Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
1 - We are a little bit lost with the Initial training plan as we are not sure how to structure it and what are good practice. Can you provide good practice for training when defining the Initial Training Plan?
Answer: The easiest way for defining the Initial Training Plan, you should consider insert the trainings specific to steps/policies that are relevant employees to master, and then that training is automatically added to the Training step.
For example, for the risk register step this is how it looks like:
In each of the steps a user can define specific trainings and assignees, those are then automatically added to the Training module. In case you want to update the training status or define new trainings, you can do this inside the Training module itself.
2 - We are not sure if we need to define different suggested training for different skills. Should it be on different skills or different rules depending on the role in the company?
Answer: Please note that there is no single answer to this question because you have different publics with different objectives:
- top management needs to make decisions over issues that many times are not so clear for them, and they do not need deep knowledge about technicalities of security issues (they will be more concerned about how it impacts the business). In these cases, your presentation should be focused on decisions they need to make on each policy
- technical personnel with operational responsibilities for security needs deep knowledge over technologies, methodologies, and process, so your presentation should be focused on the procedures and rules they need to follow
- overall personnel needs a basic understanding of security, to properly identify, report, and react to risky situations. In these cases, your presentation should be focused on examples and how to proceed according to the policies
3 - What are good training or skills for an IT Manager or Compliance officer for example?
Answer: Examples for an IT Manager would be integration of information security in IT strategy or evaluation of security of solutions providers. As for Compliance Officer, trainings related to laws and regulations impacting information security (e.g., on EU GDPR, or US HIPAA).
4 - We would also appreciate a catalog of links to training on your website that can be useful in completing the training plan?"
Answer: These articles will also help you regarding awareness and training:
- How to perform training & awareness for ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/05/19/how-to-perform-training-awareness-for-iso-27001-and-iso-22301/
- 8 Security Practices to Use in Your Employee Training and Awareness Program https://advisera.com/27001academy/blog/2015/03/02/8-security-practices-to-use-in-your-employee-training-and-awareness-program/
This material will also help you regarding awareness and training:
- Free Security Awareness Training: https://advisera.com/training/awareness-session/security-awareness-training/ - this is a series of 25 videos that cover various topics related to security.
5 - "We were going over the "Procedure for identification of requirements" and we ran into this part that wasn't clear:
- what document does the "Information Security Management System Policy" refer to? "
Answer: First of all, sorry for this confusion.
The “Information Security Management System Policy” is the same “Information Security Policy” used in Conformio.
No, there are no restrictions on the font size for IFU for medical devices.
You asked
I need you help regarding Proficiency testing and PT provider in pesticide formulation
I cannot recommend any providers as it depends on your scope and area. Have a look at EPTIS at https://www.eptis.org for posisble providers. This is an International database of Proficiency Testing (PT) schemes.
You also asked
I need your help with regard to PT testing as we couldn't find any in our scope .is there any alternative?"
The policy document ILAC-P9:06/2014 ILAC Policy for Participation in Proficiency Testing Activities is applicable to your situation. It is available at https://ilac.org/publications-and-resources/ilac-policy-series/
What I suggest you do is contact your accreditation body as well, as they will need to approve the alternative which typically would involve a bilateral study between yourself and one other laboratory or the use of certified reference materials for your own study.
This requirement refers to the need for intermediate checks on equipment to be performed according to a procedure. For certain equipment, external certified calibration (as per ISO 17025 calibration requirements), is required to conform the equipment is suitable for use and to provide metrological traceability and a measurement uncertainty for that step in the testing process (for example the use of a balance to weigh a sample). For equipment which could impact the validity of test results, intermediate checks (i.e. verifications) must be performed inhouse at suitable intervals until the next external calibration to confirm the equipment is still in calibration (i.e. has not deteriorated or drifted). This maintains confidence in the performance of the equipment. This is achieved by using traceable reference materials, or artifacts (such as certified weight pieces). The procedure could be a written work instruction or diagram, for example for the Daily verification of analytical balances.
For more information see the question and response to Are intermediate checks required for calibration laboratories? at https://community.advisera.com/topic/are-intermediate-checks-required-for-calibration-laboratories/ There are alse some useful links on that page that will assist you.
1 - Is this sufficient during an ISO 27001 certification external audit to prove that *** took the necessary actions with regards to training internal employees?
Please note that the security awareness training on our website focuses on regular users and general information security knowledge. In case you have specific security technical/management needs (e.g., secure development techniques or security strategy planning) this training won’t be sufficient.
Considering that, you need first to identify which information security competencies gaps you need to treat, so you can evaluate if our training will cover all your needs, or if you need to complement it.
This article will provide you a further explanation about awareness and training:
2 - Is there any way to prove the employees have effectively followed your training ? Something like a completion certificate?
Through the paid version of our security awareness training program, you can export the progress report and track which employees already attended the training and their results.
When using the free version, you can create quizzes to apply to employees who have taken the training to evaluate their learning.
3 - Would you recommend additional steps?
The steps provided in the Training and awareness plan template included in your toolkit are enough to be compliant with the standard.
Common approaches for information security awareness are training sessions, the use of newsletters, the use of video tutorials, and meetings between management and staff, which should be performed on a regular basis.
Regarding content, please note that you will have different publics with different interests:
ISO 27001 does not prescribe which information should be added and recorded about assets to be destroyed, so organizations are free to include the information they see fit for their needs, based on results of risk assessment and applicable legal requirements.
Recording serial numbers for each HDD would be a good practice, because serial numbers are unique identifiers, and you wouldn’t need to create your own to keep track of destroyed assets in case of need.
These articles will provide you a further explanation about assets disposal:
In such cases, to decide if this is a finding or not you need to check if the events that trigger the procedure to be performed had occurred or not.
For example, if the trigger is something like “every 6 months” or “6 months of the last occurrence”, and such period has not been completed yet by the time of the audit, then it is acceptable that the procedure has not been carried yet, and it is not a finding. Otherwise, it should be considered a finding.
An example of a document that may not be activated when an audit takes place is the Disaster Recovery Plan or an incident treatment for a specific incident.
For further information, see:
There will be some changes, although the procedure is applicable to inhouse and external clients. Depending on the organizational structure, there may be few or more changes. Simply go over the procedure step by step and customize for your context. For example, a legal contract is not required if the laboratory is part of the same legal structure as the mine /production.
Either way the clients (internal or external) requirements should be known, agreements and deviations presented in writing for inhouse clients as well. In most cases the way you record the evidence and results, can be simplified.
Have a look at my response to a similar topic at https://community.advisera.com/topic/iso-17025-for-internal-quality-control-laboratory/
You can also get a detailed description of the ISO 17025 Documentation Toolkit and free preview, at https://advisera.com/17025academy/iso-17025-documentation-toolkit/
Anonymized data is not personal data. Moreover, the process of anonymization of personal data is equivalent to the deletion of personal data, because the process is irreversible and data cannot be used to identify a data subject, directly or indirectly. So, according to GDPR, you do not need to delete data that is not personal data. However, please pay attention that the data controller does not refer to pseudonymized data, which according to Art 4 GDPR – Definitions – is “personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;”. In this case, pseudonymized data is personal data and is subject to GDPR requirements, including obeying a controller request for personal data deletion.
As part of our GDPR Toolkit, we have a document called Anonymization and Pseudonymization policy that you can use. Please check the links below:
1 - In our Risk Assessment table, is there any "minimum" content we should have to be "credible" from an auditor point of view ? Seeing our scope and assets I've listed I think I'll end up around 150 lines in the table.
ISO 27001 does not require a "minimum" number of risks, only that relevant risks are identified and treated.
Considering that, the auditor will be more concerned about the quality of the identified risks (i.e., how relevant they are for the organizations) than their quantity. The single point you need to pay attention to is to not overlook obvious risks, i.e., risks that someone with proper competence in the process or asset would easily identify. To mitigate this risk, you need to include in the risk assessment the personnel involved with the process or asset.
As for the number of risks you mentioned, 150 is a good number. To have a parameter, when using the asset-threat-vulnerability approach, a small organization generally identifies between 50 to 100 assets, with 3 vulnerabilities and 2 threats for each asset, so they identify between 300 to 600 risks.
An important thing to note is that risk for which you already have implemented controls (and you will only accept the risk) also count for your relevant risks.
These articles will provide you a further explanation about risk assessment and treatment:
2 - Is this Risk Assessment Table a good document you would be able to review for me and provide feedback on ? Or is this too specific to certain business (like ours that is focused on our SaaS platform) ?
As part of your toolkit, you can submit a certain quantity of documents for our review, so we can provide feedback about your work, and the Risk Assessment Table can be one of them.