Skedmia
ISO 28000

Introduction to ISO 28000:2022 — Supply Chain Security Management System (SeMS)

A foundation course in ISO 28000:2022: what a security management system is for, what each clause requires, and how to assess supply chain security risk and build proportionate controls that hold up in practice.

23

Lessons

~10h

Study time

30

Exam questions

Earns a QR-verifiable Certificate of Training

Overview

About this course

ISO 28000:2022 is the second edition of the international standard for security management systems, replacing ISO 28000:2007. The revision moved the standard onto the ISO harmonized structure, aligning it clause for clause with ISO 9001, ISO 14001, ISO 45001 and ISO 22301, and broadened its field of application beyond transport and logistics to any organisation that must manage security risk in its supply chain.

This foundation course teaches the standard itself, working through Clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement — with every requirement illustrated in supply chain terms. Alongside the clauses you study the threat categories a security manager actually faces (cargo crime, smuggling and stowaways, counterfeiting and diversion, sabotage, cyber-physical attack on logistics systems, insider collusion) and the controls that answer them across the facility, personnel, information, documentation and in-transit domains, including supplier and subcontractor security requirements.

It is written for logistics, procurement, security and resilience staff, and for management-system practitioners in shipping, ports, warehousing, freight forwarding and manufacturing. Afterwards you can explain each clause, run a defensible security risk assessment, design proportionate controls and set up the monitoring a certifiable SeMS needs. Relationships to ISO 28001, ISO 22301, the ISPS Code and the AEO and C-TPAT customs-security programmes are covered throughout.

Assessment is a 30-question online exam with a 70% pass mark, and successful learners receive a verifiable certificate. Around 10 hours of self-paced study. This is a foundation course, not auditor training.

CertificateOF TRAINING

What you earn

A certificate anyone can verify in seconds

Score 70% or better on the final exam and Skedmia issues your Certificate of Training with a unique certificate number. Every certificate carries a QR code that resolves to our public register, so an employer or auditor can confirm it is genuine without contacting anyone.

Verified at skedmia.com/verify

Syllabus

Course content

8 modules · 23 lessons · ~10h

01Module 1 — ISO 28000:2022 in Context — Purpose, History and Field of Application3 lessons
  • What ISO 28000:2022 Is and What a Security Management System DoesPreview30 min
  • From ISO 28000:2007 to the Second Edition — What Changed and Why30 min
  • Who Uses ISO 28000 — Sectors, Scope Boundaries and Neighbouring Frameworks25 min
02Module 2 — Context, Leadership and Support — Clauses 4, 5 and 73 lessons
  • Understanding the Organisation and Defining the SeMS Scope — Clause 430 min
  • Leadership, Security Policy and Organisational Roles — Clause 525 min
  • Support — Resources, Competence, Awareness, Communication and Documented Information — Clause 730 min
03Module 3 — Planning — Security Risk Assessment, Treatment and Objectives (Clause 6)3 lessons
  • The Supply Chain Threat Landscape — Categories of Security Threat30 min
  • Security Risk Assessment — Clause 6.1 in Practice35 min
  • Risk Treatment, Security Objectives and Planning of Changes — Clauses 6.1 to 6.330 min
04Module 4 — Operation I — Security Strategy, Facility and Personnel Controls (Clause 8)3 lessons
  • Operational Planning and Control — Security Strategy, Procedures and the Security Plan30 min
  • Facility and Physical Security Controls30 min
  • Personnel Security — Screening, Insider Threat and the Employment Lifecycle30 min
05Module 5 — Operation II — Information, In-Transit and Supply Chain Partner Security (Clause 8)3 lessons
  • Information, Cyber-Physical and Documentation Security30 min
  • In-Transit Security — Conveyances, Cargo and Journey Management30 min
  • Suppliers, Subcontractors and Customs-Security Programmes30 min
06Module 6 — Response, Performance Evaluation and Improvement — Clauses 8 to 103 lessons
  • Security Incident Management, Continuity and Recovery30 min
  • Performance Evaluation — Monitoring, Measurement, Internal Audit and Management Review — Clause 925 min
  • Improvement — Nonconformity, Corrective Action and Continual Improvement — Clause 1025 min
07Module 7 — Implementing a SeMS — Getting Started, Pitfalls and the First 90 Days3 lessons
  • Getting Started — Gap Analysis and the Implementation Roadmap25 min
  • Common Pitfalls — Where SeMS Implementations Go Wrong25 min
  • The First 90 Days — A Practical Implementation Path25 min
08Course materials & downloads2 lessons
  • ISO 28000:2022 Clause-by-Clause SeMS Readiness Checklist (PDF)
  • Supply Chain Security Risk Assessment and Treatment Register (Template) (PDF)
Final Exam30 questions · pass 70% → certificate