The Standards of ISO 28000
ISO 28000 represents a set of industry standards published in 2007 by the International Organization for Standardization (ISO). It set the requirements for a management system to ensure the security of a supply chain.
-
Objectives
-
These standards aim at improving the performance of manufacturers, transporters and retailers involved in the supply chain. The rules set a common philosophy for the handling of the product, to ensure that it reaches the customer and meets the recipient's expectations.
Principles
-
The guidelines form four groups of standards. ISO 28001 describes how to assess security risks, including terrorism threats, from a broad perspective. ISO 28002 sets a framework for developing processes to monitor and correct supply chain problems. ISO 28003 covers requirements for passing certification and helpful recommendations for auditors to evaluate compliance to the rules. Finally, ISO 28004 paints an elevated perspective of the objectives of these standards.
-
Certification
-
A company interested in obtaining ISO 28000 certification can contact an accreditation firm that will contract an auditing agency. Auditors review the company's interactions with corporate partners involved in the supply chain and compare the standards to the practices. The accreditation group grants the certification if no major deviation from the rules has been noted. Minor gaps receive a one-year grace period to fix them. Certification must be renewed every three years.
-