Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
year enlarge that scope. For example, many hospitals do it. They start with a service like blood analysis, and then enlarge with radiology, and then with urology, and so on.
So, if you use the word departments in this way, your company can do it.
You can find more information below:
Processing personal data for statistics, even though the personal identifiers are removed, is still considered a personal data processing operation and it falls under GDPR, if the state is a member of EEA or if the affected data subjects are on EEA territory. However, the publishing of de-identified personal data is not considered processing of personal data, unless the data can be used to identify a data subject. The key to understanding this is the definition of “personal data” in article 4 GDPR: “any information relating to an identified or identifiable natural person (‘data subject’)”. So if the information published by a state leads to the identification of a natural person – either by another person or by an algorithm – that information is considered personal data.
You can find more details at this link:
If you are a distributor, then you need to understand that your "production" is basically service provision. SO everywhere in the documentation that says "production," you can put "service".
Your point of view regarding 3.3.7 is OK. You cannot exclude this; you will just use the identification provided by the manufacturer. You need to have in your system the possibility to track to which customer went which LOT of medical devices.
This approach will not cause problems in the system.
However, by developing its own objectives, the organization will have to identify how they can be related to Conformio processes and modules (i.e., which information will be needed and where it can be found), while the suggested objectives in Conformio already have a defined logic related to them (e.g., suggested data sources), making using them easier to fulfill standard’s clauses related to security objectives.
First of all, sorry for this confusion.
The toolkit you have is still current.
The documents from sections A.5 and A.18 are not missing from the toolkit – you can find them here:
Included in the toolkit there is a List of Documents file that shows which documents cover which clauses of the standard.
Awesome Rhand! Thank you so much for your answer
I’m assuming that by “ISO 27001” you mean “ISO 27001 Toolkit”
Considering that, if you plan only on managing audits, the toolkit would be the best choice, because you can use only the documents related to internal audit.
Conformio is a platform to manage the whole implementation and maintenance of an Information Security Management System from definition of security objectives to continual improvement, which requires much more effort to manage (e.g., document management, risk assessment, and treatment, incident management, etc.).
The forms can be filled in two types of support, paper or digital. In some companies, paper-based records are digitized a posteriori.
Records in digital support are archived on the company's server.
Paper-based records are filed in folders according to rules and filing criteria defined on a case-by-case basis by the companies.
The bottom line is: records are the memory of the company. If we can't access the records we need when we need them, we're a memoryless company. Memoryless companies don’t learn.
You can find more information about documentation below:
1) In which cases, an auditor can decide whether to waive an audit in a company.
Answer: Considering certification/surveillance audits, these cannot be waived, because not performing a certification/surveillance audit will impact the certificate issuance.
In the case of internal audits, these can be waived considering the results of previous audits, provided that all ISMS scope is audited before a certification/surveillance audit.
For example, if you have a process audit twice a year, due to the results of previous audits (that were good), you can decide to waive one audit and perform audits only once a year.
2) In case of detecting illegal software in an audit which is the procedure for which an auditor has to go, who is required to communicate how to proceed.
Answer: This is a situation to be treated very politely.
The recommended approach is to state that it was not possible to evidence the proper management of intellectual property rights of software *** (you should NEVER state that software is illegal, remember that your findings are based on the evidence you have found, or not found).
Regarding who to communicate with, you need to communicate with the audit customer during the briefings at the end of each audit day, and that the nonconformity will be also formally communicated in the Audit report.