verified_user
Standardful
首頁chevron_right標準chevron_rightISO 28000:2022
現行有效國際標準update 最後更新:2022年3月

ISO 28000:2022

安全與韌性 安全管理系統 要求

apartment發布組織:國際標準化組織 (ISO)

標準簡介

ISO 28000:2022 是以供應鏈安全為重點的安全管理系統國際標準。該標準於 2022 年 3 月發布第二版,規定了建立、實施、維護和持續改進安全管理系統的要求。該標準涵蓋網路攻擊、恐怖主義、有組織犯罪、自然災害、疫情和地緣政治不穩定等當代威脅。

2022 年修訂版採用 ISO 協調結構(HLS),可與 ISO 9001、ISO 14001 和 ISO 27001 等其他管理系統標準整合。ISO 28000 適用於供應鏈任何階段涉及製造、服務、倉儲和運輸的各類規模組織。認證支持參與美國 C-TPAT 和歐盟 AEO 計畫等可信貿易商計畫,提供加速通關和減少檢查等便利。

local_shipping

Supply Chain Security

Provides a comprehensive framework for managing security threats across the entire supply chain, from procurement through manufacturing to final delivery and distribution.

sync

HLS Aligned

The 2022 revision adopts the ISO Harmonized Structure (HLS), enabling seamless integration with ISO 9001, ISO 14001, ISO 27001, and other management system standards.

gpp_maybe

Multi-Threat Coverage

Addresses modern security threats including cyber attacks, terrorism, organized crime, natural disasters, pandemics, and geopolitical instability affecting supply chains.

list_alt Security Management Elements

  • Security threat and risk assessment
  • Security management policy and objectives
  • Organizational context and interested parties
  • Leadership commitment and security roles
  • Operational planning and control
  • Supply chain partner security requirements
  • Incident management and business continuity
  • Performance evaluation and continual improvement

Who Needs to Comply?

groups

Organizations involved in supply chain management — manufacturers, logistics providers, freight forwarders, port operators, warehousing companies, and any organization seeking to protect its supply chain from security threats.

Key Requirements

1

Security Threat Assessment

Identify, analyze, and evaluate security threats and vulnerabilities across the supply chain. Consider physical, cyber, personnel, and information security risks relevant to the organization's operations.

2

Security Management Plan

Develop and implement security management plans that address identified threats, define response procedures, assign responsibilities, and establish communication protocols for security incidents.

3

Supply Chain Partner Management

Establish security requirements for supply chain partners, contractors, and service providers. Verify partner compliance and maintain oversight of outsourced security-relevant activities.

4

Incident Response and Recovery

Establish procedures for detecting, reporting, and responding to security incidents. Implement business continuity plans to minimize disruption and recover from security events.

Penalties & Enforcement

warning

No direct legal penalties — ISO 28000 is a voluntary standard. However, certification can be required by customs authorities for trusted trader programs (e.g., C-TPAT, AEO) and by business partners in high-security supply chains. Loss of certification may affect trade facilitation benefits.

官方文件

查看全部

實施時間線

description
2007年
ISO 28000:2007 first edition published for supply chain security management
fact_check
2008年
ISO 28001:2007 published with best practices for supply chain security assessments
update
2022年3月
ISO 28000:2022 revised edition published with HLS structure and expanded scope
trending_up
2022-2023
Adoption grows with increasing supply chain disruptions and geopolitical tensions
schedule
2025年3月
Three-year transition deadline from ISO 28000:2007 to 2022 edition

相關分類