International (ISO/TC 8, now ISO/TC 292); adopted as BS ISO 28001:2007, SIST ISO 28001:2008 and others

ISO 28001:2007 Supply Chain Security Management

82 controls. 274 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

82 controls 274 frameworks share controls with it International (ISO/TC 8, now ISO/TC 292); adopted as BS ISO 28001:2007, SIST ISO 28001:2008 and others verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ISO28001-4.1Supply chain security context0
ISO28001-4.10Operational control0
ISO28001-4.11Emergency preparedness and response3
ISO28001-4.12Performance monitoring and measurement0
ISO28001-4.13Evaluation of compliance3
ISO28001-4.14Related security incident investigation0
ISO28001-4.15Nonconformity, corrective and preventive action10
ISO28001-4.16Control of records3
ISO28001-4.17Internal audit14
ISO28001-4.18Management review15
ISO28001-4.2Security management policy0
ISO28001-4.3Security risk assessment1
ISO28001-4.4Security objectives and targets0
ISO28001-4.5Security plan0
ISO28001-4.6Resources, roles, responsibility0
ISO28001-4.7Competence and training0
ISO28001-4.8Communication and consultation16
ISO28001-4.9Documentation control0
ISO28001-A.5Cargo integrity and conveyance security0
ISO28001-A.6Personnel security and access0
ISO28001-A.7Information and IT security0
ISO28001-A.8Business partner and AEO compatibility0
ISO28001-A.9Physical security of facilities0
ISO28001-PC-01Customs and Trade Compliance1
ISO28001-PC-02Manifest and Documentation Procedures3
ISO28001-PC-03Supply Chain Incident Reporting59
ISO28001-PC-04Supply Chain Continuity Planning151
ISO28001-PI-01Personnel Security Screening146
ISO28001-PI-02Security Awareness and Training23
ISO28001-PI-03Information Security in Supply Chain3
ISO28001-PI-04Business Partner Security Requirements0
ISO28001-PS-01Facility Security139
ISO28001-PS-02Conveyance Security3
ISO28001-PS-03Cargo Security0
ISO28001-PS-04Key and Seal Management0
ISO28001-SA-04Security Risk Treatment Planning74
44 Field of application0
4.14.1 Statement of application0
4.24.2 Business partners0
4.34.3 Internationally accepted certificates or approvals0
4.44.4 Business partners exempt from security declaration requirement0
4.54.5 Security reviews of business partners0
55 Supply chain security process0
5.15.1 General0
5.25.2 Identification of the scope of the security assessment0
5.35.3 Conduction of the security assessment0
5.3.15.3.1 Assessment personnel0
5.3.25.3.2 Assessment process0
5.45.4 Development of the supply chain security plan0
5.55.5 Execution of the supply chain security plan0
5.65.6 Documentation and monitoring of the supply chain security process0
5.6.15.6.1 General0
5.6.25.6.2 Continual improvement0
5.75.7 Actions required after a security incident0
5.85.8 Protection of the security information0
AAnnex A (informative) Supply chain security process0
A.2A.2 Identification of the scope of the security assessment0
A.3A.3 Conduction of the security assessment0
A.3.1A.3.1 General: locations to assess0
A.3.2A.3.2 Performance review list0
A.3.3A.3.3 Performance review (Table A.1)0
A.3.4A.3.4 Security threat scenarios (Table A.2)0
A.4A.4 Development of the security plan0
A.4.1A.4.1 General: security plan contents0
A.4.2A.4.2 Documentation0
A.4.3A.4.3 Communication0
A.5A.5 Execution of the security plan0
A.6A.6 Documentation and monitoring of the security process0
A.7A.7 Continual improvement0
ANNEX-CAnnex C (informative): guidance for obtaining advice and certification0
BAnnex B (informative) Methodology for security risk assessment and development of countermeasures0
B.10B.10 Continuation of the process0
B.2B.2 Step one: consideration of the security threat scenarios0
B.3B.3 Step two: classification of consequences0
B.4B.4 Step three: classification of likelihood of security incidents0
B.5B.5 Step four: security incident scoring0
B.6B.6 Step five: development of countermeasures0
B.7B.7 Step six: implementation of countermeasures0
B.8B.8 Step seven: evaluation of countermeasures0
B.9B.9 Step eight: repetition of the process0
STANDARDISO 28001:2007: scope, terms and the WCO SAFE and AEO context0
STATUSEdition status and the ISO 28000 family0

Tell me when ISO 28001:2007 Supply Chain Security Management files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Roles and responsibilities matrix
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Anti-bribery policy
  • Quality objectives
  • NC register
  • Root cause analyses
  • CAPA records
  • Effectiveness reviews

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 28001:2007 Supply Chain Security Management, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition