Over 25 years of Client Success

Over 25 years of Client Success
QMII WEBSITE
Showing posts with label C-TPAT. Show all posts
Showing posts with label C-TPAT. Show all posts

Wednesday, February 12, 2014

The benefits of ISO 28000

ISO 28000:2007 was developed such that organizations of varying scale could apply the standard to supply chains of various degrees of complexity. ISO 28000 sets requirements for Security of the Supply Chain to enable an organization to establish, implement, operate, monitor, review, maintain and improve a documented management system within the context of the organization’s overall security risks.

The general rational for organizations to adopt ISO 28000 pertains to:
  • developing a security management system,
  • internal compliance with objectives of a security management policy,
  • external compliance with best practice benchmarks,
  • Recognition through accreditation.
  • Best practices in deployment of resources to mitigate security risks
Organization given the responsibility of ensuring the security of the supply lanes of their country and its associated ports are required by International Regulations to audit each of their ports on a periodic basis. Specific skills required for this auditing process must be provided to an adequate number of members of the organization in order to ensure the safety and security of the country’s Ports is maintained at the optimum levels at all times. As such they should have an adequate number of personnel trained and ready to meet this requirement.

Subject matter expertise in supply chain security is an essential part of keeping the homeland secure. The ISPS (International Ship & Port Security Code) only enables protection of the maritime assets (the ships and the ports). Upstream and downstream of the ports and ships remains a grey area. It is from here that the genesis of breaches in security takes place. It is therefore essential that the organization consider the risks and potential dangers by considering the security management of the supply chain in its entirety and beyond the maritime assets.

Going further and widening the sphere of responsibility for organization the following too needs to be considered by the TM (Top Management). ISO 9001:2008 provides the framework for ensuring efficiency and equates to the ISM (International Safety Management Code) in maritime terms. The ISO 9001 however does not cover the by-products of the processes and the pollution as also the dangers to the environment. Internally ISO 14001:2004 provides this guideline which in our maritime world is enforced based on MARPOL. 

Taking this further with the global security situation being as it is, the protection givers have to be prepared, aware and have all the tools they require. ISO 28000 provides this essential security management tool. The US initiative on C-TPAT is based on ISO 28000. Some 10,600 companies are compliant with C-TPAT. ISO 28000 is fast becoming the basis for managing security of the global supply chain.

Thursday, April 18, 2013

Security and Training – Intrinsically connected


A Process-Based approach to security based on training

One could conclude that the process-based approach where implemented correctly should ensure efficiency and lead to ‘cash in the bank’*. The ‘people>processes>system approach’ *  based on the international standard ISO 9001has been well tried, as the global economy has come closer necessitating standardization of procedures to ensure systems don’t conflict and adversely affect efficiency. Economy today is globally dependent and the process approach brings a system approach to it. Using the approach, one would think organizations would ensure continual improvement, innovate and grow the organization. The process approach as envisaged in the ISO 9001 however leaves out the risk aspects, pollution and the by-products of a process! To stay in business therefore the organizations implement the global standard ISO 14001 encompassing the Environmental Management System (EMS) requirements in addition to the Quality Management System requirements (QMS).

Consequent to the tragedy of 9/11, the post 2001 scenario underwent a negative sea change. Lack of security could wipe away the business totally! It is not that security was not a concern pre-2001; however, the vulnerability of the very symbols of American economic power changed the international equations, which adversely affected the business continuity. If the only superpower on earth was vulnerable and unable to protect its economic center from terrorists then it required a drastic change in the priorities of the business if they were to remain viable. It changed the priorities of the government’s worldwide. For a business to remain sustainable, ensure continuity it was not just essential to be process based and ensure pollution control, environmental protection, be risk based and catering to the by-products, but also of the utmost importance to ensure security of the business. Security became a prime concern. All investment in business can be lost in a moment if a security breach takes place.

The maritime industry is intrinsically involved with the world economy, in that more than 90% of world trade is by vessels trading the globe. The maritime world had its process approach to safety and pollution prevention covered by the SOLAS convention published and implemented as the mandatory ISM Code. Pollution aspects of vessels are specifically addressed by the MARPOL convention. The security uncertainty post 9/11, quickly lead to the implementation of the mandatory ISPSCode for all internationally trading vessels and for the ports where these vessels came in. With the implementation of the ISPS Code, the maritime assets are protected.

The global supply chain is however, not limited to the maritime assets! The concept of maritime asset protection needed to be broadened, as the assets were vulnerable to breach both ‘up-stream’ and ‘down-stream’ of the ISPS Code. Breach of security anywhere in the global supply chain could have catastrophic consequences on the global economy. The introduction of the global standard ISO 28000 filled this vacuum and provided the requirements for implementing procedures to create a system to protect the global supply chain.

Ninety percent of the US homeland imports come in by sea. Inspecting such a large quantity has colossal challenges. Only about 3 to 5% of the containers coming, for example are inspected! It is a daunting task for the USCG and CBP. The CBP initiative in terms of C-TPAT relies on partnership with the industry and encourages those trading with the US to make their security systems compliant with these requirements. It is essentially a process-based approach to security aligned and based on the ISO 28000.

Just the planning and implementation of the security requirements is not sufficient. Individual responsibility is integral to security and when combined with the system approach can pay dividends. All the standards be it ISO 9001, ISO 14001 or ISO 28000 or as applicable in the maritime world: ISM Code, ISPS Code or the MARPOL convention, each requires a system approach. It is vital to the success of this approach that the top managements (TM) are conscious of their responsibilities. Other stakeholders, be they owners, operators, auditors, statutory or regulatory bodies, flag State Administrations do their bit, but TM remains totally responsible for security.

This alignment of TM responsibility being paramount has another variance in the security scenario. I think this vital difference needs recognition by all parties involved in the security of the global supply chain. The major difference is epitomized (particularly for the maritime industry) in Clause A/ 19.1.3 of the ISPS Code. The clause is often considered just advisory in the verification process. However, the sting in the clause is applicable to the entire body of security. The clause virtually requires the Flag State to 'guarantee' full proof security following verification by the Administration! No other international or maritime standard requires this assurance from a regulator. All security related industries, not just the maritime industry (who in any case have no choice!) must take cue from this clause as it leads to a fresh interpretation of security responsibilities for all stakeholders in the global (particularly maritime) supply chain. The auditors, inspectors, the involved organization, regulators et al take due responsibility for the security.  To broaden the implications of the thought behind the clause each entity looking at the security aspect must be fully satisfied and guarantee 100% security. No deficiencies/ NCs (Non-Conformities) are acceptable. Howsoever minor the NC it must be addressed promptly. The strength of the global supply chain is defined by the weakest link in it, and as such, the deficiencies need to be completed before any verification certificate is given.

The challenge and requirements are then clear. The question is how is this to be ensured? Perhaps by getting the best available equipment? Hiring top-notch security personnel? Will just the participation of competent professional manpower and best of surveillance equipment do the magic? Alternatively, perhaps the putting in place of the correct procedures to complete the system is the guarantee of an impregnable security system.
                   
What it requires, I think, firstly is the total TM commitment, to ensure and motivate their teams by care and coordination to ensure the security system works. The security policy published by the TM should be totally in keeping with the actual security requirements of the organization and based on an in-depth study of the threat perceptions. The policy if well thought over and reflecting the actual of the organizations security threats will then lead to measurable objectives and goals for the security team. The team then can have the organization and procedures aligned and resourced to meet these objectives. Once the procedures are ready and introduced the vital phase of training and training alone will determine the outcome of the desired results. Both prevention in terms of preparing for a security eventuality and the response in consequence to a security tragedy will require the systematic P-D-C-A (Plan-Do-Check-ACT cycle)* approach. A good security plan based on a through security assessment (SA) as it moves to the working phase/ Implementation stage (Do) requires aware leaders leading their team through constant training.

Drills to practice and work the security procedures and build the required confidence level will require regular, well-planned training. Drills must exercise each security element of the global supply chain. The success in drills will then need to be bridged by training to ensure each element in the global supply chain (for that matter the domestic supply chain too) is exercised. The more innovative and realistic these drills and exercises the greater will be the confidence level of the management and employees (as also all stakeholders) in their ability to both prepare and be able to react to a breech in security of the supply chain or any of its elements.

SA is essential and integral to a security plan (SP). However, emphasis on carrying out a detailed and thorough threat perception as a must ‘pre-cursor’ to SA before a SP is made should be part of the system ensuring security. Each security drill and exercise should encompass the elements of ‘lessons learnt’ at each level, finally leading to the TM review. TM must remain involved and committed to the security ensuring continual improvement is taking place and innovation encouraged. It must be remembered that the terrorist organizations recruit and train a very motivated work force on their well-tried methods! These terrorists are often two steps ahead of the security measures the industry takes and are ever ready to circumvent security. The security of the global supply chain can only be ensured by the training system being innovative, proactive and capable of recognizing potential threats to the security. Following up on NC by correction and corrective action is essential, but an indicator of the organization being a step behind the ‘bad elements’. Following up on NCs against the security system at its best can be defined as reactive. The security team will be effective; the security system will function as planned when the indicators point to the capability of the system to predict potential security breaches (NCs) by analyzing security threats and trends from available security warnings, threat perceptions. The occurrence of a NC always costs the organization, however small or catastrophically. However, there is a cost associated.  With good training, the team with its involvement and commitment can recognize the potential NCs and add value to the system protecting the global supply chain and each element in it. The security system must therefore drill and exercise the team members to ensure competence and provide them the ability and confidence level to understand the security system so well that analysis of indicators is carried out with professionalism and correct TM decisions taken to secure the global economy from unscrupulous elements.

Thursday, March 21, 2013

ISO 28000: Using the International Standard in the ever deteriorating global security environment and its impact on the homeland security.

In his introduction to the National Strategy for Global Supply Chain Security, published on January 23, 2012, the President has clearly emphasized the United States commitment to ensuring “efficient and secure transit of goods through the global supply chain system”.  Any disruption to the supply chain can adversely affect the economy of our nation or for that matter any nation.  Our homeland cannot be safe if the global supply chain remains vulnerable.  Adopting the process-based management system (PBMS) approach to global supply chain security can guarantee the rejection of the misconception that security and efficiency are not possible together.

ISO 28000 is a generic security management standard based on the PDCA cycle (Plan, Do, Check, Act) already extensively employed by businesses globally to bring in efficiency, continual improvement and innovation using the international standard ISO 9001.  Companies, which are already compliant with the ISO 9001 standard, are in a ready state to incorporate the additional requirements of ISO 28000.  Where companies are not compliant with ISO 9001 and considering ISO 28000 as the initial standard to adopt the PBMS approach, they prepare themselves to benefit from the approach when they further widen their scope.  The adoption of the Customs and Borders Protection (CBP) initiative, C-TPAT by companies within the US and those trading with the US benefit as the C-TPAT initiative is based on the ISO 28000 standard and can therefore be implemented in a seamless manner.

Those companies which are considering a process-based approach to management for the first time, not only ensure the security of the global supply chain but also then prepare their systems for gaining the benefits of efficiency, continual improvement and innovation to their management systems.  Apart from C-TPAT, the other international initiatives similar to ISO 28000 include the World Customs Organization (WCO), which has adopted the Framework of Standards to Secure and Facilitate Global Trade, SAFE Framework security requirements, International Maritime Organization (IMO) / Safety of Life at Sea (SOLAS) security requirements (as included in Chapter XI-1 & 2) leading to the International Ship and Port Facility security requirements, EU Authorized Economic Operator
(AEO) security requirements.

At one time, just ensuring efficiency based on ISO 9001 was an option for companies to remain in business and to operate profitably.  However with time, to stay in business the companies had to take care of the risks, pollutants and adverse effects to the environment from the by-products of their processes.  ISO 14001 (Environmental Management System – EMS) took care of this.  However, following the tragedy of 9/11, this was not sufficient and protection of the business from security breaches became vital to ensure business continuity and profitability.  In 2001 – 2002 following the tragedy, it was the maritime community who realized their vulnerabilities and took the initiative to protect the maritime assets by adopting the IMO’s ISPS Code (International Ship and Port Facility).  This protection of the maritime assets, however, left the supply chain vulnerable to security breaches both upstream and downstream.  ISO 28000 fills this gap and brings the PBMS approach to the security of the entire global supply chain.

The supply chain globally connects the world economy today.  With the dependence on Middle East oil remaining a reality, global security of our supply chains is more critical than ever.  Terrorists and bad elements seeking to disrupt the supply chain can best be prevented by a system approach to security.  The dangers to our maritime assets in ports come from outside the ports, up and down the supply stream, so just protecting the ports is not sufficient.  The entire supply chain upstream and downstream needs planned protection using a fail-safe system.  One vessel destroyed in just the right location will affect a country’s economy for years.  One train with HAZMAT cargo destroyed in a vital location can cause great loss of life, cause mass hysteria and not only adversely affect the economy but also demoralize a nation.  Consider a remotely detonated nuclear device being exploded anywhere in the route of the long global supply chain and its impact.  In US neighborhoods, a lot of our trade from the North and South is carried out on trucks.  Securing the trucking routes can be a nightmare without a system approach.

Shipping unites the world by its complex intermodal transportation and is crucial to the world economy.  This then also makes it vulnerable to pirates and terrorists.  While the ISPS code ensures the requisite security of the maritime assets, these threats come into the ports and ships from outside.  Ninety-five percent of our imports are by sea.  The security of the ports upstream and downstream is a national necessity.  The United States also needs to consider the effects of the Panama Canal widening which will allow for new super carriers to come to our Eastern ports.  This will slow down the inspection process.  These implications will bring in nonconformities (NC) occurring over time as we receive this larger amount of shipping on our eastern shores.  Can the nation wait for the NCs to occur and then apply correction and corrective action, or should ISO 28000 be adopted across the supply chain to use the PBMS approach and ensure the security of the global supply chain?

Complexities of the supply chain cannot be managed without a system approach.  An end-to-end view of the entire operation needs to be the focus.  It will require coordination and protection carried out in a systematic manner.  The probability of a supply chain vulnerability causing harm by disruption will continue to grow without a system approach to the management of its security.  This risk can be mitigated by the adoption of the system approach fundamentals provided in this international standard .