Search results for "iso17025 vs gmp"

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO 27001 - frequency of recertification

    ... ... out certification of organizations, surveillance visits must take place at least once a year, and the certificate is valid for 3 years. After the certificate expires, an organization can decide whether to go for the recertification, but this is not mandatory - this is something you do only if you want to keep the certificate.

    This article can also help you: Surveillance visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/

  • Can the risk be accepted and the control not applied?

    ... low risk during the Risk Assessment and senior management has agreed to accept the residual risk; and we determined it be out of scope, is being demanded by the auditor to be in-scope. Is that permitted? Based on our scope and boundaries as well as documented exclusions, the control does not come into play. I’m trying to gather some additional information on the determination of in-scope vs. out-of-scope.

  • Risk register vs. risk treatment table

    Is the risk treatment table considered as risk register? or the risk register is something else?
  • Third Party Providers vs. ISMS Policy conflictions

    Hi, I have a concern presently concerning ISO27001 and company ISMS policy / third party agreement guideline vs. a third party who plays a large role in company activities. Our third party agreement guideline states that third parties shall compy with certain security requirements. We have a provider that has stated  they are not iso27001 compliant but use many ISO 27002 principals, which is fine, but we are attempting to have them sign our agreemen - they do not want to sign, and I QUOTE "Because such a framework is subject to extensive governance, both internally as by external auditors and our overseers, security is not an area where we (they) have the liberty to accommodate and apply different security requirements per individual customer" UNQUOTE They have also provided a statement to replace what we have asked " QUOTE X shall at all times operate and manage the information security, reliability, resilience, and technology planning in accordance with its security control policy. In order to provide a more understandable framework for its specific business, the  X security control policy is organised around the 5 key dimensions of: governance, change management, confidentiality, integrity and availability. X has implemented a number of initiatives that enhance security, including a company-wide commitment to adopt many of the principles of ISO 27002, which is the code of practice for information security management. This involves, amongst others, risk management practices in line with ISO 27005 and NIST standards. These internationally recognised standards provide wide-ranging security guidelines" UNQUOTE How does a company get passed this in ensuring they apply to the company security requirements especially when this aspect can be audited? Is this acceptable? Thanks for your reply Paula
  • ISO 27001 and PCI-DSS

    i got an question about iso27001 vs pci-dss and found no information. maybe you can tell me someting about it. if a company did the iso27001 and handle with ecommerce card infos, is it nessesary to implement the whole pci-dss? i mean, they are very similar and so double doings?!
  • Policy vs. standard

    What is the absolute difference between a policy and a standard?
  • Processes vs. Departments

    Do we need each department providing their process on particular activities..an example of HR section..their job is normally recruitment..so do they need to documented (maintain/retain) all the process?
  • Internal and external issues and risks and opportunities prioritization


    Answer:

    Internal and external issues differ from organization to organization but there are some that are common for all organization. Internal issues can be the organizational structure, the culture of the organization, issues related to your employees (current competence vs needed competence, their needs and expectations, etc), issues related to technology and equipment your organization use, etc.

    External issues are related to the external environment in which the company operates, this can be economical and political situation in your country, legislation, but also needs and expectations of external interested parties such as your supplier, subcontractors, customers, etc.

    Determining internal and external issues is closely related to the identification of needs and expectations of interested parties and that can be e asier and can provide you with inputs on what to consider when addressing internal and external issues. There is no formal requirement to document context of the organization but it can be very useful to do so when you are doing it for the first time.

    For more information, see:
    - How to identify the context of the organization in ISO 9001:2015 https://advisera.com/9001academy/blog/2015/05/26/how-to-identify-the-context-of-the-organization-in-iso-90012015/
    - How to determine interested parties and their requirements according to ISO 9001:2015 https://advisera.com/9001academy/blog/2015/11/10/how-to-determine-interested-parties-and-their-requirements-according-to-iso-90012015/

    The crucial step in identifying risks and opportunities is to properly determine context of the organization. Once you have this information you can start thinking about the risks and opportunities regarding your QMS. There is no single way to prioritize risks and opportunities but you should start with risks and opportunities that are directly affecting quality of your products and services and customer satisfaction, or start with ones that require least resources and time and can be resolved easily. Important thing is to make plan to address risks and opportunities, meaning to define resources, responsibilities and actions to address each risk and opportunity.

    For more information, see:
    - Methodology for ISO 9001 Risk Analysis https://advisera.com/9001academy/blog/2015/09/01/methodology-for-iso-9001-risk-analysis/
    - The Role of Risk Assessment in the QMS https://advisera.com/9001academy/blog/2014/01/07/role-risk-assessment-qms/
  • Implementation of ISO 9001 over ISO 27001

    ...  ISO 9001 vs. ISO 27001 matrix (PDF) https://info.advisera.com/9001academy/free-download/iso-9001-2015-vs-iso-27001-2013-matrix/
    - ISO 9001 Implementation Diagram (PDF) https://info.advisera.com/9001academy/free-download/iso-9001-implementation-diagram/

  • Configuration Management vs Record Control

    I would like to find out the difference between Control of Records and Configuration Management. Does ask requires organisations to have both?

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +