Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Data sharing

    It depends on the policy of the company. If your colleague has the right to access data to fulfill his/her tasks you can share data, even via the company email. A data breach is an unauthorized access or disclosure, but if your colleague is authorized to access data, GDPR is not a problem. 

    There may be a problem if your email is not protected with encryption or safe transfers protocols (to be sure you may ask your IT department) Usually business email account are safe enough, it would be different if the email address is a personal one (like Gmail or Yahoo or Hotmail with individual plans because these emails have different safeguards.

    Here an article on how increasing cybersecurity can help with GDPR compliance

    To have a deeper idea of the list of requirements of GDPR you can consider enrolling in our free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

  • Working as an assessor for ISO/IEC 17025

    To become an assessor for an accreditation body would involve firstly having the appropriate knowledge of ISO 17025 and secondly the experience and skills to audit ISO 170025 aboratories.  As a lead assessor you would focus on the management requirements, however as a technical assessor you would audit in your area of technical expertise. I suggest you contact your accreditation body as they will have a recruitment and training requirement.  


    For more general information regarding ISO 17025 auditing see the article ISO 17025 technical internal audit: The basics at https://advisera.com/17025academy/blog/2020/11/10/iso-17025-technical-internal-audit-the-basics/ and the white paper How to perform an internal audit using ISO 19011 at https://info.advisera.com/free-download/how-to-perform-an-internal-audit-using-iso-19011
    Also see some further information at the expert questions, which may be of value,
    ·        

  • FDA

    From your question, I assume that you are outside of the US and that your customer wants to register the product on the US market. FDA registration is the basic requirement for all domestic and foreign establishments that manufacture medical devices in the USA. 

    All foreign Establishments must identify a US FDA Agent while in the registration process. This is a mandatory requirement and without US FDA Agent; the registration cannot be completed.

    Owners or operators of places of business that are involved in the production and distribution of medical devices intended for use in the United States (U.S.) are required to register annually with the FDA. This process is known as establishment registration.

  • ISO 14001 Clause 6.1.4.2b

    Your organization has a list of compliance obligations. If you mention clause 6.1.4 it is because previously there was some problem(s) with compliance obligations and your organization developed a project with a set of actions to be done.

    https://www.screencast.com/users/ccruz5284/folders/Default/media/5acd7089-9316-4ebc-b180-8593293a0d01

    Was that set of actions effective?

    If they were effective there is no problem(s) with compliance obligations today. Something like:

    https://www.screencast.com/users/ccruz5284/folders/Default/media/c0d8152f-4ce9-4e33-b344-520b548ea751

    What is important is that the problem(s) disappeared!

    Now, if you want to follow the standard by the book you need to introduce clause 9.1.2 – Compliance evaluation.

    https://www.screencast.com/users/ccruz5284/folders/Default/media/ed90b6cb-4624-4393-8347-d28d7a099d0d

    In this case, the conclusions of 9.1.2 (compliance evaluation) are used to evaluate effectiveness as in 6.1.4 b)2 (check there the note to see clause 9.1)

    Please consider the following information:

  • Incident Management Procedure

    1 - I really liked the document, I just have a question, is this document based on ISO/IEC 27000:2009? Is there any updated document according to ISO/IEC 27000:2013?

    Please note that the main ISO standard for information security is ISO 27001 (which defines the requirements for the management system and potentially applicable controls), not ISO 27000 (which only defines vocabulary).

    Considering that, our ISO 27001 templates, including the Incident Management Procedure, are based on the ISO 27001:2013, which is the current version of the standard.

    For resources about incident management, please see:

    This material will also help you regarding incident management:

    2 - And also do you have a document which contains the list of incidents, event which can be considered as security incident?

    An incident is a risk that has occurred. Considering that, you can use the following resources to built your own list of potential incidents:

    This material also can help you:

  • List of points needed for making infrastructure GDPR compliment

    It is not clear from your question if you refer to the company infrastructure concerning assets and organization or to the IT infrastructure. In general, there are different levels to consider from an infrastructure point of view.

    The first of all is the privacy by design principle: you need that your infrastructure project considers GDPR requirements from the very beginning (what kind of data are going to be processed, for what purposes, how long data will be processed, who can access, how data will be secured). The Data Processing Impact Assessment process can help you to focus on specific GDPR requirements and design the infrastructure accordingly.

    Then the privacy by default principle: your infrastructure should be settled considering GDPR requirement at its strictest. (i.e., setting data retention periods, defining the process to manage data subjects rights, following the data minimization principle which requires companies to collect and process only personal data which are necessary to reach the purpose for which had been collected). Internal policies and the registry of data processing will help you.

    Adopting security measures refers to all the organizational and technical processes to ensure security. (i.e. internal policies on document access, on teleworking, on bringing your own device policies, or email security protocols, VPN, antivirus, antimalware, and so on.).

    The GDPR leaves up to the controller the choice of the solutions which fit better to its own organization. The balance is among the state of the art, the costs, the kind of personal data involved, and the threat to individual’s rights and freedom arising from data processing which may differ from the brick and mortar shop to the marketing agency which monitors the behavior of customers and run targeted marketing campaigns.

    Here you can find more information to start implementing GDPR:

    To have a deeper idea of the list of requirements of GDPR you can consider enrolling in our free online trainingEU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

  • Compliance with multiple standards

    Deciding to apply for ISO certification is not a technical decision, it is a management decision. Normally, organizations decide to implement ISO 14001 because customers require it, or because being ISO 14001 certified is good for business because of customer requirements.

    Please check the information below about implementation:

  • Accreditation of 17025

    You  asked

    1. I would like to know if all the used samples should be a CRM samples in order to obtain the 17025 accreditation and if we could realise just one repetability reproductibility test on one sample and compare the results with a CRM sample.

    Method Validation and measurement uncertainty involves investigating the effect of both systematic and random errors on the accuracy of results. This involves two components -trueness and precision. Both these are qualitative descriptions, where bias is measured to represent trueness; and a measure of spread of results, such as standard deviation to quantify precision. Precision studies include repeatability, intermediate precision and reproducibility. Typically you will use a matrix matched reference material (RM), reference method or reference value to determine any bias; while test samples or spiked sample blanks (matrix matched) are acceptable for the precision studies. Of course RMs could also be used. It is important, either way,  to represent the entire working range; menaing that low, medium and high range samples should be included.

    You  also asked

    2. we use a Spark Atomic Emission Spectrometry to realise the chemical analysis (zinc and aluminium), there is any criteria in the iso 17025 that obligate us to use an ASTM OR AN iso reference and if yes what should we do if our range of work is out the range mentioned if the standard."

    The laboratory need not use a standard method, unless a client or the sector specify you must. As an ISO 17025 accredited laboratory you need to select suitable methods and prove through method validation and quality control; they are adequate for the purpose. The involves showing that the inhouse or non-standard method achieves the performance required- for example limit of detection, accuracy, along with suitable low-enough measurement uncertainty.  This is where Proficiency testing or interlaboratory studies can be used to evaluate how the nonstandard method performs compared to laboratories who may be using a standard method. 

    For more information, see the ISO 17025 toolkit procedure Test and Calibration Method Procedure, at https://advisera.com/17025academy/documentation/test-and-calibration-method-procedure/; along with the two supporting documents Test Method Development, Verification and Validation Register and Test Method Development, Verification and Validation Record.

  • Offices within scope

    If you have e.g. hundreds of branch offices, then you should specify only the locations of main offices in your ISMS Scope document, and refer to some other document where you list all the branches - this other document could be your internal or public list of branch offices. 

    If you go for the certification, you should consult with your certification body on how to document the locations. 

    Here are some materials that will help you with setting the ISMS scope: 

Page 250-vs-13485 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +