HomeCoursesSupply Chain Security › ISO 28000 Foundation
Supply Chain Security Foundation EN · ES · FR

ISO 28000 Foundation

Understand the fundamentals of supply chain security management with ISO 28000: the concepts of a security management system (SeMS), the main requirements of the standard and how it helps organisations manage security risks across the supply chain.

2 daysof training
Foundationentry level
EN · ES · FRlanguages
OfficialPECB exam incl.

Who is this course for?

  • Professionals starting out in supply chain security
  • Security, logistics and operations staff
  • Consultants and managers introducing a SeMS
  • Those preparing for the ISO 28000 Lead Implementer or Lead Auditor level

What you'll gain

  • The PECB Certified ISO 28000 Foundation credential
  • An understanding of SeMS concepts and ISO 28000 requirements
  • Knowledge of supply chain security risk management
  • A solid base to progress towards the Lead levels

Course programme

Day 1 · Introduction to ISO 28000 and SeMS concepts
  • Supply chain security concepts and threats
  • The ISO 28000 framework and benefits
  • Roles and responsibilities in a SeMS
Day 2 · ISO 28000 requirements and exam
  • Key requirements of ISO 28000
  • Security risk management in the supply chain
  • Review and official Foundation exam

Exam, credits & certification

1 h
Duration of the official PECB exam
14 CPD
Continuing Professional Development credits awarded by the course
Included
Exam, marking and first issue of the certification, included in the price

After passing the exam, you can apply for the "PECB Certified ISO 28000 Foundation" credential. The exam includes 2 attempts: the first plus a free retake, usable within the following 12 months. Passing first time is no longer a source of pressure. CPD credits correspond to the level of the course according to PECB. Exam duration is indicative; ask me for the exact details when you enrol.

Who oversees your certification

Ricardo Coronel Lemus, PECB trainer

Ricardo Coronel Lemus

Practising GRC / vCISO consultant · PECB Certified Trainer (CT6496)

More than 20 years in cybersecurity and compliance, today a vCISO and GRC consultant with real clients in France, Spain and Mexico. As the head of RRSG, I oversee every enrolment, guide you through your certification path and coordinate your coaching with a subject-matter expert.

ISO 27001 Lead Auditor / Lead Implementer CISSPCISMCRISCCCISODORA Lead ManagerPCI DSS - PCIP

Not ready to decide? Get all the information by email

I will send you the full syllabus, available dates and the price of ISO 28000 Foundation, with no obligation.

Frequently asked questions

Do I need any prerequisites?
No formal prerequisites are required to take the course. Prior background in the field helps, but is not mandatory.
What language is the exam in?
The material is available in the languages shown and you choose yours when you pay. The exam is offered in several languages and you choose yours when you request it, separately. Coaching is delivered in English to prepare you thoroughly. If you need a specific language, contact us and we will confirm it.
What is the difference between Self-Study and Self-Study + Coaching?
Self-Study includes the official PECB material, the exam and certification, at your own pace. The coaching option adds one-to-one sessions with a subject-matter expert selected by RRSG: real-world case studies and guided exam preparation; they support you until you feel ready to get certified. Ricardo coordinates your coaching and guides you throughout the certification path.See the full coaching programme. The coaching option includes up to 3 hours of one-to-one video sessions, spread at your own pace over the 12 months of access. See the full coaching programme.
What if I don't pass the exam?
The PECB exam includes 2 attempts: the first plus a free retake usable within the following 12 months. So a failure doesn't leave you stranded. What's more, with the coaching option we prepare for the exam together with mock exams so that you arrive confident.
Is ISO 28000 relevant to supply chain resilience and regulations?
Yes. ISO 28000 provides a recognised framework to manage security risks across the supply chain, increasingly relevant to resilience expectations and to regulations addressing supply chain and third-party security.

Ready to get started with supply chain security?

Choose your option above and enrol online. A question or need some advice? Write to me or book a call.