Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Inquiry: ISO 17025 accreditation of a microbiological laboratory

    ISO 17025 is applicable for all testing and calibration laboratories. There is no mandatory requirement to use standardized methods. When using a in-house developed method you have to show you can meet the performance requirement of the method to fit the purpose. In other words, achieve suitable accuracy and precision and other parameter such a s limit of detection, based on need and risk. i.e. tolerated variation in results.

    For accreditation all mandatory requirements of ISO 17025 must be met. For technical requirements this includes method validation, ongoing internal quality control to ensure the validity of your results and participation in a proficiency testing scheme or interlaboratory comparison. I suggest you engage with your quotation body and pose the question to them of how you would proceed for your accreditation in your field. 

    The Whitepaper Clause-by-clause explanation of ISO 17025:2017 may assist you, available at https://info.advisera.com/17025academy/free-download/clause-by-clause-explanation-of-iso-17025/

    For more information on the mandatory requirements, see the Whitepaper Checklist of mandatory documents required by ISO 17025:2017 at https://info.advisera.com/17025academy/free-download/checklist-of-mandatory-documents-required-by-iso-17025

  • ISO/IEC 27001/2 Harmonization

    There still is no official date for starting the review of both ISO 27017 and ISO 27018 considering the new ISO 27002. The expectation is that this timeline will be published together with the information about the update of ISO 27001.

  • DMS/Apps - information/content delineation questions

    1. What we are getting confused over is, what information/content can stay in Fibery and Hubspot (and other Collaborative apps like Confluence – which we will be using) and what we need to move into the DMS.  Is there any guidance on how to approach this? For example, if we leave ISMS related content in Fibery and point the hyperlink to the content is that OK ...

    ISO 27001 does not prescribe where to store documents and files, so organizations can adopt the approach that better suits their needs, provided the standard’s requirements for creation, update, and control of documents are fulfilled.

    Considering that, your approach of leaving ISMS-related content in Fibery and pointing the hyperlink to the content is acceptable, provided you fulfill the standard’s requirements for the creation, update, and control of documents.

    For further information, see:

    2. Another question is, most 3rd party apps provide features to create documents. For example, Fibery has a document function to create docs to their standards. However, they do not have the fields to store many of the ISO Document standards, like control info. and classification type. And access can be open to anyone authorised. Would it be fair to say, that any ISMS related documents and records should not be stored in such an App. ? 

    Your understanding is correct. You should avoid the use of apps that cannot allow document management according to ISO 27001 requirements.

  • Question regarding Data Breach Response Team

    A data breach is defined in Art 4 GDPR – Definitions – as a “breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed”. According to Article 33 GDPR - Notification of a personal data breach to the supervisory authority – the data breach should be reported to the Supervisory Authority “unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons”. When you assess the risks related to the rights and freedoms of data subjects, you need to ask what could happen to the data subject if the compromised data would be exposed.

    If an email account is compromised, there are significant risks for conversations to be exposed, for email addresses to be exposed, attacked, or abused. All these risks need to be assessed and documented before deciding to report them to the authority. Anyway, the supervisory authority is requesting each data controller that reports a data breach to give all the details related to the data breach, including likely consequences for the affected data subjects.

    In the EU GDPR Premium Documentation Toolkit, in directory 12 – Personal Data Breaches – there are two templates to help you: a procedure for Data Breach Response and Notification and a Data Breach Notification Form to the Supervisory Authority. If you fill in all the details in these two documents, you will know better whether to report the incident to the supervisory authority or not.

    Please consult also these resources:

  • ISO 27002 changes

    Please note that ISMS audits are based on ISO 27001, not on ISO 27002. 

    Considering that, until changes made in the new ISO 27002 are incorporated in ISO 27001 Annex A, ISMS audits can be based on the valid version of ISO 27001 standard.

    This article will provide you a further explanation about new ISO 27002:

    - 11 most important facts about changes in ISO 27001/ISO 27002 https://advisera.com/27001academy/blog/2022/02/09/iso-27001-iso-27002/

  • Undocumented Controls

    Please note that by “All required ISO 27001 documents” we mean that our ISO 27001 Documentation Toolkit covers all mandatory documents and some documents that are not mandatory. The controls you listed do not need to be documented according to the standard, and in our opinion, it would be an overhead to document each and every one of them in a small company. 

    Our toolkit is created specifically for smaller companies that want to implement ISO 27001 in a quick way, without unnecessary paperwork; for larger companies that require more documents, we recommend getting some other solution.

    This article will also help you: 

  • Continuous responsibilities

    Please note that “continuous responsibilities” refers to tasks without a specific deadline (i.e., they must be performed while the ISMS is being used) that must be performed on demand.

    Considering that, you should consider such tasks as done for a specific demand when you generate the related evidence that it was performed.

    For example, the task “Identify all legal, regulatory, contractual, and other requirements related to interested parties that can affect or be affected by information security management.”, is considered “done” when you update the Register of Requirements module.

  • Task Link Issue

    Please note that regardless of whether you use the wizard to review or approve the document or not at the time of receiving the document review task, the checkpoint for the definition of the date of the next review is the date of approval of the document.

    This means that the tasks are created every x months (depending on what you have defined as the update frequency in the properties tab) from the date of approval.

    For example, if you have approved the document on March 1, 2021, and the update frequency is 6 months, then a new review task will be created every 6 months from March 1, regardless if you proceed with the review through the wizard or not.

  • Document Set

    The Advisera GDPR toolkit includes all the necessary documents needed for you to complete your GDPR-compliance journey. Since you are processing special categories of personal data (health data), I recommend performing a Data Protection Impact Assessment, per Article 35. As part of the Advisera GDPR Toolkit, there is a DPIA Methodology document that can help you. Also, you need to consider informing the data subjects affected by these transfers. As part of the GDPR Toolkit, there are templates for Privacy Notices.

    As an American company, you need to check whether you are subject to FISA 702 US Regulation. If yes, you need to take additional measures in order to protect EU data, according to Chapter V in GDPR - TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS. The best transfer mechanism to use in this case is the EU Standard Contractual Clauses, per art Article 46 – Transfers subject to appropriate safeguards, but you need to take additional measures such as encryption of data-at-rest and in-transit, with a key stored on a server in EU.

    The risks would be clearly reduced if you have full storage of data on EU servers managed by an EU organization.

    Please also consult these resources:

  • Risks registered is not effectives

    Thanks for the tips and points to enhance risks registered , however 140 risks is huge no to maintained the risks regardless the treatment, i'm expecting something around 20 risks max to be easly maintainted especiallty the main dimensions for security control under CIA , in addition ISO is not need inssist to include asset on risks handling, 

     

     

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +