ISO 28000:2022
ISO 28000:2022 specifies requirements for a security management system including the aspects critical to the security assurance of the supply chain, on the harmonized structure and the PDCA model: context including the supply chain's requirements, interested parties, a process for legal, regulatory and other security requirements, eight security management principles aligned with ISO 31000 (leadership, a structured process approach, customization, inclusive engagement, integration, dynamic improvement, human and cultural factors, relationship management), scope with control of externally provided processes; leadership and a security policy that allocates accountability and provides for review on merger or acquisition; planning through a proactive risk assessment of failures and malicious acts, environmental and cultural factors, security equipment, information management, threat and vulnerability information and supplier interdependencies, security objectives and planned change; support through resources, competence with security clearance, awareness, communication with sensitivity checks, and documented information whose value, integrity and access are determined; operation through operational control, identification of security processes including for the supply chain, risk assessment and treatment, controls over personnel and security equipment with pre-implementation risk review of organizational, procedural, technological and supplier changes and assurance of external suppliers, security strategies, procedures, processes and treatments selected from vulnerability and threat analysis, and security plans with a response structure, warning and communication procedures that are exercised, plan contents and recovery; performance evaluation through monitoring, risk-based internal audit that verifies the deployment of security equipment and personnel, and management review; and improvement through continual improvement and corrective action with investigation of failures, near misses and false alarms and risk review before implementation. Second edition of 2022, with Amendment 1:2024 on climate change; the security counterpart of ISO 22301 and the supply-chain security management standard behind C-TPAT, AEO and customs security programmes.
ISO 28000:2022 is a compliance framework from International with 7 domains and 43 controls. The largest domains are Clause 8: Operation – ISO 28000:2022 (12 controls), Clause 7: Support – ISO 28000:2022 (7 controls), Clause 4: Context of the organization – ISO 28000:2022 (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Clause 10: Improvement – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::10.1 | Continual improvement |
| iso-28000-2022::10.2 | Nonconformity and corrective action |
Clause 4: Context of the organization – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::4.1 | Understanding the organization and its context |
| iso-28000-2022::4.2.1 | General: interested parties and their requirements |
| iso-28000-2022::4.2.2 | Legal, regulatory and other requirements |
| iso-28000-2022::4.2.3 | Principles of security management |
| iso-28000-2022::4.3 | Determining the scope of the security management system |
| iso-28000-2022::4.4 | Security management system |
Clause 5: Leadership – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::5.1 | Leadership and commitment |
| iso-28000-2022::5.2.1 | Establishing the security policy |
| iso-28000-2022::5.2.2 | Security policy requirements |
| iso-28000-2022::5.3 | Roles, responsibilities and authorities |
Clause 6: Planning – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::6.1.1 | General: risks and opportunities of the management system |
| iso-28000-2022::6.1.2 | Determining security-related risks and identifying opportunities |
| iso-28000-2022::6.1.3 | Addressing security-related risks and exploiting opportunities |
| iso-28000-2022::6.2.1 | Establishing security objectives |
| iso-28000-2022::6.2.2 | Determining security objectives |
| iso-28000-2022::6.3 | Planning of changes |
Clause 7: Support – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::7.1 | Resources |
| iso-28000-2022::7.2 | Competence |
| iso-28000-2022::7.3 | Awareness |
| iso-28000-2022::7.4 | Communication |
| iso-28000-2022::7.5.1 | General: the documented information of the system |
| iso-28000-2022::7.5.2 | Creating and updating documented information |
| iso-28000-2022::7.5.3 | Control of documented information |
Clause 8: Operation – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::8.1 | Operational planning and control |
| iso-28000-2022::8.2 | Identification of processes and activities |
| iso-28000-2022::8.3 | Risk assessment and treatment |
| iso-28000-2022::8.4 | Controls |
| iso-28000-2022::8.5.1 | Identification and selection of strategies and treatments |
| iso-28000-2022::8.5.2 | Resource requirements |
| iso-28000-2022::8.5.3 | Implementation of treatments |
| iso-28000-2022::8.6.1 | General: security plans and the response structure |
| iso-28000-2022::8.6.2 | Response structure |
| iso-28000-2022::8.6.3 | Warning and communication |
| iso-28000-2022::8.6.4 | Content of the security plans |
| iso-28000-2022::8.6.5 | Recovery |
Clause 9: Performance evaluation – ISO 28000:2022
| Code | Title |
|---|---|
| iso-28000-2022::9.1 | Monitoring, measurement, analysis and evaluation |
| iso-28000-2022::9.2.1 | General: internal audits |
| iso-28000-2022::9.2.2 | Internal audit programme |
| iso-28000-2022::9.3.1 | General: management review |
| iso-28000-2022::9.3.2 | Management review inputs |
| iso-28000-2022::9.3.3 | Management review results |
What is ISO 28000:2022 and who does it apply to?
ISO 28000:2022 is a compliance framework from International with 7 domains and 43 controls. ISO 28000:2022 specifies requirements for a security management system including the aspects critical to the security assurance of the supply chain, on the harmonized structure and the PDCA model: context including the supply chain's requirements, interested parties, a process for legal, regulatory and other security requirements, eight security management principles aligned with ISO 31000 (leadership, a structured process approach, customization, inclusive engagement, integration, dynamic improvement, human and cultural factors, relationship management), scope with control of externally provided processes; leadership and a security policy that allocates accountability and provides for review on merger or acquisition; planning through a proactive risk assessment of failures and malicious acts, environmental and cultural factors, security equipment, information management, threat and vulnerability information and supplier interdependencies, security objectives and planned change; support through resources, competence with security clearance, awareness, communication with sensitivity checks, and documented information whose value, integrity and access are determined; operation through operational control, identification of security processes including for the supply chain, risk assessment and treatment, controls over personnel and security equipment with pre-implementation risk review of organizational, procedural, technological and supplier changes and assurance of external suppliers, security strategies, procedures, processes and treatments selected from vulnerability and threat analysis, and security plans with a response structure, warning and communication procedures that are exercised, plan contents and recovery; performance evaluation through monitoring, risk-based internal audit that verifies the deployment of security equipment and personnel, and management review; and improvement through continual improvement and corrective action with investigation of failures, near misses and false alarms and risk review before implementation. Second edition of 2022, with Amendment 1:2024 on climate change; the security counterpart of ISO 22301 and the supply-chain security management standard behind C-TPAT, AEO and customs security programmes. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 28000:2022 actually require?
ISO 28000:2022 has 43 controls organised across 7 domains. The largest domains are Clause 8: Operation – ISO 28000:2022 (12 controls), Clause 7: Support – ISO 28000:2022 (7 controls), Clause 4: Context of the organization – ISO 28000:2022 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 28000:2022 do I already cover?
ISO 28000:2022 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 28000:2022?
Start your ISO 28000:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 28000:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required