Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... restart after we have resubmitted the evidence that proves we have corrected it.
The certification audit is not resumed after the nonconformity is corrected. The auditor will verify if the nonconformity is resolved (after the official part of the certification audit is completed) and the evidence is sent to him.
For further information, see:
The IT disaster recovery refers to point 4 – Redundancies, which is covered by controls A.17.1.2 - Implementing information security continuity, and A.17.2.1 - Availability of information processing facilities.
This article will provide you a further explanation about Disaster Recovery:
... support" vs "The operation of information systems that support"
Please note that when you refer to "The information systems that support", all personnel who interacts with the information systems needs to be included in the scope (e.g., IT personnel, users, customers, etc.).
When you refer to "The operation of information systems that support", you limit the personnel who interacts with the information systems to the people who keep them running, i.e., the IT staff.
Please note that accreditation applies only to organizations that want to become certification bodies, i.e., organizations that can certify other organizations against a standard, like ISO 9001.
So, the statement is incorrect, because in that context the business should become certified not accredited.
For further information, see:
... ISO 17025 vs. ISO 9001 – Similarities and differences at https://advisera.com/17025academy/blog/2019/07/11/iso-17025-vs-iso-9001-main-differences-and-similarities/
Also have a look at the Advisera 9001 academy resources at https://advisera.com/9001academy/, which includes resources to assist, such as whitepaper Clause-by-clause explanation of ISO 9001:2015 and the ISO 9001:2015 Gap Analysis Tool.
1 - Do you have a presentation that shares some insight on the opposite route - Using ISO 27001 for implementing ISO 9001?
These materials can give you the insights you are looking for:
2 - And would there be any value in going down that route, given our customers do not normally require ISO 9001?
Please note that besides benefits for the customer (which are the main drive for ISO 9001), the organization itself can benefit from implementing ISO 9001:
So, even if customers do not require it, implementing ISO 9001 can bring value to the organization.
For further information, see:
... professional social networks like LinkedIn, Security groups on Google Groups, or the American Institute of Certified Public Accountants (AICPA), which certifies accountants to audit for SOC 2.
This article will provide you a further explanation about SOC2:
Considering the 45 templates in the ISO 27001 Documentation Toolkit, roughly 80% of the documents can be used to support a SOC 2 certification.
This article will provide you a further explanation about ISO 27001 and SOC2: