Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Is ISO 14001 really the best certification for your particular case?
Everything depends on what your organization need.
Let me try to explain, as a waste management company, I believe your organization has some kind of official qualification issued by a particular relevant authority. With that official qualification a potential client may look to your organization and think something like “OK, this company is officially qualified to do the job of collecting waste”. The point is, why should a particular potential client choose your company among several waste management companies all equally qualified by the same or equivalent particular relevant authority?
What kind of benefits is your organization looking for? Will your brand benefit from being ISO 14001 certified? And from being ISO 9001 certified? If your company is looking for cost reduction, higher efficiency, perhaps ISO 9001 can be recommended. If your company is looking for improving image among community and the job market perhaps even ISO 45001 certification can be recommended.
If your organization decides to go for ISO 14001, basically you have to determine how your organization interacts with the environment while collecting and managing waste. You start by determining the environmental aspects and impacts, the how your organization interacts with the environment:
Each one of these interaction vectors’ is a specific type of environmental aspect.
So, for each type of environmental aspect check where they appear, or can appear, in your organization’s activities products and services. Consider operation under normal, abnormal and emergency situation.
You have also to determine the legislation and regulation applicable to your organization (compliance obligations). From there you determine priorities for improvement:
Them you have to define an environmental policy and objectives. From there, it is implementation by developing action plans to improve the interaction with the environment.
Then, perform an internal audit and the management review. There you can decide if your organization is ready for a certification audit.
You can audit the entire organization or site by site. This should be discussed with potential certification bodies before starting the implementation project, sometimes they have different opinions.
Perhaps the following links can be useful:
First is important to note that the context of the organization is any internal or external factor that can affect the ISMS.
Considering that, concrete examples of elements of organizational context are:
Based on these you can identify elements that can help you understand how information security must be considered.
This article will provide you a further explanation about the Context of the organization for 27001:
These materials will also help you regarding the Context of the organization for 27001:
1. Is there a rework procedure in the tool kit? I did not see it in there and I believe it is an ISO requirement for clause 8.3.4. Thank you.
Rework is covered in the 15_Procedure_for_Control_of_Non_Conforming_Products_Premium_EN in section 3.4 Handling non-conforming product.
For more information on how to handle non-conforming products, please see the following article:
2. I have a question about the clinical evaluation requirement. What exactly is needed for media manufacturer class 1 medical device? In looking at the documents in the toolkit it I am not sure if it applies.
All requirements and topics that are covered in the folder Clinical evaluation is necessary for manufacturers of class I medical devices. So you need to make literature research about your product, make an equivalence with an existing product on the market, and make a report as described in annexes 1, 2, 3, and 4.
More information on the clinical evaluation you can find in the following articles in the MDR:
If your medical device is Class I, then it does not require the involvement of the notify body. In that case, you need to prepare the Self-declaration of conformity and technical file according to the Annex II Technical documentation and Annex III Technical documentation on Post-market surveillance. However, you need to contact the notify body in regards to the certification of ISO 13485:2016.
Which elements must be in the Declaration of conformity, you can find in Annex 4 – EU Declaration of conformity.
For more information, see:
The content of the Training & Awareness Plan needs to include needed training and awareness activities for all personnel included in the ISMS scope, not only the Internal Audit Team.
For example, it can include basic training for regular final users and at the same time advanced security techniques for IT and SW development personnel.
This article will provide you a further explanation about awareness and training:
This material will also help you regarding awareness and training:
By your question, I’m assuming that control A.13.2.4 Confidentiality or nondisclosure agreements are applicable to your scenario.
Considering that, the answer to this question will depend on the laws and regulations applicable to your jurisdiction, so you should consider hiring local legal expert advice.
For example, some laws and regulations may require an NDA only from the outsourcer organization, or that this NDA must be extended to individual NDAs to their employees.
This article may provide you a start on applicable laws and regulations, but note that these references depend on the contributions of our reader, and some of them can be outdated:
For further information, see:
If you want to implement an environmental management system (EMS) perhaps the following steps could be useful for an organization:
Perhaps the following links can be useful:
I’m assuming you are referring to personal certifications
Considering that, the order on which to pursue these certifications will depend on your needs:
Since you mentioned IT risk and compliance, the specific field of certification for you would be audit:
These articles will provide you a further explanation about ISO 27001 and ISO 20000 personal audit certifications:
For the ISO 27001 Lead Auditor Course, please see:
Please note that it is our policy not to make recommendations about technologies, but broadly speaking most solutions used in cloud environments (e.g., virtual machines and lead balancers, etc.) now have policy enforcement and activities monitoring capabilities, so you need to check with your provider which capabilities it can provide to you and if these capabilities are enough to fulfill your needs (based on the results of risk assessment and applicable legal requirements).
For further information, see:
Please note that documents describe rules to be followed and/or actions to be performed, whereas records evidence actions performed and/or results achieved. Additionally, documents can be updated, while records cannot (at most they can be complemented, i.e., new information can be added, but the original information cannot be changed).
Considering that, Risk Assessments are records (they evidence that risk assessment was performed and the assessed risks), as well as Risk Treatment Plans (they evidence which actions were performed to treat risks and achieved results). Since records cannot be updated, it only makes sense to apply version control on them if they can be complemented (in this case the information for version control can be the date of the last included complement). However, they need to have ways to be uniquely identified.
As records, they indeed need to have specific retention time, based on business and legal requirements.
This article will provide you a further explanation about record management:
These materials will also help you regarding record management:
ISO 9001:2015 sets no mandatory requirements to use performance indicators of an employee. So, if your organization wants to use them it is free to determine them. I can give some suggestions, linking performance of an employee to:
Performance of process indicators affected by the employee (process indicators are mandatory according to ISO 9001:2015)
Results of competence evaluation
The following material will provide you more information: