ISO 28001:2007
Supply Chain Security (certified via ISO 28000:2022)
Cargo, routes and logistics partners under verifiable control.
ISO 28001:2007 is a best-practice and guidance standard. The certifiable standard in this family is ISO 28000:2022 — Security and resilience. Security management systems. Requirements. Secure Trust implements the system to ISO 28000:2022 and applies ISO 28001:2007 as supply chain security assessment guidance. Every proposal states clearly which standard certification is sought against.
What it is
What the standard covers
ISO 28001 sets good practice and requirements for supply chain security: threat assessment across cargo and routes, facility access control, business partner verification, container seals and traceability, and response plans for logistics security incidents.
Who it is for
- Logistics operators and carriers
- Free zones, ports and terminals
- Importers and exporters
- Warehouses and distribution centres
Problems it helps manage
- Cargo theft, contamination or tampering
- Logistics partners without documented verification
- Weak facility access controls
- Security requirements from international clients or customs
Business benefits
- Threats assessed by route, node and cargo type
- Documented physical and personnel controls
- Traceability and business partner verification
- Stronger position with international clients and authorities
Sectors
Where it applies
Support
What the engagement includes
- Documented initial gap analysis
- Management system design
- Complete, tailored documentation
- Implementation support, on site or remote
- Training for the key team
- Internal audit and closure of findings
- Readiness and support through the certification audit
Integration with other standards
This standard commonly integrates with: ISO 9001, ISO 45001, ISO 22301. An integrated system reduces duplicated documentation and audit time.
Stages
How the project runs
Gap analysis and planning
We review the real operation, not a questionnaire. We identify gaps against the standard, critical processes, existing evidence and regulatory risk.
Selecting the standard or combination
We define which standard answers the organisation's risk and objective. The choice is technical, not a matter of popularity.
Management system design
We structure processes, responsibilities, indicators and controls according to size, sector and applicable regulation.
Documentation development
We write policy, procedures, records and matrices tailored to the operation. No generic templates.
Guided implementation
We work with each process owner until the system is used day to day, not only stored in a folder.
Team training
We train the key team on the standard, on the system and on their role during the audit.
FAQ
Frequently asked questions — ISO 28001
Does it replace trusted trader customs programmes?
Does it apply to warehousing only?
Does it include information security?
You may also need
Related standards
Quality Management System
The foundational system every other standard builds on.
View details →ISO 45001:2018Occupational Health and Safety Management System
Safety is managed before the incident, not after it.
View details →ISO 22301:2019Business Continuity Management System
What the organisation does when something stops.
View details →Next step
Every organisation is different. The right system starts with a gap analysis.
Write to us and we will arrange a strategy meeting: we review your current situation, define the right system, set scope and timelines and resolve technical and regulatory questions.
A certification done properly is not chased. It is built.
