We would like to integrate documentation with regards to ISO 9001:2015 and ISO 27001, however, we have technical problem how to do it. There are several procedures that are common for ISO 9001 and ISO 27001, but there also separate procedures for each of these standards. We do not know how to title these procedures it should be Quality Management System and Information Security System according to EN ISO 9001, EN ISO 13485, EN ISO 17100 and EN ISO 27001 even if this particular procedure does not apply to ISO 27001 or ISO 9001? Or maybe Quality Management System procedure and later refer to relevant standards?
Answer:
You can follow the way that you want, which means that you can follow the way more easy for you. If you have various Management Systems, for me the best way is to establish an Integrated Management System, developing an unique document for those that are common: Integrated Policy, Integrated Internal Audit, Integrated Management Review, etc. And for those that are not common, you can include in the title the name of the Management System related: ISMS Risk Management, QMS Supplier Management, or even if you have 3 system and a procedure not apply to the others, you can refer in the title to the 2 systems: ISMS-QMS-name-procedure.
Finally, this procedure can be interesting for you Document management in ISO 27001 & BS 25999-2 : https://advisera.com/27001academy/blog/2010/03/30/document-management-within-iso-27001-bs-25999-2/
Comment as guest or Sign in
Jan 12, 2016