Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Statement of conformity

    Simply stated, measurement uncertainty cannot be ignored when it comes to conformity statements reported under accreditation. During contract review a laboratory must confirm with the customer that it can meet the requirements for accuracy and are able to perform the measurements. The issue of Measurement uncertainty must be discussed and evaluated to avoid the risk of false pass (acceptance), as the uncertainty could result in the measurement reported being larger than the specification, due to the uncertainty component,

    If the expanded measurement uncertainty is smaller than the accuracy requirements of the regulators or client, then the agreed decision rule could, for example, be: “PASS” indicates that the test method conforms with the accuracy requirements of the testing standard. The expanded measurement uncertainty (k = 2 ,95 %  probability) is not greater than the accuracy requirements defined as <value>. You could also refer to a table.

    For more information, refer to the ILAC guideline G8:09/2019 Guidelines on Decision Rules and Statements of Conformity available for download from https://ilac.org/publications-and-resources/ilac-guidance-series/ and refer to your accreditation body requirements. A good example of a guideline from an accreditation body is the UKAS Lab 48 Decision Rules and Statements of Conformity, available from hhttps://www.ukas.com/resources/publications/laboratory-accreditation/

  • ISO 27017

    1 - They've asked if there's any way they can be certified, considering they're already ISO 27001 certified. I've been researching the topic for a while and i've only seen this type of compliance statement being given to Cloud service providers.

    Answer: First it is important to note that ISO 27017 is not a certifiable standard (some certification bodies "certify" against ISO 27017, but only during an ISO 27001 or ISO 27701 certification processes, because ISO 27001 and ISO 27701 are the only certifiable standards in the ISO 27000 series).

    Considering that, to be "certified" against ISO 27017 all an organization needs to do is to include the applicable controls related to ISO 27017 in its Statement of Applicability (of course, as a result of performing the risk assessment and risk treatment process) and implement the risk treatment plan also considering the ISO 27017 controls.

    These articles can provide further information:
    - What is ISO 27001 https://advisera.com/27001academy/what-is-iso-27001/
    - Relationship between ISO 27701, ISO 27001, and ISO 27002 https://advisera.com/27001academy/blog/2019/12/10/relationship-between-iso-27701-iso-27001-and-iso-27002/
    - ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/


    2 - I wanted to ask if you have seen this attestation being requested and given to any company that is only a cloud consumer.

    Thank you in advance for your attention!

    Answer: Please note that ISO 27017 also has controls applicable considering the point of view of the customer, so cloud consumers also can request to be “certified” as explained in the previous question.

  • Monitoring and Measurement / Environmental Controls

    Yes, you can reduce the number of sampling sites. It is recommended that you perform validation of that process, where you will analyze all data that you have collected so far and explain why is it justified to reduce the number of sampling sites.

    For more information, please see the following link:

Page 199-vs-13485 of 1128 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +