BS ISO 28001-2007 Security management systems for the supply chain - Best practices for implementing supply chain security assessments and plans - Requirements and guidance《供应链的安全管.pdf
《BS ISO 28001-2007 Security management systems for the supply chain - Best practices for implementing supply chain security assessments and plans - Requirements and guidance《供应链的安全管.pdf》由会员分享,可在线阅读,更多相关《BS ISO 28001-2007 Security management systems for the supply chain - Best practices for implementing supply chain security assessments and plans - Requirements and guidance《供应链的安全管.pdf(36页珍藏版)》请在麦多课文档分享上搜索。
1、BRITISH STANDARDBS ISO 28001:2007Security management systems for the supply chain Best practices for implementing supply chain security Requirements and guidanceICS 03.100.10; 47.020.99g49g50g3g38g50g51g60g44g49g42g3g58g44g55g43g50g56g55g3g37g54g44g3g51g40g53g48g44g54g54g44g50g49g3g40g59g38g40g51g55
2、g3g36g54g3g51g40g53g48g44g55g55g40g39g3g37g60g3g38g50g51g60g53g44g42g43g55g3g47g36g58BS ISO 28001:2007This British Standard was published under the authority of the Standards Policy and Strategy Committee on 30 November 2007 BSI 2007ISBN 978 0 580 58319 3National forewordThis British Standard is the
3、 UK implementation of ISO 28001:2007. It supersedes DD ISO/PAS 28001:2006 which is withdrawn.The UK participation in its preparation was entrusted to Technical Committee SME/32, Ships and marine technology Steering committee.A list of organizations represented on this committee can be obtained on re
4、quest to its secretary.This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application.Compliance with a British Standard cannot confer immunity from legal obligations.Amendments issued since publicationAmd. No. Date Comments
5、Reference numberISO 28001:2007(E)INTERNATIONAL STANDARD ISO28001First edition2007-10-15Security management systems for the supply chain Best practices for implementing supply chain security, assessments and plans Requirements and guidanceSystmes de management de la sret pour la chane dapprovisionnem
6、ent Meilleures pratiques pour la mise en application de la sret de la chane dapprovisionnement, valuations et plans Exigences et guidageBS ISO 28001:2007ii iiiContents Page Foreword iv Introduction.v 1 Scope1 2 Normative references1 3 Terms and definitions .2 4 Field of application5 4.1 Statement of
7、 application.5 4.2 Business partners .5 4.3 Internationally accepted certificates or approvals 5 4.4 Business partners exempt from security declaration requirement .6 4.5 Security reviews of business partners6 5 Supply chain security process 6 5.1 General .6 5.2 Identification of the scope of securi
8、ty assessment.6 5.3 Conduction of the security assessment .7 5.4 Development of the supply chain security plan.8 5.5 Execution of the supply chain security plan 8 5.6 Documentation and monitoring of the supply chain security process .8 5.7 Actions required after a security incident 8 5.8 Protection
9、of the security information 9 Annex A (informative) Supply chain security process10 A.1 General .10 A.2 Identification of the scope of the security assessment 10 A.3 Conduction of the security assessment .11 A.4 Development of the security plan15 A.5 Execution of the security plan .17 A.6 Documentat
10、ion and monitoring of the security process 17 A.7 Continual improvement 17 Annex B (informative) Methodology for security risk assessment and development of countermeasures.18 B.1 General .18 B.2 Step one Consideration of the security threat scenarios 20 B.3 Step two Classification of consequences .
11、22 B.4 Step three Classification of likelihood of security incidents.23 B.5 Step four Security incident scoring24 B.6 Step five Development of countermeasures .24 B.7 Step six Implementation of countermeasures 25 B.8 Step seven Evaluation of countermeasures25 B.9 Step eight Repetition of the process
12、25 B.10 Continuation of the process.25 Annex C (informative) Guidance for obtaining advice and certification.26 C.1 General .26 C.2 Demonstrating conformance with ISO 28001 by audit 26 C.3 Certification of ISO 28001 by third party certification bodies.26 Bibliography27 BS ISO 28001:2007iv Foreword I
13、SO (the International Organization for Standardization) is a worldwide federation of national standards bodies (ISO member bodies). The work of preparing International Standards is normally carried out through ISO technical committees. Each member body interested in a subject for which a technical c
14、ommittee has been established has the right to be represented on that committee. International organizations, governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of electr
15、otechnical standardization. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of technical committees is to prepare International Standards. Draft International Standards adopted by the technical committees are circulated to the m
16、ember bodies for voting. Publication as an International Standard requires approval by at least 75 % of the member bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO shall not be held responsible for identi
17、fying any or all such patent rights. ISO 28001 was prepared by Technical Committee ISO/TC 8, Ships and marine technology, in collaboration with other relevant technical committees responsible for specific nodes of the supply chain. This first edition of ISO 28001 cancels and replaces ISO/PAS 28001:2
18、006, which has been technically revised. BS ISO 28001:2007vIntroduction Security incidents against international supply chains are threats to international trade and the economic growth of trading nations. People, goods, infrastructure and equipment including means of transport need to be protected
19、against security incidents and their potentially devastating effects. Such protection benefits the economy and society as a whole. International supply chains are highly dynamic and consist of many entities and business partners. This International Standard recognizes this complexity. It has been de
20、veloped to allow an individual organization in the supply chain to apply its requirements in conformance with the organizations particular business model and its role and function in the international supply chain. This International Standard provides an option for organizations to establish and doc
21、ument reasonable levels of security within international supply chains and their components. It will enable such organizations to make better risk-based decisions concerning the security in those international supply chains. This International Standard is multimodal and is intended to be in concert
22、with and to complement the World Customs Organizations Framework of Standards to secure and facilitate global trade (Framework). It does not attempt to cover, replace or supersede individual customs agencies supply chain security programmes and their certification and validation requirements. The us
23、e of this International Standard will help an organization to establish adequate levels of security within those part(s) of an international supply chain which it controls. It is also a basis for determining or validating the level of existing security within such organizations supply chain(s) by in
24、ternal or external auditors or by those government agencies that choose to use compliance with this International Standard as the baseline for acceptance into their supply chain security programmes. Customers, business partners, government agencies and others might request organizations which claim
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSISO280012007SECURITYMANAGEMENTSYSTEMSFORTHESUPPLYCHAINBESTPRACTICESFORIMPLEMENTINGSUPPLYCHAINSECURITYASSESSMENTSANDPLANSREQUIREMENTSANDGUIDANCE

链接地址:http://www.mydoc123.com/p-586867.html