Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
I think OCP stands for Operational Control Procedures. So, OCP in shop floor seems to be Operational Control Procedures used in shop floor to improve environmental aspects management and control. For example, Operational Control Procedures about segregating wastes correctly, or about good practices to minimize energy or water consumption. OCP Control Method can be, I guess, about procedure control: approval, distribution, updating, obsolete removal.
You can find more information below:
Grazie
We are not experts in this specific industry, but for small and midsized business all over the world, this template has helped them to identify assets for their ISO 27001 ISMSs:
This article will provide you a further explanation about managing assets:
These materials will also help you regarding managing assets:
ISO 27001 does not prescribe responsibilities about backup, so organizations are free to define them as best fulfill their needs.
Considering that, for defining the responsibilities for the backup process, you should analyze potential risks (e.g., lack of knowledge, human error, sabotage, etc.), and applicable legal requirements (e.g., laws, regulations, and contracts), to identify how responsibilities should be defined.
For example, through risk analysis, you may find that there are no relevant risks if the DBA is responsible for taking and storing the Backup, but you may have a contract with a client that defines a different role to be responsible for the backup process (e.g., the backup should be performed and managed by a system administrator).
To see how a backup policy compliant with ISO 27001 looks like, please access the demo template at this link: https://advisera.com/27001academy/documentation/backup-policy/
These articles will provide you a further explanation about defining responsibilities:
These materials will also help you regarding the definition of responsibilities:
Existem duas formas comuns de se formalizar a segregação de funções, dependendo da forma como a organização gerencia seus processos:
Para mais informações sobre segregação de funções, leia:
Este material também pode ajudar a entender como implementar a segregação de funções:
1 - The certification body has set 2 days for surveillance audit. what is cost for the second and third year and what is the cost of recertification (Roughly)?
There is no standard value for surveillance and recertification cost, so this information you need to ask directly to your certification body. Normally contracts with certification bodies are set considering a full certification cycle (i.e., certification audit and surveillance audits), so this information about costs may be included in the contract clauses (the recertification cost is similar to the certification cost). For comparison, you may use quotations from other certification bodies.
For further information, see this material:
2 - What happens if for some reason the organization didn't pay for the annual subscription for two years for example and then wanted to re-certify after that.
First is important to note that there is no such thing as an annual subscription for certification bodies. To keep your certification, you need to undergo surveillance audits at scheduled times, or your certification will be suspended, and in case of prolonged delay (that will be less than two years), the certification will be canceled, and you will need to undergo all the certification process again.
3 - Is there any hidden cost in the process of yearly audit and recertification audit?
Some hidden costs you need to pay attention are related to the auditor’s travel costs (if he or she is out of your town), as the client will be responsible for his or her lodging, and the auditors’ fee related to his or her experience in the client's industry because their feedback is considered more valuable.
For further information, see:
No, it is not in the standard that any aspect/impact that has a legal requirement is automatically significant.
Please check this picture:
If an environmental aspect has compliance obligations and they do not comply the aspect is significant, but if they are satisfied then it is up to your evaluation criteria to determine if they are or not significant.
Please check this information below with more detailed answers:
Please note that while control A.11.2.8 aims at equipment (e.g., computers and mobile devices), control A.11.2.9 has a wider coverage, including papers, removable storage media, and other equipment normally found on workstations (e.g., photocopiers).
In a sense, you can think that control A.11.2.8 can be used to implement a part of control A.11.2.9.
This article will provide you a further explanation about clear desk policy and clear screen policy:
This material will also help you regarding clear desk policy and clear screen policy:
No mundo ISO, os requisitos / documentos obrigatórios estão relacionados às palavras “deve” ou “deverá”, enquanto os requisitos / documentos não obrigatórios estão relacionados às palavras “pode” ou “deveria”. Os documentos e registros obrigatórios para cumprir as cláusulas das seções principais da norma (seções 4 a 10) são:
Outra situação é que alguns documentos são necessários para cumprir controles que são obrigatórios se pelo menos uma dessas situações acontecer:
Se nenhuma das condições acima acontecer, não há necessidade de implementar um documento relacionado a esse controle.
Além dos documentos para cumprimento das cláusulas das seções principais, sem uma avaliação detalhada de uma organização, não é possível definir quantos documentos uma organização teria e quais seriam um exagero.
Estes artigos fornecerão mais explicações sobre os documentos ISO 27001 e seleção de controles:
No, it is not a requirement to engage an external consultant to help develop and implement a management system.
That is precisely one of the reasons for the existence of Advisera, to help organizations to work without the need of a consultant. Please check this article - Do you really need a consultant for implementation of ISO 14001? - https://advisera.com/14001academy/blog/2019/02/28/do-you-really-need-a-consultant-for-implementation-of-iso-14001/
Please consider our courses to help practitioners, you can enroll for free: