022) is a management system standard: Security Management System. Specifies requirements for a security management system, including aspects relevant to the supply chain. It offers a holistic, common approach and is not industry or sector specific. It can be applied to any activity, internal or external, at all levels. It applies to all types and sizes of organisation, including commercial enterprises, government agencies and non-profits.
- Class
- Management system standard
- Edition
- 2022
- Related sectors
- 3
- Last verified
What is this standard?
Specifies requirements for a security management system, including aspects relevant to the supply chain. It offers a holistic, common approach and is not industry or sector specific. It can be applied to any activity, internal or external, at all levels.
What ISO 28000 does not replace
- It is not an information security management system; ISO/IEC 27001 is a separate record.
- It does not substitute for a private security service licence or public security authority.
Who is it for?
All types and sizes of organisation, including commercial enterprises, government agencies and non-profits.
What triggers an assessment?
- Physical or operational security risk is being managed.
- Supply chain security is a customer or regulatory requirement.
- A common security framework is needed across a multi-site operation.
Official source
Amendment source
- Amendment 1: Climate action changes ↗ — Last verified:
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.