ISO 28000 Security Management for Supply Chain Resilience Training Course
| Course code | SD-SM-007 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Supply-chain disruption is often treated as an operational problem until cargo theft, tampering, unauthorised access, supplier failure, cyber-enabled interference or weak site controls expose gaps in governance. ISO 28000 provides a management-system framework for controlling these security risks across facilities, transport routes, logistics providers and critical suppliers. This course helps practitioners turn security concerns into defined risk controls, measurable objectives, documented processes and evidence that can withstand customer, regulator and auditor scrutiny.
Participants work through the requirements of ISO 28000:2022 and apply them to a realistic supply-chain security management system (SCMS). They learn to define organisational context and interested parties; establish security leadership and policy; assess threats, vulnerabilities and consequences; select proportionate controls; manage outsourced processes; prepare incident-response arrangements; and evaluate performance through monitoring, internal audit and management review. The course also addresses the integration of security management with resilience, business continuity, health and safety, quality and environmental management arrangements.
Delivery combines instructor-led interpretation of the standard with workshops using risk registers, control plans, audit checklists and corrective-action records. Participants analyse a multi-site supply-chain case involving a high-value product route, third-party warehousing and a security incident. By the end of the week, each participant leaves with an ISO 28000 implementation action plan, a tailored security risk-treatment register and a practical outline for auditing their own SCMS.
The course is designed for professionals who already contribute to security, logistics, procurement, compliance, HSE or operational-risk decisions and now need a structured ISO 28000 method for improving supply-chain resilience.
Course objectives
By the end of this course, participants will be able to:
- Interpret ISO 28000:2022 clauses and translate them into supply-chain security management system requirements
- Define organisational context, interested parties, scope boundaries and security-management responsibilities
- Conduct a threat, vulnerability and consequence assessment using an ISO 31000-aligned risk register
- Develop risk-treatment plans linking security threats to preventive, detective and response controls
- Create measurable security objectives, KPIs and monitoring plans for routes, facilities and suppliers
- Evaluate outsourced logistics and supplier security controls through due-diligence criteria and contract requirements
- Plan ISO 28000 internal audits using process-based checklists, evidence sampling and nonconformity statements
- Produce a phased ISO 28000 implementation roadmap with ownership, milestones and management-review inputs
Benefits of attending
For you
- Gain a defensible method for converting supply-chain security concerns into ISO 28000 controls and evidence
- Build credibility when advising leaders on cargo, facility, supplier and transport security priorities
- Develop an implementation roadmap that can support ISO 28000 certification preparation or internal improvement work
- Strengthen internal-audit capability for security management systems and outsourced logistics controls
- Add practical security-resilience expertise relevant to supply chain, HSE, compliance and operational-risk career paths
For your organisation
- Establish a repeatable framework for identifying and treating security risks across the end-to-end supply chain
- Improve oversight of third-party carriers, warehouses and suppliers through defined assurance and contract controls
- Reduce inconsistent responses to theft, tampering, access breaches and other security incidents
- Create auditable evidence for customer requirements, certification projects and management-review decisions
- Link security objectives and performance indicators to resilience, continuity and operational-risk governance
Target competencies
Who should attend
- Supply Chain Security Managers — who must establish consistent controls across sites, routes and logistics partners
- Logistics and Distribution Managers — who manage transport, warehousing and cargo-handling exposure
- HSE Managers — who need to align security risk controls with existing management-system practices
- Procurement and Supplier Assurance Managers — who set security expectations for critical vendors and outsourced providers
- Business Continuity and Operational Resilience Managers — who must connect security incidents to continuity and recovery plans
- Internal Auditors and Compliance Officers — who need to assess ISO 28000 conformance and control effectiveness
Requirements and prerequisites
Participants should have working experience in supply-chain operations, logistics, physical security, procurement, HSE, business continuity, risk management or internal audit. Familiarity with basic management-system concepts such as policy, process ownership, corrective action, risk registers, KPIs and internal audits is assumed. Participants should understand how their organisation uses suppliers, carriers, warehouses or distribution routes. Prior knowledge of ISO 28000 is not required, and no formal lead-auditor qualification is needed. The course does not require coding, specialist security-system configuration or previous use of BowTieXP, although comfort working with spreadsheets and process documentation is helpful.
Training methodology
The programme uses short instructor-led sessions to interpret ISO 28000:2022, followed by facilitated application to a running supply-chain case. Participants map a security management system scope, build a threat and vulnerability register, select controls using BowTie logic, draft supplier-assurance questions and test incident-response arrangements. Small groups review simulated audit evidence and write nonconformity statements. Daily debriefs connect the case to participants' own facilities, routes and providers. The final session is an implementation-planning workshop that converts course outputs into a prioritised workplace action plan.
Course outline
Day 1: ISO 28000 foundations and SCMS scope
- ISO 28000:2022 structure, purpose and clause architecture
- Supply-chain security threats across facilities, transport and information flows
- Security management system scope and boundary definition
- Organisational context analysis using internal and external issue mapping
- Interested-party requirements and compliance obligation identification
- Leadership accountability, security policy and role assignment
- Integration points with ISO 9001, ISO 14001 and ISO 45001 systems
Workshop: Participants define the scope, interested parties and high-level process map for a fictional multi-site distribution security management system.
Day 2: Security risk assessment and control design
- ISO 31000 risk-management principles applied to supply-chain security
- Threat, vulnerability and consequence analysis
- Risk criteria, likelihood scales and consequence rating matrices
- Security risk-register design and risk-owner allocation
- Bow-tie analysis for cargo theft and tampering scenarios
- Preventive, detective, response and recovery control selection
- Residual-risk evaluation and risk-acceptance authority
Workshop: Participants complete a risk register and bow-tie analysis for a high-value shipment exposed to theft, tampering and route disruption.
Day 3: Operational controls, suppliers and incident readiness
- Operational planning and control requirements under ISO 28000
- Site access control, visitor management and asset-protection measures
- Transport-route security and chain-of-custody controls
- Supplier due diligence and outsourced-process control
- Security clauses, service levels and assurance evidence in contracts
- Incident reporting, escalation and investigation workflows
- Emergency preparedness, business continuity and recovery coordination
Workshop: Teams create a supplier-security assurance checklist and an incident-response workflow for a third-party warehouse breach.
Day 4: Performance evaluation and internal audit
- Security objectives, KPIs and operational performance measures
- Monitoring plans for losses, breaches, response times and supplier compliance
- Documented information, record retention and evidence control
- ISO 19011 audit principles and auditor conduct
- Process-based internal audit planning and sampling
- Writing objective findings, nonconformities and opportunities for improvement
- Management-review inputs, decisions and follow-up actions
Workshop: Participants review a simulated audit pack, identify evidence gaps and write ISO 28000-aligned audit findings.
Day 5: Improvement, implementation and resilience roadmap
- Nonconformity correction, root-cause analysis and corrective action
- Continual-improvement cycles for security control effectiveness
- Prioritising implementation actions using risk, effort and control maturity
- ISO 28000 implementation phases and certification-readiness considerations
- Security governance dashboards and management-review reporting
- Stakeholder communication and workforce security-awareness planning
- Personal action planning for workplace application
Workshop: Participants produce a phased ISO 28000 implementation roadmap, risk-treatment priorities and a 90-day action plan for their organisation.
Tools & standards covered
ISO 28000:2022, ISO 31000:2018, ISO 19011:2018, BowTieXP
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
21 – 25 Sep 2026Book
Kigali · USD 3,500 -
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Dubai · USD 4,500 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Mombasa · USD 3,200
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Security Management
Advanced Security Management for Enterprise Risk Leaders Training Course
Enterprise security leaders are expected to protect people, facilities, information, supply chains and business continuity while giving exec…
Security Management for Oil and Gas Facilities Training Course
Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulato…
Security Management for Corporate Security Managers Training Course
Corporate security managers are expected to protect people, sites, information and operations while justifying expenditure to senior leaders…
Security Management for Banking Branch and ATM Protection Training Course
Bank branches and ATM estates face a distinct combination of threats: armed robbery, cash-in-transit attack, ATM skimming, card trapping, ex…