Uppsats
A Gap Analysis of Supply Chain Security Against ISO 28000 at a Defense Industry Company: A Case Study of Governance, Formalisation and Alignment
H
Chalmers tekniska högskola / Institutionen för teknikens ekonomi och organisation
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Supply chain security has emerged as a strategically significant governance challengefor organisations operating in security sensitive industries. As hostile actorsincreasingly target supply chain dependencies to exploit vulnerabilities below thethreshold of armed conflict, the need for structured and formalised governance ofsupply chain security has become a strategic imperative rather than a complianceobligation. This examination investigates the degree of alignment between existingsupply chain security practices at an established defence and security industryorganisation and the requirements of ISO 28000, with the aim of identifying areas ofcompliance, partial alignment and significant nonconformance across relevantorganisational processes and supplier interfaces.A mixed methods approach within a single case study framework is applied, combiningsemi-structured interviews with employees across relevant organisational functions andan analysis of internal company documentation. ISO 28000 serves as the analyticalreference framework through which empirical material is systematically assessed.The gap analysis reveals substantial alignment in several foundational areas whereexisting organisational structures and processes reflect the underlying governance logicof the standard. However, these structures are developed primarily in relation to ISO27001 and are not configured to address supply chain security as a distinct governancedomain. Partial alignment is identified across areas where relevant structures exist butfall short of the formalisation and institutional embeddedness required by the standard.Significant nonconformances are identified in the absence of formally designatedcompliance ownership, the reliance on informal coordination as a substitute for formalgovernance, the absence of measurable supply chain security objectives and the lack ofa context analysis oriented towards the supply chain security environment.The assessment concludes that the overall correspondence with ISO 28000 is partialrather than substantive. Supply chain security must be constituted as a governed domainin its own right, with formally designated compliance ownership, measurable objectivesand structured verification mechanisms, before the organisation meaningfully pursuesalignment with the standard.
Information
- Författare
- Malmfors, Hilda, Edhage, Teodor
- Lärosäte / institution
- Chalmers tekniska högskola / Institutionen för teknikens ekonomi och organisation
- Publiceringsdatum
- 2026
- Uppsatstyp
- H
- Språk
- Engelska