Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
ISO 9001:2015 has no mandatory requirement for the existence of manual or procedures. It is up to each organization to decide if a manual is useful and what should be its content.
I recommend organizations to have a quality manual, but it is just a recommendation. Please check this article about mandatory documentation - List of mandatory documents required by ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/
The following material will provide you information about the quality manual:
Usually, implementing anything without control lead, sooner or later, into waste of time and money.
IT projects (including ITIL/ISO 20000 implementation) usually require interfacing between systems (i.e. technological solution, as a basis for IT services), processes, roles, etc. Without a decent plan and management, implemented solutions will run in isolation without expected benefits. Additionally, maintenance will be complex, data will be duplicated, processes will be chaotic…
Here are few articles that can give you more information:
Ready, steady… go – Starting ITIL implementation https://advisera.com/20000academy/blog/2014/06/10/ready-steady-go-starting-itil-implementation/
ITIL and ISO 20000 – What does Project Management have to do with it? https://advisera.com/20000academy/blog/2015/03/31/itil-and-iso-20000-what-does-project-management-have-to-do-with-it/
How to use ITIL to avoid 50% of IT project failures https://advisera.com/20000academy/blog/2015/05/12/how-to-use-itil-to-avoid-50-of-it-project-failures/
The main steps for implementing a quality management system are the same. However, the larger an organization, the more complex, the more vertical it is. So, normally, larger organizations require more formalization and more training. For example, a larger organization may need documented procedures for some activities that another smaller organization, in the same economic sector, may decide to not formalize in a documented procedure. A smaller organization may use a All-Hands Meeting to communicate a message to everybody, a larger organization may need to use a newsletter, a video or other scalable option.
About implementing ISO 9001:2015 perhaps this free webinar on demand, articles and book can help you:
Protocols are a set of rules and standards stablished by an external regulating body, whereas SOPs, are the methods used to achieve or comply with those protocols. Protocols do not necessary have an SOP and also, you can develop a SOP regardless of whether there is a protocol that needs to be complied. In addition, protocols are goal-oriented or problem-oriented, since they describe what has to be achieved while SOPs are the practical instructions that an individual needs to follow to achieve that goal. For instance, a protocol may indicate the accuracy that a process requires, meanwhile the SOP is the procedure a lab uses to conduct the process.
For more information about protocols and SOPs see the following materials:
- Enroll for free in the course – ISO 9001:2015 Foundations Course - https://advisera.com/training/iso-9001-foundations-course/
- Book - Discover ISO 9001:2015 Through Practical Examples - https://advisera.com/books/discover-iso-9001-2015-through-practical-examples/
Para que la alta dirección se comprometa con cumplir los requisitos de ISO 9001:2015 le recomiendo que por un lado presente los beneficios que brinda la implementación de ISO 9001:2015 a la organización y por otro que hable el lenguaje que entiende la alta dirección.
Puede traducir los requisitos de ISO 9001 a un lenguaje más sencillo que contenga un sesgo más empresarial. Por ejemplo, en vez de hablar de documentos obsoletos, hable a la dirección de pérdida de reputación que podría producirse si la organización emplea documentos que no están actualizados. O en vez de hablar de no conformidades dentro del control de calidad, se hable de pérdida de dinero.
Aunque el dinero se trata de un lenguaje poderoso en la alta dirección también les interesa temas como la participación del mercado, los clientes ganados o perdidos, el margen de beneficios, la diferenciación de la competencia así como los riesgos a evitar y las oportunidades a aprovechar.
Para más información como sobre comprometer a la alta dirección vea los siguientes materiales:
- Seis beneficios clave de la implemenntación de ISO 9001: https://advisera.com/9001academy/pt-br/kit-de-documentacao-da-iso-9001/nowledgebase/seis-beneficios-clave-de-la-implementacion-de-iso-9001/
- To what extent should top management be involved in your QMS: https://advisera.com/9001academy/blog/2016/11/22/to-what-extent-should-top-management-be-involved-in-your-qms/
- ISO 9001 top management audit: how to perform it successfully: https://advisera.com/9001academy/blog/2019/05/15/iso-9001-top-management-audit-how-to-perform-it-successfully/
- Presentación - Why ISO 9001:2015 awareness presentation: https://info.advisera.com/9001academy/free-download/why-iso-9001-2015-awareness-presentation
- Curso gratuito en línea - Curso de Fundamentos ISO 9001:2015 - https://advisera.com/es/formacion/curso-fundamentos-iso-9001/
- Libro - Discover ISO 9001:2015 Through Practical Examples - https://advisera.com/books/discover-iso-9001-2015-through-practical-examples/
1 - Can we take the ISO 27001 certificate with a master's degree in general management in organizational strategy and 4 months of experience as a business intelligence consultant?
ISO certifications for persons do not require previous competences or experiences, so it is possible to take them with this current background.
There are several different ISO 27001 personal certifications available, and you have to choose what is most appropriate for you:
These materials will help you:
2 - Can we work remotely as an aid in audit or iso 27000 implementation projects under these conditions?
Remote work is possible for audit and implementation projects, depending on the scope (some activities like audit or implementation of some physical controls only can be made in loco). You should define these situations with your customers.
Regarding consultancy services, besides information security-related certifications, you also need to consider competencies related to project management, and accumulate experience, either working with another consultant or performing activities in the information security field for a company. You also should consider the Lead Implementer certification.
For more information, see: