Awareness Training Program on Information Security

ISO 28000

This two-day course consists of two stages. The first and second day are applicable to all participants and will cover general topics including risks to the supply chain from terrorism, International Standards and current regulations in the US & the EU.

What is the ISO 28000 standard?

ISO 28000 is a standard which specifies requirements for security including those aspects critical to the supply chain. These aspects include, but are not limited to, financing, manufacturing, information management, and the facilities for packing, storing, and the transfer of goods between modes of transport and locations. This specification was published by The International Standards Organisation in 2005. ISO 28000 is applicable to all sizes of organisations, from small to multinational, in manufacturing, services, storage or transportation that wishes to establish, implement, maintain and improve a security management system (at any stage of the production or supply chain).

With billions of dollars worth of goods moving at any given time along global supply chains, the newly published ISO 28000 for security management systems will help combat threats to the safe and smooth flow of international trade. The ISO 28000 framework helps organisations to comply with specific requirements like CT-PAT (US Customs), World Customs Organisation (WCO) and European Union requirements pertaining to the security of supply chains.

Course Benefit
The first two days of this course help the participants to understand how to implement a systematic framework for security management in which organisations drive continual improvement, using a risk based approach.

Course Content:

There are approximately four hours of preparation aimed at creating awareness of potential security threat scenarios within the supply chain. The three day course shall cover:


Day 1

• Introduction
• Background and history of supply chain security
• C-TPAT requirements
• WCO requirements
• EU requirements and ISO 28000
• Group work
• Supply chain security threats
• Supply chain security risks

Day 2

• Threats and risks; how to mitigate them
• Group work: Mitigation risk for large and small companies
• Security assessment and security plan
• Detection techniques, monitoring and preventive techniques
• Incident response and recovery planning

Pre Requisite For Participants:

No specific education or practical experience is required. However, previous exposure to any management system such as ISO 9001 or ISO 14001 will be an advantage for the first and second day. During the third day, the course shall cover only the specific requirements for auditing against ISO 28000, hence previous experience in auditing (either internal or external) any management systems is essential.


A certificate of completion will be issued to successful participants based on performance during the course as well as the examination which will be conducted on the final day of the course.








