Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
That way you will answer to quadrants 1 and 2. If your organization operates in a stable sector that will be enough. However, if your organization operates in a dynamic sector perhaps your organization should consider some activities relevant for quadrants 3 and 4. For example, yearly meetings with innovative suppliers, or subscribing relevant technical journals or magazines.
ISO 9001:2008 is no longer the current standard. ISO 9001:2008 is outdated after September 2018 when the transition period for ISO 9001:2015 finished. So, I recommend to no longer use ISO 9001:2008.
You can find detailed information about how to plan and implement a quality management system in the following links:
You can use a tablet, or a smartphone, together with an application like Whatsapp, or Zoom or Skype.
You can find more information below:
I believe one of the latest developments related to the Management Systems certification domain is the use of remote audits in first stage certification audits and surveillance audits. However, to get a more detailed answer I recommend that you contact your certification body.
You can find more information below:
Controls A.12.4.1 (Event logging) and A.12.4.3 (Administrator and operator logs) are covered by the document Security Procedures for IT Department, located on folder 08 Annex A Security Controls >> A.12 Operations Security
To cover control A.12.4.2 (Protection of log information) you can use the document A.8.3 Information Classification Policy, located on folder 08 Annex A Security Controls >> A.8 Asset Management, to define rules according to the information classification of the log.
To cover control A.12.4.4 (Clock synchronization), you can use the Statement of Applicability, briefly explaining in the column "Implementation method" how the clock is synchronized.
This article will provide you a further explanation about log and monitoring:
This material will also help you regarding log and monitoring:
Organizations cannot think about the future without considering what is happening in its context, internal and external.
Consider the case of a company specialized in recruiting crews for:
These are examples of external issues that surely will affect future business opportunities. As an internal issue consider for example the difficulty of the same company to migrate operations to an online channel due to lack of know-how or resistance from staff.
You can find more information below:
ISO 27001 does not prescribe how to develop documents but is important to note that you are talking about different types of documents.
The Risk Assessment and Risk Treatment Methodology is a procedure (it defines how risk assessment and risk treatment are performed), developed once and updated as needed, while the Risk Treatment Plan and the Risk Assessment Report are records (the first contain the results of risk assessment and the second a summary of the risk assessment and treatment results), which can be generated multiple times and are not normally updated.
Considering that, procedures and records should not be merged in a single document, because of the dynamic nature of records (after some time you w.ould have an unmanageable document basically containing records).
Regarding the Risk Treatment Plan and the Risk Assessment Report, they are not normally merged because the report is a summary, and the Risk Treatment Plan is normally referred to as an annex for the Risk Assessment Report
These articles will provide you a further explanation about risk management and records management:
These materials will also help you regarding risk management and records management:
If your device is a medical device according to the definition stated in the Medical device regulative (MDR 2017/745), then ISO 13485:2016 is applicable for you. ISO 13485:2016 is the only harmonized standard that is covering quality management system, and each manufacturer has an obligation to show compliance with applicable harmonized standards.
For the definition see:
For the use of harmonized standard please refer to the following article
EU MDR Article 8 – Use of harmonized standards - https://advisera.com/13485academy/mdr/use-of-harmonised-standards/
If you need any help for the implementation of the ISO 13485:2016, these materials can help
You can see our ISO 13485:2016 DOcumentation toolkit on following link: https://advisera.com/13485academy/iso-13485-documentation-toolkit/
Yes indeed, any testing or calibration laboratory, irrespective of size can be accredited. In your case, the client is internal, I assume the production plant ? The benefits of accreditation apply for inhouse laboratories too. Some internal laboratories have larger risks to ensuring quality and safeguarding impartiality than commercial contract work laboratories, so this needs to be carefully addressed.
The following articles may be of interest:
Six key benefits of ISO 17025 implementation at https://advisera.com/17025academy/blog/2019/10/18/six-key-benefits-of-iso-17025-implementation/
What is ISO 17025? at https://advisera.com/17025academy/what-is-iso-17025/
Also have a look at similar topics in the 17025 Expert Advice Community
ISO 17025 for internal quality control laboratory at https://community.advisera.com/topic/iso-17025-for-internal-quality-control-laboratory/
Assuring impartiality and confidentiality (for an internal laboratory) at https://community.advisera.com/topic/assuring-impartiality-and-confidentiality/