ISO 28004-3-2014 pdf free download.Security management systems for the supply chain – Guidelines for the implementation of ISO 28000 – Part 3: Additional specific guidance for adopting ISO 28000 for use by medium and small businesses (other than marine ports).
This part of ISO 28004 has been developed to supplement ISO 28004-1 by providing additional guidance to medium and small businesses (other than marine ports) that wish to adopt ISO 28000. The additional guidance in this part of ISO 28004, while amplifying the general guidance provided in the main body of ISO 28004-1, does not conflict with the general guidance, nor does it amend ISO 28000.
2 Normative references
The following documents, in whole or in part, are normatively referenced in this document and are indispensable for its application. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
ISO 28000:2007, Specification for security management systems for the supply chain
ISO 28004-1:2007, Security management systems for the supply chain — Guidelines for the implementation
of ISO 28000— Part 1: General principles
3 Additional guidance
ISO 28000 Is designed to be adopted by any size organization interested in better securing their supply chain or services they provide to supply chain operators. The main body of ISO 28004 is designed to provide guidance to organizations of any size that wish to adopt ISO 28000. Because ISO 28004 is designed to provide guidance to a wide size range of organizations it may appear more complex than is needed by a smaller sized organization. The purpose of this part of ISO 28004 is to simplify the guidance for use by smaller sized organization. Entities using this part of ISO 28004 for guidance should refer to the main body of ISO 28004 when more information on specific issues is needed than is provided in this part of ISO 28004. The guidance provided in this part of ISO 28004 does not amend ISO 28000 or the main body of ISO 28004. Where specific methodologies are discussed in this part of ISO 28004 they are provided for illustrative purposes (to explain what needs to be accomplished) and other methodologies could be substituted.
Organizations adopting ISO 28000 will need to:
— specify what their objectives are in regard to providing supply chain security;
— assess the current state of supply chain security;
— develop plans that will include existing supply chain processes and procedures, and any additional processes/procedures or systems that have been identified as necessary to meet the stated supply chain security objectives;
— train personnel as to their duties and responsibilities as defined in the supply chain security plan;ISO 28004-3 pdf free download.