Back to Frameworks

ISO 28000:2022

International
v2022 (second edition) with Amd 1:2024
7 domains
43 controls

ISO 28000:2022 specifies requirements for a security management system including the aspects critical to the security assurance of the supply chain, on the harmonized structure and the PDCA model: context including the supply chain's requirements, interested parties, a process for legal, regulatory and other security requirements, eight security management principles aligned with ISO 31000 (leadership, a structured process approach, customization, inclusive engagement, integration, dynamic improvement, human and cultural factors, relationship management), scope with control of externally provided processes; leadership and a security policy that allocates accountability and provides for review on merger or acquisition; planning through a proactive risk assessment of failures and malicious acts, environmental and cultural factors, security equipment, information management, threat and vulnerability information and supplier interdependencies, security objectives and planned change; support through resources, competence with security clearance, awareness, communication with sensitivity checks, and documented information whose value, integrity and access are determined; operation through operational control, identification of security processes including for the supply chain, risk assessment and treatment, controls over personnel and security equipment with pre-implementation risk review of organizational, procedural, technological and supplier changes and assurance of external suppliers, security strategies, procedures, processes and treatments selected from vulnerability and threat analysis, and security plans with a response structure, warning and communication procedures that are exercised, plan contents and recovery; performance evaluation through monitoring, risk-based internal audit that verifies the deployment of security equipment and personnel, and management review; and improvement through continual improvement and corrective action with investigation of failures, near misses and false alarms and risk review before implementation. Second edition of 2022, with Amendment 1:2024 on climate change; the security counterpart of ISO 22301 and the supply-chain security management standard behind C-TPAT, AEO and customs security programmes.

Verified

ISO 28000:2022 is a compliance framework from International with 7 domains and 43 controls. The largest domains are Clause 8: Operation – ISO 28000:2022 (12 controls), Clause 7: Support – ISO 28000:2022 (7 controls), Clause 4: Context of the organization – ISO 28000:2022 (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Clause 10: Improvement – ISO 28000:2022

2 controls
Controls in the Clause 10: Improvement – ISO 28000:2022 domain of ISO 28000:20222 controls
CodeTitle
iso-28000-2022::10.1Continual improvement
iso-28000-2022::10.2Nonconformity and corrective action

Clause 4: Context of the organization – ISO 28000:2022

6 controls
Controls in the Clause 4: Context of the organization – ISO 28000:2022 domain of ISO 28000:20226 controls
CodeTitle
iso-28000-2022::4.1Understanding the organization and its context
iso-28000-2022::4.2.1General: interested parties and their requirements
iso-28000-2022::4.2.2Legal, regulatory and other requirements
iso-28000-2022::4.2.3Principles of security management
iso-28000-2022::4.3Determining the scope of the security management system
iso-28000-2022::4.4Security management system

Clause 5: Leadership – ISO 28000:2022

4 controls
Controls in the Clause 5: Leadership – ISO 28000:2022 domain of ISO 28000:20224 controls
CodeTitle
iso-28000-2022::5.1Leadership and commitment
iso-28000-2022::5.2.1Establishing the security policy
iso-28000-2022::5.2.2Security policy requirements
iso-28000-2022::5.3Roles, responsibilities and authorities

Clause 6: Planning – ISO 28000:2022

6 controls
Controls in the Clause 6: Planning – ISO 28000:2022 domain of ISO 28000:20226 controls
CodeTitle
iso-28000-2022::6.1.1General: risks and opportunities of the management system
iso-28000-2022::6.1.2Determining security-related risks and identifying opportunities
iso-28000-2022::6.1.3Addressing security-related risks and exploiting opportunities
iso-28000-2022::6.2.1Establishing security objectives
iso-28000-2022::6.2.2Determining security objectives
iso-28000-2022::6.3Planning of changes

Clause 7: Support – ISO 28000:2022

7 controls
Controls in the Clause 7: Support – ISO 28000:2022 domain of ISO 28000:20227 controls
CodeTitle
iso-28000-2022::7.1Resources
iso-28000-2022::7.2Competence
iso-28000-2022::7.3Awareness
iso-28000-2022::7.4Communication
iso-28000-2022::7.5.1General: the documented information of the system
iso-28000-2022::7.5.2Creating and updating documented information
iso-28000-2022::7.5.3Control of documented information

Clause 8: Operation – ISO 28000:2022

12 controls
Controls in the Clause 8: Operation – ISO 28000:2022 domain of ISO 28000:202212 controls
CodeTitle
iso-28000-2022::8.1Operational planning and control
iso-28000-2022::8.2Identification of processes and activities
iso-28000-2022::8.3Risk assessment and treatment
iso-28000-2022::8.4Controls
iso-28000-2022::8.5.1Identification and selection of strategies and treatments
iso-28000-2022::8.5.2Resource requirements
iso-28000-2022::8.5.3Implementation of treatments
iso-28000-2022::8.6.1General: security plans and the response structure
iso-28000-2022::8.6.2Response structure
iso-28000-2022::8.6.3Warning and communication
iso-28000-2022::8.6.4Content of the security plans
iso-28000-2022::8.6.5Recovery

Clause 9: Performance evaluation – ISO 28000:2022

6 controls
Controls in the Clause 9: Performance evaluation – ISO 28000:2022 domain of ISO 28000:20226 controls
CodeTitle
iso-28000-2022::9.1Monitoring, measurement, analysis and evaluation
iso-28000-2022::9.2.1General: internal audits
iso-28000-2022::9.2.2Internal audit programme
iso-28000-2022::9.3.1General: management review
iso-28000-2022::9.3.2Management review inputs
iso-28000-2022::9.3.3Management review results

What is ISO 28000:2022 and who does it apply to?

ISO 28000:2022 is a compliance framework from International with 7 domains and 43 controls. ISO 28000:2022 specifies requirements for a security management system including the aspects critical to the security assurance of the supply chain, on the harmonized structure and the PDCA model: context including the supply chain's requirements, interested parties, a process for legal, regulatory and other security requirements, eight security management principles aligned with ISO 31000 (leadership, a structured process approach, customization, inclusive engagement, integration, dynamic improvement, human and cultural factors, relationship management), scope with control of externally provided processes; leadership and a security policy that allocates accountability and provides for review on merger or acquisition; planning through a proactive risk assessment of failures and malicious acts, environmental and cultural factors, security equipment, information management, threat and vulnerability information and supplier interdependencies, security objectives and planned change; support through resources, competence with security clearance, awareness, communication with sensitivity checks, and documented information whose value, integrity and access are determined; operation through operational control, identification of security processes including for the supply chain, risk assessment and treatment, controls over personnel and security equipment with pre-implementation risk review of organizational, procedural, technological and supplier changes and assurance of external suppliers, security strategies, procedures, processes and treatments selected from vulnerability and threat analysis, and security plans with a response structure, warning and communication procedures that are exercised, plan contents and recovery; performance evaluation through monitoring, risk-based internal audit that verifies the deployment of security equipment and personnel, and management review; and improvement through continual improvement and corrective action with investigation of failures, near misses and false alarms and risk review before implementation. Second edition of 2022, with Amendment 1:2024 on climate change; the security counterpart of ISO 22301 and the supply-chain security management standard behind C-TPAT, AEO and customs security programmes. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 28000:2022 actually require?

ISO 28000:2022 has 43 controls organised across 7 domains. The largest domains are Clause 8: Operation – ISO 28000:2022 (12 controls), Clause 7: Support – ISO 28000:2022 (7 controls), Clause 4: Context of the organization – ISO 28000:2022 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 28000:2022 do I already cover?

ISO 28000:2022 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO 28000:2022?

Start your ISO 28000:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 28000:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required