Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Purchase persuasion

    I’m assuming you are referring to convince leadership to support an ISO 27001 implementation.

    Considering that, to improve your chances to get support for an ISO 27001 initiative in your organization you should provide real examples of benefits related to:

    • compliance with regulations regarding data protection, privacy, and IT governance applicable to the organization
    • competitive differential that can be achieved by being capable to demonstrate your organization can protect customer information
    • decrease in costs incurred by information related incidents
    • improving internal organization

    Another important point to be considered is the presentation. For top management, you should avoid using technical jargon (concentrate on business benefits).

    These articles will provide you a further explanation about ISO 27001 benefits and top management:

    These materials will also help you regarding ISO 27001 benefits and top management:

  • ISO 22301 Compliance Matrix

    You can download an explanation of ISO 22301 standard here: Clause-by-clause explanation of ISO 22301 https://info.advisera.com/27001academy/free-download/clause-by-clause-explanation-of-iso-223012008

    In the ISO 27001 & ISO 22301 toolkit you purchased, you will find the document called "List of documents" - it defines which documents are needed for ISO 22301 implementation.

    To simplify this, if you want to implement only ISO 22301 without ISO 27001, you would need to implement documents from these folders, in this very sequence:

    00 Document management
    01 Preparations for the project
    02 Identification of requirements
    05 Risk assessment and treatment
    08 Annex A controls - A.17 Business continuity
    09 Training and awareness
    10 Internal audit
    11 Management review
    12 Corrective actions

  • Writing quality SOP for work infrastructure

    In SOP for infrastructure you need to consider the following:

    • Description of the buildings, workspace, and associated utilities
    • What kind of the process equipment you have (both hardware and software)
    • What kind of supporting service you have
    You need to document requirements for the maintenance activities and with what kind of records you will prove that those maintenance requirements are fulfilled.

    More information on this topic you can find in the following article:

    You can also see how the procedures for infrastructure and records of the infrastructure maintenance in our ISO 13485:2016 documentation toolkit look like:

    • Procedure for Infrastructure and Work Environment https://advisera.com/13485academy/documentation/procedure-for-infrastructure-and-work-environment-iso-13485-2016/
    • Record of Infrastructure Maintenance https://advisera.com/13485academy/documentation/record-of-infrastructure-maintenance-iso-13485-2016/

    • EU GDPR membership and countries outside of the membership

      Concerning the EU GDPR membership and countries outside of the membership;The EU GDPR will be mirrored by the UK-GDPR version - would this be subject to regular reviews?

      The UK chose to mirror the EU GDPR in order to have an adequate decision by the EU Commission and not lose the free flow of data among EU and UK. It is difficult to forecast regular reviews, either on the EU GDPR or the UK GDPR side.We can imagine a coherent evolution for both regulations in order to provide a standard to controllers and processors, but most will depend on how the relationship between the UK and the EU will continue.

      Hypothetically, if the EU were to break up - would the GDPR be able to continue under a unified, but individual country membership?I live in the UK (Scotland) and hope this does not become a reality.

      The EU GDPR is a regulation of the EU and it produces effects in Member State on the basis of the EU Treaties. In the unlikely event of EU break up, the Treaties will not produce their effects anymore and the GDPR will have no effects in the former EU States unless the country mirrors it with internal legislation. The negotiation on the dissolving EU may also end with an international agreement adopting the GDPR as a separate treaty in order to benefit each State of the same regulation. 

      Here you can find more information on the territorial scope of the GDPR

      To have a deeper idea of the list of requirements of GDPR you can consider enrolling in our free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

  • Page 244-vs-13485 of 1128 pages

    Didn’t find an answer?

    Start a new topic and get direct answers from the Expert Advice Community.

    CREATE NEW TOPIC +