ISO 28000 Foundation Training Course for Supply Chain Security

Provided by: Professional Evaluation and Certification Board (PECB)
ISO 28000 Foundation Training Course for Supply Chain Security

Course Overview:

The ISO 28000 Foundation course provides participants with a structured introduction to security management systems and supply chain security principles. It explains how organizations can identify, assess, control, and monitor security risks affecting logistics operations, transportation networks, cargo movements, facilities, personnel, information, suppliers, and outsourced services.

This ISO 28000 Foundation Training introduces the core requirements of a security management system, including organizational context, leadership, security policy, risk-based planning, operational controls, performance evaluation, and continual improvement. Participants explore how security risks can emerge from physical failures, criminal activity, unauthorized access, operational weaknesses, natural events, external service disruptions, information compromise, and continuity threats.

The ISO 28000 Foundation Course also demonstrates how organizations can align security processes across upstream and downstream supply chain activities. Participants learn how to understand stakeholder expectations, identify applicable obligations, establish security objectives, assign responsibilities, document key processes, and develop suitable security treatments.

Through practical workplace examples, the course connects ISO 28000 Supply Chain Security with logistics security management, transportation security, cargo security management, supply chain threat assessment, and organizational resilience. It is designed to provide foundational knowledge for professionals who support security management activities or contribute to security management system implementation projects.

 

Target Audience:

  • Security managers, supervisors, and coordinators
  • Supply chain and logistics professionals
  • Transportation and distribution managers
  • Warehouse and cargo operations supervisors
  • Procurement and supplier management professionals
  • Risk management and business continuity personnel
  • Compliance and governance professionals
  • Quality and integrated management system coordinators
  • Operations managers and process owners
  • Internal control professionals
  • Consultants seeking foundational ISO 28000 knowledge
  • Employees supporting security management activities
  • Professionals pursuing a career in supply chain security

 

Targeted Organizational Departments:

  • Corporate Security and Protective Services
  • Supply Chain and Logistics
  • Transportation and Fleet Operations
  • Warehousing and Distribution
  • Cargo Handling and Terminal Operations
  • Procurement and Supplier Management
  • Enterprise Risk Management
  • Business Continuity and Organizational Resilience
  • Compliance and Regulatory Affairs
  • Quality and Integrated Management Systems
  • Health, Safety, Security, and Environment
  • Internal Audit and Governance
  • Information Security and Data Management
  • Facilities and Asset Management
  • Emergency Response and Crisis Management

 

Targeted Industries:

  • Logistics, freight forwarding, and distribution
  • Maritime shipping, ports, and terminal operations
  • Aviation, airports, and air cargo
  • Road transportation and fleet management
  • Rail transport and multimodal logistics
  • Manufacturing and industrial production
  • Warehousing and fulfilment centres
  • Oil, gas, petrochemical, and energy
  • Construction and engineering supply chains
  • Retail, wholesale, and e-commerce
  • Customs brokerage and international trade
  • Government and public-sector organizations
  • Defence and critical infrastructure
  • Pharmaceuticals and healthcare supply chains
  • Food, agriculture, and cold-chain logistics
  • Telecommunications and technology
  • Banking, insurance, and high-value asset transportation
  • Humanitarian and emergency supply chains

 

Course Offerings:

By the end of this course, participants will be able to:

  • Explain the purpose, scope, terminology, and structure of ISO 28000.
  • Describe the principles of security management systems.
  • Understand the Plan-Do-Check-Act approach to security management.
  • Identify internal and external issues affecting organizational security.
  • Determine relevant interested parties and their security expectations.
  • Explain how legal, regulatory, contractual, and voluntary requirements affect security controls.
  • Understand how to define the scope of a security management system.
  • Explain leadership responsibilities, security policy requirements, and organizational accountabilities.
  • Identify security-related threats, risks, vulnerabilities, dependencies, and opportunities.
  • Apply basic ISO 28000 Risk Assessment concepts to supply chain scenarios.
  • Distinguish between risk identification, analysis, evaluation, and treatment.
  • Explain security objectives, operational criteria, controls, and security plans.
  • Recognize competence, awareness, communication, and documented information requirements.
  • Understand operational planning for logistics, transportation, warehousing, and cargo security.
  • Explain monitoring, measurement, internal audit, management review, corrective action, and continual improvement.
  • Contribute effectively to a Security Management System Implementation project.

 

Training Methodology:

The ISO 28000 Foundation Training Course uses an interactive, workplace-focused methodology that converts security management requirements into clear and practical applications. Instructor-led presentations explain the main concepts, terminology, and requirements, while facilitated discussions connect them to logistics, transportation, warehousing, manufacturing, cargo handling, supplier management, and corporate security operations.

Participants examine realistic case studies involving theft, cargo tampering, unauthorized access, information compromise, supplier disruption, infrastructure failure, severe weather, operational interruption, and security incidents. These activities help participants understand how ISO 28000 Risk Assessment considers threats, vulnerabilities, likelihood, consequences, existing controls, and treatment priorities.

Group exercises are used to identify interested parties, map supply chain dependencies, define system boundaries, classify security risks, and evaluate potential controls. Clause-mapping activities connect organizational context, leadership, planning, support, operations, performance evaluation, and continual improvement.

Scenario-based workshops address Logistics Security Management, Transportation Security Training, Cargo Security Management, Global Supply Chain Security, and Supply Chain Resilience Training. Daily review sessions reinforce key concepts, clarify misunderstandings, and help participants relate the course to their responsibilities. Examples of relevant templates, registers, checklists, and planning approaches are demonstrated for instructional purposes, but operational tools and commercial systems are not provided.

 

Course Toolbox:

The course provides insights and instructional examples related to:

  • Security management terminology
  • Plan-Do-Check-Act process mapping
  • Organizational context analysis
  • Interested-party identification
  • Security management system scope definition
  • Legal and regulatory requirements mapping
  • Supply chain process mapping
  • Dependency and interdependency analysis
  • Supply Chain Threat Assessment
  • Threat and vulnerability identification
  • Security Risk Assessment
  • Risk classification and prioritization
  • Security risk treatment planning
  • Security objectives and performance indicators
  • Roles, responsibilities, and authority mapping
  • Competence and awareness planning
  • Security communication planning
  • Documented information control
  • Operational security control selection
  • Supplier and outsourced-process security review
  • Cargo and transportation security scenarios
  • Security incident response planning
  • Warning and communication arrangements
  • Recovery and resilience planning
  • Security performance monitoring
  • Internal audit preparation
  • Management review planning
  • Nonconformity and corrective action

These are presented as insights and examples of tools relevant to the course. Operational software, proprietary systems, and ready-made organizational tools are not provided.

 

Course Agenda:

Day 1: ISO 28000 Fundamentals and Security Management Context

  • Topic 1: Purpose, Scope, and Application of ISO 28000
  • Topic 2: Security Management Concepts, Principles, and Terminology
  • Topic 3: Supply Chain Security, Dependencies, and Interdependencies
  • Topic 4: The Plan-Do-Check-Act Security Management Model
  • Topic 5: Understanding Organizational Context and Security Conditions
  • Topic 6: Interested Parties, Requirements, and System Scope
  • Reflection & Review: Reviewing how organizational context and stakeholder expectations shape an ISO 28000 Security Management System.

 

Day 2: Leadership, Security Policy, and Risk-Based Planning

  • Topic 1: Leadership Commitment and Security Governance
  • Topic 2: Developing and Maintaining the Security Policy
  • Topic 3: Security Roles, Responsibilities, and Authorities
  • Topic 4: Identifying Security Threats, Risks, and Opportunities
  • Topic 5: Assessing Likelihood, Consequences, and Vulnerabilities
  • Topic 6: Security Objectives, Action Plans, and Planned Changes
  • Reflection & Review: Connecting leadership, security policy, ISO 28000 Risk Assessment, and measurable security objectives.

 

Day 3: Support, Competence, Communication, and Documentation

  • Topic 1: Resources Required for Security Management
  • Topic 2: Competence Requirements for Security-Critical Roles
  • Topic 3: Employee and Contractor Security Awareness
  • Topic 4: Internal and External Security Communication
  • Topic 5: Creating and Updating Documented Information
  • Topic 6: Controlling Security Documents, Records, and Data
  • Reflection & Review: Evaluating how resources, competence, communication, and controlled information support effective security operations.

 

Day 4: Operational Security Controls and Security Plans

  • Topic 1: Operational Planning and Control Requirements
  • Topic 2: Mapping Security-Critical Processes and Activities
  • Topic 3: Risk Assessment, Treatment, and Control Selection
  • Topic 4: Logistics, Transportation, and Cargo Security Controls
  • Topic 5: Security Strategies, Procedures, and Treatment Plans
  • Topic 6: Response, Warning, Communication, and Recovery Planning
  • Reflection & Review: Applying ISO 28000 Requirements and Controls to realistic supply chain security and disruption scenarios.

 

Day 5: Performance Evaluation and Continual Improvement

  • Topic 1: Security Performance Monitoring and Measurement
  • Topic 2: Analysis, Evaluation, and Security Performance Indicators
  • Topic 3: Internal Audit Principles and Programme Requirements
  • Topic 4: Management Review Inputs, Decisions, and Follow-Up
  • Topic 5: Managing Nonconformities and Corrective Actions
  • Topic 6: Continual Improvement and Implementation Readiness
  • Reflection & Review: Consolidating the main ISO 28000 requirements and identifying how participants can support implementation activities.

 

FAQ:

What specific qualifications or prerequisites are needed for participants before enrolling in the course?

No formal qualifications, previous ISO experience, or security management certification is required. The course is designed for participants seeking foundational knowledge of ISO 28000 and security management systems. Familiarity with logistics, supply chain operations, transportation, compliance, risk management, or organizational security may be helpful but is not mandatory.

 

How long is each day's session, and is there a total number of hours required for the entire course?

Each day's session is generally structured to last around 4–5 hours, with breaks and interactive activities included. The total course duration spans five days, approximately 20–25 hours of instruction.

 

Is ISO 28000 limited only to logistics and transportation companies?

No. Although the standard has strong relevance to supply chain, logistics, transportation, cargo, and warehousing activities, it can be applied by organizations of different sizes and sectors. Any organization seeking a structured approach to security risk management, operational security, resilience, and continual improvement can benefit from its principles.

 

How This Course is Different from Other ISO 28000 Foundation Courses:

This ISO 28000 Foundation Course moves beyond a basic explanation of requirements by connecting security management principles with practical workplace conditions. Instead of presenting the standard as a series of isolated clauses, the course shows how context, leadership, risk assessment, resources, operational controls, monitoring, and improvement work together as one integrated security management system.

Participants examine realistic challenges involving cargo theft, tampering, supplier dependence, outsourced services, unauthorized access, information compromise, infrastructure disruption, emergency response, and operational recovery. This practical focus makes the course especially relevant to professionals in security, logistics, transportation, compliance, risk, procurement, and operations.

The course also emphasizes the relationship between Supply Chain Threat Assessment, risk treatment, security objectives, competence, documentation, performance indicators, and corrective action. Participants therefore gain a clearer understanding of how risks influence management decisions and operational controls.

Unlike advanced implementation or auditor programmes, this course remains appropriately foundation-level. It develops the knowledge required to understand ISO 28000 Requirements, communicate with implementation teams, support relevant organizational activities, and contribute to security management projects without suggesting that participants will independently implement or audit a complete system after completing the course.

credits: 5 credit per day

Course Mode: full-time

Provider: Agile Leaders Training Center

No Events Currently Scheduled

This course is available on demand. Contact us to arrange training dates that suit your schedule.

Contact Us
footer.svg