Specification for security management systems for the supply chain
This standard has been revised by ISO 28000:2007.
ISO/PAS 28000:2005 specifies the requirements for a security management system, including those aspects critical to security assurance of the supply chain. These aspects include, but are not limited to, financing, manufacturing, information management and the facilities for packing, storing and transferring goods between modes of transport and locations. Security management is linked to many other aspects of business management. These other aspects should be considered directly, where and when they have an impact on security management, including transporting these goods along the supply chain.
ISO/PAS 28000:2005 is applicable to all sizes of organizations, from small to multinational, in manufacturing, service, storage or transportation at any stage of the production or supply chain that wishes to:
- establish, implement, maintain and improve a security management system;
- assure compliance with stated security management policy;
- demonstrate such compliance to others;
- seek certification/registration of its security management system by an Accredited third party Certification Body; or
- make a self-determination and self-declaration of compliance with ISO/PAS 28000:2005.
There are legislative and regulatory codes that address some of the requirements in ISO/PAS 28000:2005. It is not the intention of ISO/PAS 28000:2005 to require duplicative demonstration of compliance.
Organizations that choose third party certification can further demonstrate that they are contributing significantly to supply chain security.