Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Yes, our ISO 13485 Documentation toolkit is compliant with 21 CFR part 80. Especially, due to the resolution from fall 2020 where FDA intends to harmonize and modernize the Quality System regulation for medical devices. The revisions will update the existing requirements with the specifications of an international consensus standard for medical device manufacturers, ISO 13485:2016. The revisions are intended to promote the use of more modern risk management principles and reduce regulatory burdens on device manufacturers and importers by harmonizing domestic and international requirements.
More information on this resolution you can find on the following link:
You can see how our ISO 13495:2016 documentation toolkit is structured and preview of it on the following link: https://advisera.com/13485academy/iso-13485-documentation-toolkit/
Firstly, how would the pack apply to Software as a Medical Device (SaMD)? Looking at the preview there is a lot that seems unnecessary as it is focused on the development of a physical product?
Yes, you are right, there are some procedures that you do not need as a manufacturer of Software, like Procedure for sterilization, or work environment. However, all other procedures are applicable for you like for any other manufacturer. I understand that your dilemma is whether to buy the whole toolkit or just some of its parts. For advice on which option is best for you in this case, our sales team will let you know.
Secondly, on the software front where would Software Requirements be specified (e.g SRS Doc) is this kept as an external doc and referenced? On a similar line, what about Software Testing (e.g. unit testing, user testing)? Would you again keep an external record and link to it in the “Record of Software Validation”?
Software Requirements can be set as an external document because it is rather specific for each software.
For any software testing that is necessary to be performed due to IEC 62304:2006 Medical device software — Software life cycle processes, we do not have such a template. This Documentation toolkit is concentrated on the requirements from ISO 13485 and general aspects of MDR. Since there is such a variety of medical devices, it was not possible to prepare templates for all kinds of tests.
If the purpose of processing is the same as that the email was given, you can use the emails. You need to evaluate if your clients can reasonably think that he/she is going to receive those surveys. If the answer is not, you will need consent, otherwise, you can send the NPS survey.
EU GDPR is a general regulation that applies all across Europe. However, EU Member States German Data Protection law has implemented the EU GDPR in some specific fields, like employment, health data, children data, consumer protection, etc. You need to consider the purpose of processing and how you will process those data. Are you asking for information about a particular category of personal data? I.e., is the survey on political opinions or sexual orientation?
You need also to consider if the data collected are anonymized, if they are transferred and if there is any personal profiling or automatic decision.
All these elements will have an impact on how the GDPR will apply to the online survey.
Here you can find more information about German data protection law, GDPR, and the data processing
If you want to learn how to comply with EU GDPR requirements you may consider enrolling in our free training EU GDPR Foundations course: https://advisera.com/training/eu-gdpr-foundations-course//
Intended use is covered in the Technical file Integrated and both in the Clinical evaluation plan and Clinical evaluation report.
Please note that the standard itself states in its introduction that adopting an information security management system (ISMS) is a strategic decision for an organization.
Considering that, using ISO 27001 to implement an ISMS, can be seen as an unfolding of the Information Security (IS) strategy, i.e., as a tactical element (because an ISMS can be implemented using other frameworks like NIST Cyber Security Framework - CSF).
These articles will provide you a further explanation about ISO 27001 application:
These materials will also help you regarding ISO 27001:
The wording to be used is the UK General Data Protection Regulation (UK GDPR). It is enforced by the Data Protection Act 2018.
The name is similar because it comes from the EU Withdrawal Act 2018 which allowed the UK Government to retain EU legislation making some adjustments to adapt to the domestic legal system, so they changed any reference to the EU with reference to the UK.
1. Is there a possibility to integrate ISO 9001 with 20000 or this is not recommendable? If this is not recommendable, how will the usage of the three management systems according to the three standards (9001, 20000, 27001) be facilitated?
ISO 27001, ISO 20000, and ISO 9001 share some common requirements that can be fulfilled by the same documents with minor adjustments (this makes integration highly recommendable), like document control procedure, internal audit, and management review. For requirements specific to each standard, you will need to develop specific documents.
There is no specific procedure for such integration, but broadly speaking you can follow the steps to implement ISO 27001 and use the following material to identify when common requirements can be integrated:
For further information, see:
2. What outcomes could be expected within the certification process provided that we have developed the systems in compliance with the applicable standards:
a. One integrated management system?
b. Separate systems for each of the three standards?
c. One system for 27001 and one system integrating 9001 and 20000, each of them with different scope?
Please note that this answer will depend on your chosen certification body because some of them are able to perform integrated systems certification audits.
Considering that, you need to contact your chosen certification body so you can clarify this information with them.
This article will provide you a further explanation about certification audit:
These materials will also help you regarding certification audit:
1 - Doesn't ISO 27001 have to describe an assessment of confidentiality, integrity and availability? In the risk analysis, I only evaluate according to threat and weakness. These have an effect on confidentiality, integrity and availability.
Please note that ISO 27001 does not prescribe any approach for risk assessment so organizations can choose the method that better suits their needs.
Considering that, if your chosen method complies with the requirements of clause 6.1.2 (Information security risk assessment) it is acceptable by standard’s requirements.
In your case, if you assess threats and weaknesses in terms of loss of confidentiality, integrity, and availability of information, then your approach is compliant with this requirement of the standard.
In case you are looking for a reference for information security risk assessment and treatment, you can consider ISO 27005, the ISO standard for information security risk management.
To see how a risk assessment and treatment methodology compliant with ISO 27001 looks like, please access the free demo of this template: https://advisera.com/27001academy/documentation/Risk-Assessment-and-Risk-Treatment-Methodology/
This article will provide you a further explanation about risk assessment:
These materials will also help you regarding information security risk management:
2 - For example, I find the Business Impact Analysis at the BSI. Don't I have to do this in ISO 27001 as well?
Please note that ISO 27001 does not require Business Impact Analysis to be performed. ISO 27001 core processes are risk assessment and risk treatment. Business Impact Analysis is a requirement for ISO 22301, the ISO standard for the management of business continuity.
For further information, see:
ISO 27001 main clauses do not require organizational context and interested parties to be documented, only that they are taken into account when defining the ISMS framework.
However, in case you find control A.18.1.1 (Identification of applicable legislation and contractual requirements) applicable to your ISMS, you need to document requirements, and for practical purposes, it is best to document requirements together with their respective interested parties.
To see how a list of ISMS requirements compliant with ISO 27001 looks like, see the free demo of this List of Legal, Regulatory, Contractual and Other Requirements template: https://advisera.com/27001academy/documentation/list-of-legal-regulatory-contractual-and-other-requirements/
This article will provide you a further explanation about ISO 27001 mandatory documents:
These articles will provide you a further explanation about organizational context and interested parties:
These materials will also help you regarding organizational context and interested parties: