ISO 28000 2007 SUPPLY CHAIN
SECURITY MANAGEMENT SYSTEM DEVELOPMENT PLAN |

|
The following material presents a brief Supply
Chain Security Management
System (SCSMS) Development Plan. It
summarizes the general approach
you would take to develop your own
SCSMS. It uses a PDCA approach
and is taken directly from our
plain English version of the standard. If you
use our Plain English
ISO 28000 Standard to develop your organization’s
SCSMS,
you will automatically
take the following steps:
- Define the scope of your organization’s
SCSMS.
- Define your organization’s security
management policy.
- Develop a methodology to identify threats
and assess risks.
- Establish procedures to identify threats
and assess risks.
- Identify your organization’s threats and
assess your risks.
- Establish procedures to identify and
select security controls.
- Select and implement your security control
measures.
- Respect legal, statutory, and regulatory
requirements.
- Establish your organization’s security
objectives.
- Establish your organization’s security
targets.
- Establish programs to achieve objectives
and targets.
- Establish security management roles and
responsibilities.
- Appoint a member of top management to
manage security.
- Ensure the competence of those who
influence security.
- Establish security training and awareness
procedures.
- Implement security training and awareness
procedures.
- Establish procedures to manage security
communications.
- Establish a security management
documentation system.
- Control your organization’s security
documents and data.
- Implement operational security control
measures.
- Establish emergency SCSMS plans and
procedures.
- Monitor and measure your security
performance.
- Maintain a record of monitoring and
measuring activities.
- Evaluate your SCSMS plans, procedures, and
capabilities.
- Investigate security incidents and take
remedial action.
- Control your organization’s security
management records.
- Perform regular audits of your
organization’s SCSMS.
- Review your SCSMS at planned intervals.
- Update and improve your SCSMS.
|
Legal
Restrictions on the Use of this Page
Thank
you for visiting this page. You are, of course, welcome to view our
material as often as you wish, free of charge. And as long as you
keep intact
all copyright notices, you are also welcome to print or make one
copy of this
page for your own personal, noncommercial, home use. But, you are not
legally authorized to print or produce additional copies or to
copy and paste
any of our material onto another web site or to republish it in
any way.
Copyright © 2009 - 2012 by Praxiom Research Group Limited.
All Rights Reserved.
