39% of ISO 28001:2007 Supply Chain Security Management you already have
ISO 22000 already covers about 39% of ISO 28001:2007 Supply Chain Security Management, leaving
22 of 36 controls as genuinely new work.
Already covered 0
Likely covered 14
New work 22
No control in ISO 22000
maps directly to one in ISO 28001:2007 Supply Chain Security Management. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 22000 reaches these. This is the list to scope.
ISO28001-4.1Supply chain security context
ISO28001-4.10Operational control
ISO28001-4.12Performance monitoring and measurement
ISO28001-4.13Evaluation of compliance
ISO28001-4.14Related security incident investigation
ISO28001-4.16Control of records
ISO28001-4.2Security management policy
ISO28001-4.3Security risk assessment
ISO28001-4.4Security objectives and targets
ISO28001-4.5Security plan
ISO28001-4.6Resources, roles, responsibility
ISO28001-4.7Competence and training
ISO28001-4.9Documentation control
ISO28001-A.5Cargo integrity and conveyance security
ISO28001-A.6Personnel security and access
ISO28001-A.7Information and IT security
ISO28001-A.8Business partner and AEO compatibility
ISO28001-A.9Physical security of facilities
ISO28001-PC-01Customs and Trade Compliance
ISO28001-PI-04Business Partner Security Requirements
ISO28001-PS-03Cargo Security
ISO28001-PS-04Key and Seal Management
Show the 14 you already have
ISO28001-4.11Emergency preparedness and response
ISO28001-4.15Nonconformity, corrective and preventive action
ISO28001-4.17Internal audit
ISO28001-4.18Management review
ISO28001-4.8Communication and consultation
ISO28001-PC-02Manifest and Documentation Procedures
ISO28001-PC-03Supply Chain Incident Reporting
ISO28001-PC-04Supply Chain Continuity Planning
ISO28001-PI-01Personnel Security Screening
ISO28001-PI-02Security Awareness and Training
ISO28001-PI-03Information Security in Supply Chain
ISO28001-PS-01Facility Security
ISO28001-PS-02Conveyance Security
ISO28001-SA-04Security Risk Treatment Planning
How this is calculated
Already covered means a mapping runs from a control in ISO 22000 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition