Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
By the phases you mentioned, I´m assuming you are looking for documents for a Business Continuity Management System.
Considering that, to see how a BCP and related procedures compliant with ISO 22301 looks like, I suggest you take a look at these template demos:
- Business Continuity Plan https://advisera.com/27001academy/documentation/business-continuity-plan/
- Incident Response Plan https://advisera.com/27001academy/documentation/incident-response-plan/
- Transportation Plan https://advisera.com/27001academy/documentation/transportation-plan/
- Disaster Recovery Plan https://advisera.com/27001academy/documentation/disaster-recovery-plan/
- Activity Recovery Plan https://advisera.com/27001academy/documentation/activity-recovery-plan/
To make sure you are in the right implementation path, I suggest you to take a look at this article:
- 17 steps for implementing ISO 22301 https://advisera.com/27001academy/knowledgebase/17-steps-for-implementing-iso-22301/22301/iso-22301/
To see how documents complaint with ISO 22301 looks like, please take a look at the free demo of our ISO 223001 documentation toolkit: https://advisera.com/27001academy/iso22301-documentation-toolkit/
These articles will provide you a further explanation about ISO 22301 and how to develop e BCP and related procedures:
- What is ISO 22301 https://advisera.com/27001academy/what-is-iso-22301/
- Business continuity plan: How to structure it according to ISO 22301 https://advisera.com/27001academy/knowledgebase/business-continuity-plan-how-to-structure-it-according-to-iso-22301/
- How to write business continuity plans? https://advisera.com/27001academy/blog/2010/04/08/how-to-write-business-continuity-plans/
These materials will also help you regarding ISO 22301:
- Writing a business continuity plan according to ISO 22301 [free webinar on demand] https://advisera.com/27001academy/webinar/writing-a-business-continuity-plan-according-to-iso-22301-free-webinar-on-demand/
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/
When I have to integrate several management systems I follow the following path. First, I look for the backbone on which to build the building. Normally, it is ISO 9001. Why? Because organizations exist to serve someone in the outside world, a customer, a client, an interested party. So, based on the process approach I draw the system between clients with needs and expectations and clients served. I draw what I call the “Cristiano Ronaldo of the business” in your case would be something from going from eggs to chicks, from chicks to chickens, from chickens to portions, from orders received to orders delivered. Then I draw all the support processes (related to training, purchasing, maintenance, …)
While serving your clients your organization interacts with the environment. What are your environmental aspects and impacts? What are the compliance obligations? Does your organization need to develop new practices that should be integrated with your working practices?
While serving your clients what are the risks and dangers for your employees? What are the compliance obligations? Does your organization need to develop new practices that should be integrated with your working practices?
While working in your organization people don’t wear four hats according to the mindset (quality hat, environmental hat, health and safety hat, and food safety hat). They do their job, and while doing their job they act according to the different requirements simultaneously.
The following material will provide you information about management systems integration:
The implementation duration and costs depend on many variables (e.g., size and complexity of the scope, financial resources, and expertise available, etc.), but for very small and small-sized business generally is possible to implement ISO 27001 within 3 months.
For more information about the time needed for the implementation, I suggest you see this article:
Regarding costs, what I can tell you are some cost issues you should consider:
These materials can provide you more information:
Please note that a travel agency works with several information of customers that need to be protected (e.g.: names and addresses, travel routes, etc.). Criminals with access to this information can use them to perpetrate crimes (house robbery, identity thief, etc.).
Considering that, an ISO 27001 certification can be relevant for a travel agency by potentializing some benefits, such as:
This article will provide you a further explanation about ISO 27001 benefits:
These materials will also help you regarding ISO 27001 benefits:
Your assumption is correct. Since 2012 all ISO management systems share the same basic structure, which makes it easier to integrate them.
This article will provide you a further explanation about ISO 27001 structure and integration:
These materials will also help you regarding ISO 27001:
No, the medical mask does not require sterilization. It depends on the manufacturer what kind of mask want to put on the market, what are the customer requirements (for example hospitals) and so on.
Applicable standards for the mask you can find on the following link:
A company can have implemented ISO 13485 only for the Desing and development. In that case, some requirements will be stated as „non-applicable“, like: 7.5.3 Installation activities, 7.5.4. Service activities, 7.5.5 Particular requirements for sterile medical devices, 7.5.7 Particular requirements for validation of processes for sterilization and sterile barrier systems. The main procedure, in that case, will be Desing and development, which will replace the procedure for production and service provision.
For more information, please see the following article:
You can see how we have prepared the Design and development procedure in our ISO 13485:2016 Documentation toolkit:
"Firstly, I want to thank you so much for providing such help. It is really valuable.I would like to ask you about the following.Current situation:
I have a mobile application (Notes & todo lists) running on Android that stores & processes data.- This data could be personal or personally identifiable.- The app stores the data on the user's device in the app folder that is accessible by the user only.- We do not collect or store any data in the cloud.- The app also has google ads. Users are informed and have to give consent before using the app- There is no requirement for sign up or requests for email, name, passwords, financial information etc.- Data stored (because it is a notes app) can be personal interests, schedules, names, numbers etc.
What I would like to know:
Considering the app above:If I do not encrypt the data stored in the device am I in breach of GDPR?
The GDPR lets the controller decide if security measures as appropriate to the data processing or not, so encryption can be a good security measure and it is recommended but it is non-mandatory. Article 32 GDPR states that the controller needs to consider the risks for freedom and rights of users, the state of art, the costs of implementation, the nature, scope, and purpose of processing and to balance it in order to verify the appropriate security measure (i.e., the app may not encrypt data because are stored on user device but request two-factor authentication or access with fingerprint).
Do I need to appoint an EU Data Protection representative?
If you are not located in the EU yes you need to appoint an EU representative, as required by Article 27 GDPR.
Does the GDPR really apply to this application since there is no collection of data and only the user has access to it?Thank you so much for your help."
GDPR applies to data processing which is defined by Article 4 GDPR “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;”
Your app records and makes available personal data to the user so it processes personal data, then your company probably acquires data of users who downloaded the app, their device numbers or email or Google Play account, in fact, you ask consent for processing data, the GDPR will apply even if your app does not transmit personal data of your user you still process other personal data (device number, email, google accounts, etc.).
Here you can find more information on GDPR implementation:
If you need to understand how to process personal data under GDPR, you can consider enrolling in our free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
Your organization as the client has the authority to determine qualification requirements for suppliers. If they want to serve your organization, they have to comply.
However, there is nothing in ISO 9001:2015 requiring that suppliers must be ISO 9001 and IATF-16949 certified.
The following material will provide you more information:
Has any requirements for the auditor for conducting an internal audit and how to ensure the auditor conduction audit is competent?
Answer:
Each organization has the authority to determine the competence requirements of its internal auditors. Normally, organizations consider that internal auditors should have knowledge of the audit criteria (ISO 9001:2015 in this case) and should have training in internal audits. You can even decide that an auditor has to study a book on audits or attend an online course and do an in-house exam. Internal auditor competence requirements can be established in a job description, for example. Audit competence or audit effectiveness can be measured, for example by comparing internal audit results with external audit results.
Is it any requirements for attending internal audit training and getting certificates?
If have please give a reference on İSO 19011.
Answer:
No, there is no formal requirements for choosing people to attend internal audit training. Anyone can be internal auditor, unless psychologically they do not want to do it.
The following material will provide you information about internal auditors: