Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Let me see if I understand your question properly. You are asking what is the budget for the implementation of the ISO 13485 and Medical device regulation 2017/745 in your department. Considering the ISO 134b5, we can only state the approximate costs of the documentation toolkit. We do not know the prices of the notified bodies, especially now when the prices with MDR are much higher.
So, on the following link you can see what Documentation toolkit packages we are offering and what each package contains (how much time with the consultant in 1 & 1 meeting, how many e-mails, and how many documents we can review):
At the end of each page, under the title NEED MORE SUPPORT? you will see the packages.
1. What is the best way to do risk management?
Regardless of the methodology used (ISO 27001 does not prescribe a methodology to be used, only requirements to be fulfilled, so organizations are free to use the approach that better suits their needs), the best way to do risk management is by involving the people which works directly with the processes and information to be protected, because they are the best source of information to help identify and analyze the risks, and also during daily operations they can provide a faster response in case of new risks arise or incidents occur.
This article will provide you a further explanation about risk management:
These materials will also help you regarding risk management:
2. How do I raise awareness for information security?
Common approaches for information security awareness are training sessions, the use of newsletters, the use of video tutorials, and meetings between management and staff, which should be performed on a regular basis.
Regarding content, please note that you will have different publics with different interests:
These articles will provide you a further explanation about awareness:
These materials will also help you regarding awareness:
3. How to setup an ISMS which is used with excitement? How do I get colleagues all across the organisation to not only understand the necessity, but also the advantages of an ISMS for their daily work?
The most effective ways to set up an ISMS to get the engagement of people are:
For further information, see:
I’m assuming that by “contingent workers” you mean outsourced or non-permanent personnel who are hired on a per-project basis (e.g., freelancers, independent contractors, consultants, etc.).
Considering that, and ISO 27000, which defines the vocabulary for information security management systems compliant to ISO 27001, you can use the concept of “outsourced organization”.
For ISO 27000:
Please also note that you can also use other terms like contractors, external parties, because they are present in ISO management standards, although there is no formal definition for these terms in ISO glossaries.
As you know, job descriptions should be related to the job for which it is responsible. The main issues to be added according to the qualification of the personnel doing the job and the category of the employee are given below.
As a note; In addition, IATF 16949: 2016, customer-specific requirements and customer special characteristics training should be given to employees.
This decision depends primarily on who is the holder of the product, whose name will be on the product as the manufacturer.
If you are a manufacturer (license), then the manufacturer is expected to have ISO 13485 implemented. According to ISO 13485, when the manufacturer (license holder) outsources any part of the production process, this part of the process is still the manufacturer's responsibility. This means that regardless of the fact that you have outsourced that part of the production, that production must also be carried out in accordance with the requirements of ISO 13485. It doesn't matter if they will be ISO 13485 certified, or if you will make all this documentation as part of your ISO 13485 quality system. It all depends on how you agree. There must be a Quality Agreement between you and that company in which all mutual responsibilities will be described. Be prepared that regardless of your mutual agreement and the fact whether they are certified or not, there is a possibility that during your audit by a certification body, the auditor requires that an audit be conducted in that outsourced company as well.
For more information on this topic, please see the following article:
You can see how we designed a Quality agreement with the subcontractor in our ISO 13485:2016 Documentation toolkit:
Yes, you need to have the List of internal documents. The purpose of this list is to catalogize all documents that have been created for the management system. It doesn't matter if they are in electronic or paper form. This list tells you which documents are currently in use, which version of that document is currently active, and since when.
External documents are all documents that come into your company and are necessary for your work. This usually includes laws and regulations, contracts with suppliers and customers, and similar.
For more information on this subject, please see the following articles:
Medical devices that want to be put on the EU market must be prepared according to the requirements from the Medical device regulation (MDR, 2017/745). In this regulation are requirements both how the medical device must be designed, constructed, produced, and tested to prove its safety and performance.
For all medical device manufacturers, it is mandatory to have implemented a quality management system (Article 10). Also, manufacturers must prove compliance with a list of harmonized standards that are published by the European Commission in the Official Journal (Article 8). There are more than 300 different standards on that list, but the only standard that covers the quality management list is ISO 13485:2016. That is why it is expected for the manufacturers on the EU market to have implemented ISO 13485:2016.
Besides the quality management system, each medical device must have prepared technical documentation according to Annex 2 and Annex 3 of the MDR.
In ISO 13485:2016 there is requirement 7.1 Planning of product realization that asks form the manufacturers to document one or more processes for risk management in the product realization. ISO 14971:2019 is the standard that covers requirements regarding risk management, especially for medical devices.
The following links are for future readings:
Please note that if all employees are accessing from home the same services and company-owned hardware they accessed when they worked in the company, then the ISMS scope does not need to be changed.
The use of personal devices to access company’s services and owned hardware from home can be handled by means of identification of relevant risks related to the use of personal devices and to remote access, which can be treated by means of controls such as A.6.2.1 Mobile device policy, A.6.2.2 Teleworking, and A.13.2.1 Information transfer policies and procedures.
The use of company’s owned hardware by employees from their homes can be handled by means of identification of relevant risks related to telework, which can be treated by means of controls such as A.6.2.1 Mobile device policy, A.6.2.2 Teleworking, and A.11.2.6 Security of equipment and assets off-premises
To see how policies covering these controls look like, please take a look at these free demos:
These articles will provide you a further explanation about teleworking:
These materials will also help you regarding teleworking:
1 - Clauses 4.1 and 4.2, are they based on the organization as a whole, rather than the department in scope? It seems like even clause 4.1 & 2 is a huge task, and identifies things that aren’t covered by the IT department. It seems odd to identify these issues as an organization, only to not cover them as they aren’t covered by our scope.
Answer: Please note that for clauses 4.1 and 4.2 you need to consider the organization as a whole because if you consider only your intended scope in terms of the IT department, you may miss elements that may impact the organization’s purpose, intended Information Security Management System (ISMS) outcomes, and/or interested parties and their requirements, but are not directly related to your intended scope.
For example, for a web store, the purpose can be selling products, the intended outcomes for the ISMS can be the protection of data related to buyers and products, and an interested party may sales department. In this context, if the web store’s sales department needs to keep part of buyers’ data out of IT systems for some reason (e.g., regulation or contract), and the IT department is not aware of this situation, the scope may be incorrectly defined (e.g., if you want to keep only the IT department in the ISMS scope, then you need to state that buyers’ data that exists out of IT systems are out of scope).
For further information, see:
- How to define context of the organization according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-define-context-of-the-organization-according-to-iso-27001/
- How to identify interested parties according to ISO 27001 and ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/
2 - Also, in terms of interested parties, would our students count? If so, would it be over the age of consent in GDRP terms of, or all ages?
Answer: This answer will depend on what you consider for the organization’s purpose and intended ISMS outcomes.
For example, if the organization’s purpose and intended ISMS outcomes are related to education or customer data, then students should be considered as interested parties. Regarding GDPR, because the related information can be considered PII, the information of students of all ages must be protected if you need to comply with GDPR. What will happen is that for students under the age of consent you will need to consider additional protections.
3 - Also, do you know if any schools or multi-academy trusts in the *** have achieved ISO27001? If not, are there any resources or information you could point me too that are focused on educational establishments that I could gain some guidance from?
Answer: We are not aware of specifics on certifications in this industry in the country you mentioned. From 2019 ISO Survey (https://www.iso.org/the-iso-survey.html and https://isotc.iso.org/livelink/livelink?func=ll&objId=21414015&objAction=Open&nexturl=%2Flivelink%2Flivelink%3Ffunc%3Dll%26objId%3D18808772%26objAction%3Dbrowse%26viewType%3D1) you can see the number of ISO 27001 certifications issued for this industry. To know about specifics, you need to contact the certification bodies in your country and ask for this information.
Some references you may find useful:
- https://www.gov.uk/government/publications/school-and-college-security/school-and-college-security
- https://www.beaming.co.uk/insights/cybersecurity-safeguarding-approach-schools/
- https://www.ncsc.gov.uk/information/resources-for-schools
4 - Finally, (apologies this may be oddly worded!) but as the IT department, does that just cover the processes/information used by them, or does it also mean the services/equipment the IT department provides for others to use? Such as require 2 factor authentication for staff in other departments to login to a service?
We’re also going to purchase the documentation and support pack with you, but our ordering process can take a little while, so just wanted to get these couple of questions out in advance!
Answer: Please note that you first need to consider if the protection of these services/equipment the IT department provides for others to use is relevant to your information security objectives. If so, you need to consider them as part of the scope of the IT department, because the implementation of controls will be focused only within the scope.
These articles will provide you a further explanation about scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
These materials will also help you regarding scope definition:
- How to set the ISMS scope according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/how-to-set-the-isms-scope-according-to-iso-27001-free-webinar-on-demand/
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
If your service is clearly defined and there is no innovation in it then you can consider clause 8.3 as non-applicable.
The following material will provide you more information about exclusions: