Overview
ISO 28007-1:2015 - Ships and marine technology - Guidelines for Private Maritime Security Companies (PMSC) providing Privately Contracted Armed Security Personnel (PCASP) on board ships - Part 1: General - is guidance for applying ISO 28000 to maritime armed security. It provides sector‑specific recommendations that PMSCs can implement to demonstrate safe, auditable delivery of PCASP services on ships, including risk management, personnel vetting, training, rules for use of force (RUF) and incident handling. Compliance is based on following the document’s “should” recommendations; certification can be by first, second or third party. The standard complements ISO 28000 (security management systems for the supply chain).
Key topics and requirements
ISO 28007-1 structures PMSC requirements around a Security Management System (SMS) and covers:
- Security Management System elements: understanding context, interested parties, scope, leadership, competence, roles, organizational structure and financial stability.
- Planning: security policy, risk assessment, objectives, legal/regulatory compliance, and authorization/licensing of firearms and security equipment.
- Resources and personnel: selection, background screening, vetting of PCASP and subcontractors; insurance and outsourcing controls.
- Training & awareness: training standards, firearms training, documented training procedures and record keeping.
- Operation: operational planning and control, command and control, team size/composition, guidance on Rules for the Use of Force (RUF), incident management, reporting, evidence protection, casualty management and HSE (health, safety and environment).
- Performance evaluation: monitoring, measurement, internal audit, management review, nonconformity/corrective action and continual improvement.
- Human rights: alignment with legal obligations and the UN Guiding Principles on Business and Human Rights (UNGPs) is emphasized.
Practical applications - who uses it and why
ISO 28007-1 is used by:
- Private Maritime Security Companies (PMSC) that provide PCASP aboard vessels in areas at high risk of piracy.
- Ship‑owners, operators and charterers who contract armed security services and require auditable assurance.
- Certification bodies, flag states, insurers, port authorities and vetting/assurance teams assessing security governance.
Typical uses:
- Extend an ISO 28000 SMS to include armed maritime security operations.
- Define and document RUF consistent with international and flag‑state law.
- Standardize vetting, firearms authorization, training and incident response to reduce liability and improve contractor selection.
- Support commercial tenders and certification statements (recommended certificate wording is provided in the standard).
Related standards
- ISO 28000 - Specification for security management systems for the supply chain (normative reference).
- ISO/PAS 28007:2012 - superseded by ISO 28007-1:2015.
Keywords: ISO 28007-1:2015, PMSC, PCASP, ISO 28000, private maritime security, rules for use of force, firearms training, maritime security services, security management system, piracy risk.