Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
This catalog included in the toolkit is generally enough for most of our customers, but if you need additional threats and vulnerabilities to you risk assessment, I suggest you see this document from Enisa, which shows a set of materials with lists of threats and vulnerabilities:
First of all, we apologize for this situation. This article was written for the 2005 version of the standard.
Although version 2005 of ISO 27001, in fact, prescribed four mandatory procedures, its current version does not prescribe them anymore (although some organizations keep/elaborate them as good practice). These currently non-mandatory procedures are: procedure for document and record control, internal audit procedure, corrective action procedure, and management review procedure.
This article will provide you a further explanation about all mandatory documents and records for ISO 27001:
When working with organizations I start with what I think is the most basic rating system:
Does it comply with compliance obligations? If no, it is significant. If yes, apply a second test based on frequency/probability versus severity.
Where L stands for Low, M stands for Medium and H stands for High.
Please check this information below with more detailed answers:
First is important to note that ISO 27001 does not prescribe how to document responsibilities in an ISMS, so organizations are free to document them the best they fit their needs.
Considering that, there are two common ways:
These articles will provide you a further explanation about documenting responsibilities and segregation of functions:
Em primeiro lugar, é importante observar que a ISO 27001 não prescreve como documentar responsabilidades em um SGSI, portanto, as organizações são livres para documentá-las da melhor forma que atendam às suas necessidades.
Considerando isso, existem duas maneiras comuns:
Estes artigos fornecerão mais explicações sobre a documentação de responsabilidades e segregação de funções:
ISO 9001 is a standard developed for organizations not for individuals. Nevertheless, it has benefits for employees. Please, check this article - What are the benefits of ISO 9001 for your employees? - https://advisera.com/9001academy/blog/2016/06/14/what-are-the-benefits-of-iso-9001-for-your-employees/
You can find more information below:
Implementing a quality management system (QMS) for a consulting firm implies being very pragmatic and knowledgeable about ISO 9001:2015. Now the standard is less and less bureaucratic, it is up to each organization the task to design, develop and implement its QMS.
Setup a project sponsor, a project manager and a project team. Determine the scope of the QMS. Your organization may provide consultancy services in several areas, but only want to certify one or two services. Ensure top management support, get training and as a first step perform a Gap analysis, to determine the amount of work to be done - comparing what your organization already has in place versus ISO 9001:2015 requirements. From that GAP Analysis you can develop your Project Plan, listing what needs to be done, by whom, until when.
Then, an important step is to design a model of how your organization work as a set of interrelated processes. For example:
Decide how to describe and monitor those processes.
From there it is implementation in order to close the gaps found. Then, perform an internal audit and the management review. There you can decide if your organization is ready for a certification audit.
This is a very short description of the journey but below you can find more detailed information:
Para definir los procesos en ISO 14001 debe de tener en cuenta las etapas del ciclo de vida de sus productos o servicios, tanto aquellos que puede controlar como aquellos en los que puede influir, para poder identificar todos los aspectos ambientales asociados a los procesos y establecer los controles operacionales necesarios.
El diagrama de tortuga por un lado emplea el caparazón para nombrar el proceso, y por otro, utiliza las cuatro patas de la tortuga para representar cuatro preguntas sobre un proceso: con quién, con qué, cómo, con qué criterios (los indicadores de desempeño que indican el éxito o fracaso del proceso), y la cabeza y la cola para representar las preguntas sobre las entradas del proceso y las salidasdel proceso.
Para más información de cómo identificar los procesos en el diagrama de tortuga vea los siguientes materiales:
- The importance of the process approach: https://advisera.com/9001academy/blog/2015/12/01/iso-9001-the-importance-of-the-process-approach/
- Curso fundamentos de la norma ISO 9001:2015: https://advisera.com/es/formacion/curso-fundamentos-iso-9001/
- Libro - Discover ISO 9001:2015 through practical examples: https://advisera.com/books/discover-iso-9001-2015-through-practical-examples/
You asked
"I will like to know how to set up a project applying the said standard
The starting point is to purchase the standard from ISO or your national Standards publishing organisation. Then to assist with implementation and applying for accreditation, look to reputable assistance such as the Advisera ISO 17025 Academy. The home page is at https://advisera.com/17025academy/
Have a look at the free resources at https://advisera.com/17025academy/free-downloads/ and download the Diagram of ISO 17025 Implementation Process as well as the Project Plan for ISO/IEC 17025 implementation shown on that page.
Thereafter look at the benefits of using the toolkit, where various options are offered at https://advisera.com/17025academy/comparison/ and the available previews of the entire kit at https://advisera.com/17025academy/iso-17025-documentation-toolkit/
You also asked
and the effects of ISO 17025 on projects
The following articles will give you some information on the importance of the ISO 17025 standard and it how can help your company and clients.
What is ISO 17025? at https://advisera.com/17025academy/what-is-iso-17025/
Six key benefits of ISO 17025 implementation at https://advisera.com/17025academy/blog/2019/10/18/six-key-benefits-of-iso-17025-implementation/
More and more academic laboratories and companies running various development projects which include testing, are seeing the benefits of ISO 17025 accreditation.
Thirdly, you asked
and how I can obtain a certification for the same ISO. To show competence on potential employers."
Laboratories achieve accreditation to ISO 17025, not certification. It is also not possible for a person to be certified to ISO 17025. What is possible is to show the technical competency and operational competency of personnel who work effectively within an ISO 17025 managed laboratory system. This is done through objective evidence during training and monitoring.
If you are not working in an ISO 17025 accredited laboratory, you could develop your knowledge by working through the standard and toolkit, and attending training on the system and implementation requirements of ISO 17025. Thereafter you can develop your skills and competency by applying the knowledge and contributing to the success of a laboratory in implementing and/or maintaining accreditation. Internal auditing, risk assessments; as well as method validation and measurement uncertainty are examples of areas where you can attend courses and obtain training certificates. Once applied in the laboratory, you can demonstrate your competency and obtain a competency declaration from management. Furthermore if you are responsible for the validity of results, as a technical signatory for your laboratory, you will also be assessed by the accreditation body. Your name may then appear on the laboratory’s accreditation certificates.
Besides the Advisera ISO 17025 toolkit at https://advisera.com/17025academy/iso-17025-documentation-toolkit/, you may also be interested in the ISO 17025 Academy webinars at https://advisera.com/17025academy/webinars/
Working with organizations I try to do that by showing top management the pain from the present: Defects, costs, complaints, delays, lost customers, loss, and their consequences for the organization. It is what can push them to change.
Other alternative is to try to pull them to change by showing how a quality management system can help in improving performance.
For both situations I invest a lot in aligning the quality management system with the strategic orientation.
You can find more information below: