Secure Trust Accounting & Finances
ES WhatsApp
28001

ISO 28001:2007

Supply Chain Security (certified via ISO 28000:2022)

Cargo, routes and logistics partners under verifiable control.

ISO 28001:2007 is a best-practice and guidance standard. The certifiable standard in this family is ISO 28000:2022 — Security and resilience. Security management systems. Requirements. Secure Trust implements the system to ISO 28000:2022 and applies ISO 28001:2007 as supply chain security assessment guidance. Every proposal states clearly which standard certification is sought against.

What it is

What the standard covers

ISO 28001 sets good practice and requirements for supply chain security: threat assessment across cargo and routes, facility access control, business partner verification, container seals and traceability, and response plans for logistics security incidents.

Who it is for

  • Logistics operators and carriers
  • Free zones, ports and terminals
  • Importers and exporters
  • Warehouses and distribution centres

Problems it helps manage

  • Cargo theft, contamination or tampering
  • Logistics partners without documented verification
  • Weak facility access controls
  • Security requirements from international clients or customs

Business benefits

  • Threats assessed by route, node and cargo type
  • Documented physical and personnel controls
  • Traceability and business partner verification
  • Stronger position with international clients and authorities

Sectors

Where it applies

Logistics and transportFree zones and portsInternational tradeExport manufacturingWarehousingCourier and last mile

Support

What the engagement includes

  • Documented initial gap analysis
  • Management system design
  • Complete, tailored documentation
  • Implementation support, on site or remote
  • Training for the key team
  • Internal audit and closure of findings
  • Readiness and support through the certification audit

Integration with other standards

This standard commonly integrates with: ISO 9001, ISO 45001, ISO 22301. An integrated system reduces duplicated documentation and audit time.

Stages

How the project runs

Gap analysis and planning

We review the real operation, not a questionnaire. We identify gaps against the standard, critical processes, existing evidence and regulatory risk.

Selecting the standard or combination

We define which standard answers the organisation's risk and objective. The choice is technical, not a matter of popularity.

Management system design

We structure processes, responsibilities, indicators and controls according to size, sector and applicable regulation.

Documentation development

We write policy, procedures, records and matrices tailored to the operation. No generic templates.

Guided implementation

We work with each process owner until the system is used day to day, not only stored in a folder.

Team training

We train the key team on the standard, on the system and on their role during the audit.

FAQ

Frequently asked questions — ISO 28001

Does it replace trusted trader customs programmes?
No. It is a supply chain security system that reinforces and evidences controls; customs programmes are handled with each authority.
Does it apply to warehousing only?
Yes. Scope is defined by node and activity within the chain.
Does it include information security?
Only in a limited way. For data and systems it is complemented by ISO/IEC 27001.

Next step

Every organisation is different. The right system starts with a gap analysis.

Write to us and we will arrange a strategy meeting: we review your current situation, define the right system, set scope and timelines and resolve technical and regulatory questions.

A certification done properly is not chased. It is built.

WhatsApp