"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to ISO 28000
- Purpose of ISO 28000
- Supply chain security management
- Management system principles
- Key terminology
- Scope and application
- Implementation approach
Module 2: Understanding Supply Chain Security
- Supply chain environments
- Security challenges
- Supply chain dependencies
- Security vulnerabilities
- Organisational responsibilities
- Security management objectives
Module 3: ISO 28000 Management System Framework
- Management system structure
- Core requirements
- Process approach
- Risk-based thinking
- System integration
- Continual improvement
Module 4: Planning the Implementation
- Implementation objectives
- Project scope
- Implementation phases
- Roles and responsibilities
- Resource requirements
- Implementation roadmap
Module 5: Understanding Organisational Context
- Internal issues
- External issues
- Business environment
- Supply chain environment
- Strategic considerations
- Context analysis
Module 6: Interested Parties and Requirements
- Identifying interested parties
- Customer requirements
- Supplier expectations
- Regulatory considerations
- Security expectations
- Monitoring changing requirements
Module 7: Defining System Scope
- Organisational boundaries
- Supply chain activities
- Locations
- Processes
- Interfaces
- Scope documentation
Module 8: Leadership and Commitment
- Leadership responsibilities
- Management commitment
- Strategic alignment
- Resource support
- Security culture
- Management involvement
Module 9: Security Policy
- Policy objectives
- Policy development
- Organisational commitments
- Communication
- Policy implementation
- Policy review
Module 10: Roles, Responsibilities and Authorities
- Governance structure
- Security responsibilities
- Process ownership
- Decision authority
- Accountability
- Internal communication
Module 11: Security Risk Management Framework
- Risk management principles
- Risk criteria
- Risk methodology
- Risk ownership
- Risk documentation
- Risk monitoring
Module 12: Threat Identification
- Internal threats
- External threats
- Physical threats
- Operational threats
- Supply chain disruption
- Emerging threats
Module 13: Vulnerability Assessment
- Identifying vulnerabilities
- Process vulnerabilities
- Facility vulnerabilities
- Supplier vulnerabilities
- Transportation vulnerabilities
- Prioritising weaknesses
Module 14: Security Risk Assessment
- Likelihood assessment
- Impact assessment
- Risk evaluation
- Risk prioritisation
- Risk acceptance
- Risk registers
Module 15: Security Risk Treatment
- Treatment options
- Preventive controls
- Protective measures
- Mitigation strategies
- Residual risk
- Treatment monitoring
Module 16: Security Objectives and Planning
- Establishing objectives
- Measurable targets
- Responsibilities
- Resources
- Timelines
- Monitoring achievement
Module 17: Resources and Competence
- Resource planning
- Competence requirements
- Skills assessment
- Awareness
- Training needs
- Capability development
Module 18: Communication and Awareness
- Internal communication
- External communication
- Security awareness
- Communication responsibilities
- Incident communication
- Communication effectiveness
Module 19: Documented Information
- Documentation requirements
- Policies and procedures
- Operational records
- Document control
- Version management
- Record retention
Module 20: Operational Planning and Control
- Operational requirements
- Security procedures
- Control implementation
- Process controls
- Control responsibilities
- Operational monitoring
Module 21: Supplier and Third-Party Security
- Supplier risk assessment
- Security requirements
- Contractor controls
- Supplier monitoring
- Third-party dependencies
- Supplier performance
Module 22: Transportation and Cargo Security
- Transportation risks
- Cargo protection
- Vehicle security
- Route security
- Handover controls
- Transportation monitoring
Module 23: Facility and Access Security
- Facility protection
- Access controls
- Restricted areas
- Visitor management
- Asset protection
- Physical security monitoring
Module 24: Security Incident Management
- Incident identification
- Incident reporting
- Escalation procedures
- Response responsibilities
- Incident investigation
- Lessons learned
Module 25: Emergency Preparedness and Response
- Emergency scenarios
- Response procedures
- Responsibilities
- Communication arrangements
- Testing exercises
- Recovery actions
Module 26: Supply Chain Continuity and Resilience
- Critical supply chain activities
- Disruption scenarios
- Continuity strategies
- Alternative arrangements
- Recovery priorities
- Building resilience
Module 27: Performance Monitoring and Measurement
- Security KPIs
- Monitoring methods
- Performance indicators
- Data analysis
- Performance trends
- Evaluating effectiveness
Module 28: Internal Audit and Management Review
- Internal audit programme
- Audit planning
- Reviewing implementation
- Management review inputs
- Management review outputs
- Leadership oversight
Module 29: Nonconformity and Corrective Action
- Identifying nonconformities
- Immediate correction
- Root cause analysis
- Corrective action planning
- Effectiveness review
- Preventing recurrence
Module 30: Continual Improvement and System Maturity
- Improvement opportunities
- Performance evaluation
- Risk reassessment
- Control enhancement
- Organisational learning
- Sustaining system effectiveness
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device
Course Overview
This course develops the practical knowledge required to lead the implementation and ongoing management of an ISO 28000-aligned supply chain security management system. Participants explore organisational context, leadership, security risk assessment, operational controls, supplier security, incident management, resilience, performance monitoring, internal audits, management review, corrective actions, and continual improvement.