Contact us
Illustration for ISO management-system services

ISO 28000

ISO 28000 security and supply-chain security management consulting

ISO 28000 consulting helps manufacturers, warehouse operators, logistics providers and other businesses address security risks, supply chain interfaces and incident response within their management system. Vosurein reviews the scope, existing processes and evidence, then helps assign responsibilities, implement controls and conduct internal reviews.

Discuss ISO 28000 security management consulting needs

For Your Business

Who this service is for and when to start

Manufacturers, warehouse operators, logistics providers and other businesses with security management needs. Start by identifying gaps and priorities when responsibilities are unclear, cargo handovers lack traceability or outsourced controls have not been reviewed.

The Challenge

Common challenges faced by businesses

Working access controls and surveillance equipment do not establish who is responsible for cargo handovers, temporary access permissions or carrier incidents. If incident records cover only losses, without examining entry procedures and partner responsibilities, the same weakness may recur at another site.

Our Approach

Methods and applicable requirements

The adopted version is ISO 28000:2022, including Amd 1:2024 Climate Action Amendment. Version history: 2007 edition.

This is a requirements standard for security management systems, covering supply chain-related aspects but not limited to any industry, organization size, or logistics activities. The system arrangements can include internal and external activities; the actual scope must align with responsibilities and risks.

The following consulting tasks can be arranged to suit your needs.

Current Situation and Risks

Identify threats, vulnerabilities, existing controls, and improvement priorities.

Site and Operations

Organize management processes for personnel, visitors, vehicles, goods, and critical areas.

Supply Chain and Partners

Confirm how suppliers, carriers and warehouse operators are assessed, how handovers work and who is responsible.

Incidents and Recovery

Set up incident reporting, response and communication, and track improvements after exercises.

Training and Review

Assist with trials, internal audits, management reviews, and improvement tracking.

Process

Consulting scope and process

  1. Review the security scope and threats

    Interview security and operations contacts to review threats and vulnerabilities involving personnel, goods and critical areas. Compare them with existing equipment and procedures, identifying handovers or interfaces with no responsible owner.

  2. Access, cargo and partner controls

    Link access authorization, goods handover, and external partner requirements to risk, confirming who can decide isolation, reporting, or operation recovery in case of anomalies.

  3. Trial of Reporting and Handover Processes

    Use actual handovers and visitor operations to check procedures, track permission changes and carrier reports for timeliness, and correct arrangements that are difficult to implement on site.

  4. Incident Drills and Effectiveness Review of Controls

    Arrange tabletop exercises or drills based on possible incidents, check communication and handling records, and have management decide on improvement priorities and resources.

Preparation

What documents do companies need to prepare?

  • Organisational sites: Critical areas, activities, and security responsibilities.
  • Operational Flow: Handover of personnel, vehicles, goods, and information.
  • Security Measures: Access control, authorization, contracting, and supplier procedures.
  • Incident Data: Summaries of anomalies, drills, inspections, and improvements.

For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.

Project Planning

Estimating time and cost

Work is estimated from the number of sites, cargo flows, outsourced interfaces and gaps in security records. Additional sites or varied handover arrangements may require more interviews and on-site checks.

The service covers security management procedures and exercise reviews. Access control and surveillance installation, outsourced security operations and customs qualification applications require separate agreements. Third-party certification is arranged for the selected scope.

FAQ

Frequently asked questions

If you already have access control, surveillance equipment, or security services, what more do you need?

Equipment and outsourced services are only part of the controls. Define the risks, responsibilities, incident response and review procedures, then use records to check whether the controls work in practice.

Is ISO 28000 suitable for businesses outside logistics?

Assess suitability against actual security needs. The standard covers supply chain security, but its scope is not limited to logistics.

How does ISO 28000 relate to ISO 28001, AEO and C-TPAT?

ISO 28000 addresses overall security management. ISO 28001 focuses on supply chain security assessment and planning. Customs and customer programmes have separate requirements; ISO certification does not automatically grant eligibility.

Can existing systems and records be reused?

Start with existing site and operations summaries, cargo flows, partner lists, security procedures and handover incident records. Check their period, scope and evidence quality, then fill the gaps. Rewriting every document is not a prerequisite.

There are few security incidents, so do we still need drills?

Fewer incidents do not mean all controls have been tested. Select appropriate scenarios based on major risks to confirm clear responsibilities for communication, decision-making, and recovery operations.

How are consulting and third-party certification responsibilities divided?

Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.

Should we review the scope when adding a warehouse?

It is necessary to examine the threats, vulnerabilities, handovers, and outsourcing relationships of the new site to determine whether existing measures are applicable, rather than simply copying the original warehouse inspection sheets.

Related

Related services and enquiries

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents