SCS Notes - Last-minute Review
Learning Outcomes
Identify areas along the supply chain that are vulnerable to security breaches.
Examine how supply chain visibility can be enhanced with technology.
Describe supply chain security initiatives to address security issues.
Why Supply Chain Security?
Prevent nuclear, biological and chemical materials from falling into wrong hands.
Prevent theft/pilferage, sabotage, piracy, product contamination, environmental hazards, counterfeit products, contraband.
Threats to Global Supply Chains
High-severity threats include: hacking into IT systems; nuclear device; dirty bomb in container; plane attack; infectious agent; oil tanker attack; food contamination; cargo theft; car bomb; employee sabotage; bombing of a major bridge.
Severity/impact scale: High to Low (reference Deloitte-based chart).
Implications (facts & figures)
Global transit loss estimates:
Typically income reduction for Fortune 500 due to poor security
Estimated, of cargo thefts are “made to order thefts”
Threat rated “severe” in Brazil, Russia, South Africa, Indonesia, Nigeria & Malaysia
An effective terrorist attack cost is unknown but would be impactful and disrupt supply chains
Supply Chain Security: Key Domains
Transportation Security: training, communication, non-intrusive inspection, secure inter-modal containers, air cargo security
Information Flow Security: password protection, firewalls, data segmentation, encryption
Personnel Security: background checks, security clearances, identification and verification
Material Flow Security: tracking & tracing, sensors for tampering, tamper-resistant seals, advanced reporting
Physical Facility Security: fences, guards, lighting, CCTV, screening
How criminals obtain information; What they look for; When will they attack
How obtain information: loose talk, questions, route recognition, information willingly given, buying information, interception, surveillance
What criminals look for: non-compliance, weakest link, times when protections are lowest or product is abundant
When will criminals attack: when control is possible, escape is easy, least expected
Who is at Risk
Manufacturer – counterfeit products
Oil & Gas – sabotage
F&B – bio-terrorism
Chemical & Pharmaceutical – theft & counterfeit
Aviation – terrorism
Logistics, Transport & SCM – smuggling, cargo theft
Maritime – smuggling, trafficking, WMD
Service – migratory impact
Insurance – claims
Supply Chain – all parties
Why Vulnerabilities Are Rising
Just-in-time/lean approaches
Global sourcing/globalization of supply chains
Outsourcing
Supply consolidation; reduction of supplier base
Volatility of demand
Lack of visibility and control procedures
Global SCS Programs / Initiatives
ISO 28000:2022 – security management systems standard for the supply chain; apply to organization
Secure Trade Partnership (STP)
Transported Asset Protection Association (TAPA) Standards A, B and C
Customs-Trade Partnership Against Terrorism (C-TPAT)
24 hour Advance Manifest Rule
Container Security Initiative (CSI)
ISO 28000 series
ISO 28000:2022 specifies requirements for security management systems; aims to improve resilience and integrated security management
ISO 28000:2007 focused on managing security in the supply chain, not the security department
Secure Trade Partnership (STP)
Launched by Singapore Customs in 2007; voluntary certification
STP certification encourages robust security via risk-based approach
STP-Plus offers easier trade through Mutual Recognition Arrangements with other countries
STP Certification Requirements
Security checks include Premises Security & Access Controls; Personnel Security; Cargo Security; Conveyance Security; Information & IT Security; 8 Key Security Elements; Crisis Management; Incident Management
Examples: GPS tracking; standardized elements; incident handling
WCO AEO Program
Authorized Economic Operator: customs-business partnership program; compliance with WCO standards
Benefits: improved security and facilitation; MRAs with partner countries
MRA Benefits
Higher clearance facilitation; priority inspection; expedited clearance during disruption; cost savings
Transported Asset Protection Association (TAPA)
Global org (~2500 members); develops standards to minimize cargo losses
Standards: FSR, TSR, GSR, PSR, CSS
TAPA Security Standards
FSR: facility security for warehousing/in-transit storage
TSR: secure trucking
GSR: guarding services
PSR: secure parking
CSS: cyber security standards
Freight Security Elements Documentation
Document freight security requirements; elements; contractual language; performance expectations; standard assessment protocol; scoring; corrective actions; training; incident handling
TAPA Audit Scoring Matrix
Snapshot of audit rating, process & procedures, criteria, facility classification, overall percentage, areas of concern
C-TPAT
US Customs program (2001) to improve container security; private-public partnership
Benefits: cargo less likely to be screened; improved security
Participants: importers, carriers, brokers, warehouses, manufacturers
Validation: supply chain security profile; risk assessment; compliance evaluation
Guideline coverage: Personnel Security; Physical Security; Access Control; Education & Training; Manifest Procedures; Conveyance Security
24-Hour Advance Manifest Rule
Ocean: cargo declaration 24 hours before lading
Air: wheels up <4h; or 4+ hours before arrival
Penalties for incomplete data
Container Security Initiative (CSI)
Government-to-government; CBP in foreign ports; screen high-risk cargo before loading
Non-intrusive inspections; WMD screening
100% manifest data to US; foreign port screening
CSI Ports (examples)
Halifax, Rotterdam, Singapore, Yokohama, etc.
Learning Outcomes (closing)
Review of the three learning outcomes for quick recall