GB/T 43632-2024 Security management systems for the supply chain—Development of resilience in the supply chain—Requirements with guidance for use
GB/T 43632-2024 Security management systems for the supply chain—Development of resilience in the supply chain—Requirements with guidance for use
Basic Information
Scope
This document specifies the requirements for supply chain resilience management guidelines, so that relevant organizations can formulate and implement relevant policies, objectives, and programs; taking into account the following: a) the laws, regulations, and other requirements that the organization must comply with; b) information about major risks, hazards, and threats that may affect the organization, its stakeholders, and supply chains; c) the protection of the organization's assets and processes; d) the management of disruptive events. This document applies to risks identified by the organization as controllable, changeable, or reducible, as well as unpredictable risks. This document itself does not specify specific performance standards. All requirements in this document are intended to be applied to various management systems based on the PCDA model in organizations. This document provides all the elements required for the aforementioned applications (including elements related to technology, facilities, processes, and personnel). The scope of application of this document depends on factors such as the organization's risk acceptance capability, policies, the nature and scale of the organization's activities, products, and services, as well as the organization's operating locations and conditions. This document applies to all organizations with the following needs: a) establishing, implementing, maintaining, and improving a resilience management policy for the organization and its supply chain; b) ensuring that the organization complies with the resilience management policy it has established; c) demonstrating that the organization's management system includes a sound resilience management policy through the following methods: 1) self-determination and self-declaration; 2) seeking confirmation from relevant parties (such as customers) that the organization is qualified; 3) seeking confirmation of the organization's self-declaration from an external party; 4)