Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Workplace hazards

    The current pandemic illness that is affecting people world wide is certainly a hazard that needs to be taken into account in the hazard assessment for the processes in a company. As such it can be considered an OH&S hazard, and should be included in updated process controls for working processes.

    You can learn more about the hierarchy of controls in the article: 5 levels of hazard controls in ISO 45001 and how they should be applied, https://advisera.com/45001academy/blog/2015/09/02/5-levels-of-hazard-controls-in-iso-45001-and-how-they-should-be-applied/

  • Linking ISO 45001 to data management

    Since ISO 45001 aligns with all the other ISO management system documents you will find the same requirements for controlling documented information in clause 7.5. The requirements here give requirements for controlling procedures and records as well as archiving, and are the same as other standards such as ISO 9001 and ISO 14001. As such you can have one process for documentation control for all management system standards.

    You can read more about the documentation requirements changes in the article: New approach to ISO 145001 documentation, https://advisera.com/45001academy/blog/2018/03/13/new-approach-to-iso-45001-documentation/

  • Confidentiality, Integrity, and Availability

    Please note that ISO 27001 specifies that the CIA is related to risks (6.1.2 c 1), and to consequences (6.1.2 d 1), not to assets. Considering that, when using asset-based Risk Assessment, you need to consider the CIA on the asset-threat-vulnerability set, and to consequences related to it.

    When you talk about a risk-based Risk Assessment approach, I'm assuming you are referring to the description of a risk scenario (scenario-based). In this case, the CIA must refer to the described scenario and related consequences, while that in a process-based Risk Assessment approach the CIA must refer to the defined process and related consequences.

    For example:

    • For asset-based:  paper document - fire - the document is not stored in a fire-proof cabinet (affects availability)
    • For scenario-based: Data leak with impact on regulatory compliance occurring once every five years (affects confidentiality)
    • For process-based: Payment process failure, resulting in people receiving wrong values (affects integrity)

    For further information, see:

  • Data to information

    Some examples of data being converted to information can be:

    Product quality control results after comparing them with specifications become conforming or non-conforming products.
    Design and development verification results after comparing with specifications become conforming or non-conforming designs.

    So, data is about facts related with something. Facts are neutral. Then, after comparing facts with some rules, they acquire meaning. They become data.

    You can find more information below:

  • COVID -19 and ISO 9001 policy, processes and procedures

    Normally, organizations do not make changes in policies and processes due to COVID-19. What I see is organizations making changes in procedures because they change the way they do some activities.

    You can see more information below:

  • Implementando la lista de verificación de códigos

    Como implementaría la lista de verificación de códigos de documentos en una empresa?

  • Parameters for clean room

    Cleanrooms are classified according to the cleanliness level of the air inside them. The cleanroom class is the level of cleanliness the room complies with, according to the quantity and size of particles per volume of air. 

    All necessary information regarding cleanroom technology you can find in the following standards:

Page 321-vs-13485 of 1127 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +