Skip to main content

Overview

ISO 28000:2022 - Security and Resilience: Security Management Systems for the Supply Chain - specifies requirements for security management systems for organisations involved in supply chains of any type. It provides a framework for assessing security threats, implementing security controls, and maintaining records that demonstrate security management is operating effectively. ROOTKey provides the cryptographic traceability and tamper-evident record infrastructure that ISO 28000 security records require to be audit-ready.

Key Requirements and ROOTKey Coverage

Clause 6 - Planning

ISO 28000 Clause 6 requires organisations to assess security risks in their supply chain operations and document the controls selected in response. ROOTKey anchors:
  • Security risk assessments at each review cycle - tamper-evident proof of what was assessed and when
  • Security plans and control selection records - verifiable evidence of the management decisions taken

Clause 8 - Operations

Clause 9 - Performance Evaluation

ISO 28000 Clause 9 requires monitoring, measurement, analysis, and evaluation of the supply chain security management system. ROOTKey supports:
  • Audit records anchored at completion - verifiable evidence of audit conduct and findings
  • Management review records anchored at each review - immutable minutes and action items

Clause 10 - Improvement


Multi-Party Custody Records

ISO 28000 security management covers the full supply chain - which inherently involves multiple organisations with different systems and incentives. The standard requires that security records can be traced across organisational boundaries. ROOTKey’s multi-party vault architecture addresses this directly: → See also: Supply Chain Traceability use case

Certification Support

ISO 28000 certification requires auditors to verify that security management records are accurate and protected from tampering. ROOTKey provides:

Request a supply chain security review

We’ll design a multi-party vault architecture for your supply chain that satisfies ISO 28000 audit requirements and supports certification.

Supply chain traceability use case

Full implementation guide for ISO 28000-aligned multi-party supply chain traceability.