ISO28001-4.1 | Supply chain security context | 0 |
ISO28001-4.10 | Operational control | 0 |
ISO28001-4.11 | Emergency preparedness and response | 3 |
ISO28001-4.12 | Performance monitoring and measurement | 0 |
ISO28001-4.13 | Evaluation of compliance | 3 |
ISO28001-4.14 | Related security incident investigation | 0 |
ISO28001-4.15 | Nonconformity, corrective and preventive action | 10 |
ISO28001-4.16 | Control of records | 3 |
ISO28001-4.17 | Internal audit | 14 |
ISO28001-4.18 | Management review | 15 |
ISO28001-4.2 | Security management policy | 0 |
ISO28001-4.3 | Security risk assessment | 1 |
ISO28001-4.4 | Security objectives and targets | 0 |
ISO28001-4.5 | Security plan | 0 |
ISO28001-4.6 | Resources, roles, responsibility | 0 |
ISO28001-4.7 | Competence and training | 0 |
ISO28001-4.8 | Communication and consultation | 16 |
ISO28001-4.9 | Documentation control | 0 |
ISO28001-A.5 | Cargo integrity and conveyance security | 0 |
ISO28001-A.6 | Personnel security and access | 0 |
ISO28001-A.7 | Information and IT security | 0 |
ISO28001-A.8 | Business partner and AEO compatibility | 0 |
ISO28001-A.9 | Physical security of facilities | 0 |
ISO28001-PC-01 | Customs and Trade Compliance | 1 |
ISO28001-PC-02 | Manifest and Documentation Procedures | 3 |
ISO28001-PC-03 | Supply Chain Incident Reporting | 59 |
ISO28001-PC-04 | Supply Chain Continuity Planning | 151 |
ISO28001-PI-01 | Personnel Security Screening | 146 |
ISO28001-PI-02 | Security Awareness and Training | 23 |
ISO28001-PI-03 | Information Security in Supply Chain | 3 |
ISO28001-PI-04 | Business Partner Security Requirements | 0 |
ISO28001-PS-01 | Facility Security | 139 |
ISO28001-PS-02 | Conveyance Security | 3 |
ISO28001-PS-03 | Cargo Security | 0 |
ISO28001-PS-04 | Key and Seal Management | 0 |
ISO28001-SA-04 | Security Risk Treatment Planning | 74 |
4 | 4 Field of application | 0 |
4.1 | 4.1 Statement of application | 0 |
4.2 | 4.2 Business partners | 0 |
4.3 | 4.3 Internationally accepted certificates or approvals | 0 |
4.4 | 4.4 Business partners exempt from security declaration requirement | 0 |
4.5 | 4.5 Security reviews of business partners | 0 |
5 | 5 Supply chain security process | 0 |
5.1 | 5.1 General | 0 |
5.2 | 5.2 Identification of the scope of the security assessment | 0 |
5.3 | 5.3 Conduction of the security assessment | 0 |
5.3.1 | 5.3.1 Assessment personnel | 0 |
5.3.2 | 5.3.2 Assessment process | 0 |
5.4 | 5.4 Development of the supply chain security plan | 0 |
5.5 | 5.5 Execution of the supply chain security plan | 0 |
5.6 | 5.6 Documentation and monitoring of the supply chain security process | 0 |
5.6.1 | 5.6.1 General | 0 |
5.6.2 | 5.6.2 Continual improvement | 0 |
5.7 | 5.7 Actions required after a security incident | 0 |
5.8 | 5.8 Protection of the security information | 0 |
A | Annex A (informative) Supply chain security process | 0 |
A.2 | A.2 Identification of the scope of the security assessment | 0 |
A.3 | A.3 Conduction of the security assessment | 0 |
A.3.1 | A.3.1 General: locations to assess | 0 |
A.3.2 | A.3.2 Performance review list | 0 |
A.3.3 | A.3.3 Performance review (Table A.1) | 0 |
A.3.4 | A.3.4 Security threat scenarios (Table A.2) | 0 |
A.4 | A.4 Development of the security plan | 0 |
A.4.1 | A.4.1 General: security plan contents | 0 |
A.4.2 | A.4.2 Documentation | 0 |
A.4.3 | A.4.3 Communication | 0 |
A.5 | A.5 Execution of the security plan | 0 |
A.6 | A.6 Documentation and monitoring of the security process | 0 |
A.7 | A.7 Continual improvement | 0 |
ANNEX-C | Annex C (informative): guidance for obtaining advice and certification | 0 |
B | Annex B (informative) Methodology for security risk assessment and development of countermeasures | 0 |
B.10 | B.10 Continuation of the process | 0 |
B.2 | B.2 Step one: consideration of the security threat scenarios | 0 |
B.3 | B.3 Step two: classification of consequences | 0 |
B.4 | B.4 Step three: classification of likelihood of security incidents | 0 |
B.5 | B.5 Step four: security incident scoring | 0 |
B.6 | B.6 Step five: development of countermeasures | 0 |
B.7 | B.7 Step six: implementation of countermeasures | 0 |
B.8 | B.8 Step seven: evaluation of countermeasures | 0 |
B.9 | B.9 Step eight: repetition of the process | 0 |
STANDARD | ISO 28001:2007: scope, terms and the WCO SAFE and AEO context | 0 |
STATUS | Edition status and the ISO 28000 family | 0 |