Overview
ISO 28000:2022 - Security and Resilience: Security Management Systems for the Supply Chain - specifies requirements for security management systems for organisations involved in supply chains of any type. It provides a framework for assessing security threats, implementing security controls, and maintaining records that demonstrate security management is operating effectively. ROOTKey provides the cryptographic traceability and tamper-evident record infrastructure that ISO 28000 security records require to be audit-ready.Key Requirements and ROOTKey Coverage
Clause 6 - Planning
ISO 28000 Clause 6 requires organisations to assess security risks in their supply chain operations and document the controls selected in response. ROOTKey anchors:- Security risk assessments at each review cycle - tamper-evident proof of what was assessed and when
- Security plans and control selection records - verifiable evidence of the management decisions taken
Clause 8 - Operations
Clause 9 - Performance Evaluation
ISO 28000 Clause 9 requires monitoring, measurement, analysis, and evaluation of the supply chain security management system. ROOTKey supports:- Audit records anchored at completion - verifiable evidence of audit conduct and findings
- Management review records anchored at each review - immutable minutes and action items
Clause 10 - Improvement
Multi-Party Custody Records
ISO 28000 security management covers the full supply chain - which inherently involves multiple organisations with different systems and incentives. The standard requires that security records can be traced across organisational boundaries. ROOTKey’s multi-party vault architecture addresses this directly:
→ See also: Supply Chain Traceability use case
Certification Support
ISO 28000 certification requires auditors to verify that security management records are accurate and protected from tampering. ROOTKey provides:Request a supply chain security review
We’ll design a multi-party vault architecture for your supply chain that satisfies ISO 28000 audit requirements and supports certification.
Supply chain traceability use case
Full implementation guide for ISO 28000-aligned multi-party supply chain traceability.

