Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
You can start with clause 6.1.2, when you determine environmental aspects and impacts and you realize that, more than consumption, you have wastage of water. Then you can have clause 6.1.4 where you have an action plan to address that significant environmental aspect. That action plan may be translated into rules, good practices for operational control, clause 8.1.
Please check this information below with more detailed answer:
I'm assuming you are referring to controls A.17.1.1 and A.17.1.2.
Considering that, controls from ISO 27001 Annex A section A.17 (Information security aspects of business continuity management) aims to minimize risks that, in case of an event that disrupts business operations, the information will be kept protected, and operations that rely on them will be resumed as quickly as possible.
To show compliance with control A.17.1.1, an organization needs to identify and include information security requirements in its reparations for business continuity. To do that the organization should ensure that the information security requirements are included when planning for business continuity and disaster recovery. One way to do that is by performing a business impact analysis for information security aspects to verify if the information security requirements being covered in adverse situations.
To show compliance with control A.17.1.2, an organization needs to ensure processes, procedures, and controls required for information security are documented, implemented, and maintained. To do that the organization should:
This article will provide you a further explanation about business continuity for ISO 27001:
This material will also help you regarding business continuity for ISO 27001:
Rules and obligations of how to manage a certification mark, where you can all put a mark for ISO 13485 you must get from your certification body.
Internal issues are about events or products and services that may affect an organization’s environmental performance. For example, a transport company with a very old and inefficient truck fleet.
External issues are about legal, economic, social, or political issues. For example, government may impose more demanding limits to emissions or customers may decide to reward companies with better environmental performance.
As examples of measurable environmental targets, we may have:
You just have to add a specific target, time frame and responsible.
As examples of risks we may have:
As examples of opportunities we may have:
You can find more information below:
Start with the purpose of the IT function.
What are the expected results of the work of the IT function?
When working with ISO 9001:2015, the risk is the effect of uncertainty on objectives – or anything which may impact upon meeting objectives or expected results.
I can think of the following negative outcomes:
More important than the examples is having a methodology.
The following material will provide you more information about risks and opportunities:
ISO 14001:2015 states that organizations when determining environmental aspects and impacts should consider the lifecycle of its products and services. ISO 14001:2015 uses the word “consider” because each organization must be aware of its context. A small organization has little power or impact over suppliers. A small organization has little influence over its customers and/or customers’ customers. So, considering your organization’s power and influence and the set of suppliers and customers and other participants until final disposal of your products or services, evaluate where significant environmental aspects and impacts are and where your power and influence can help reduce or minimize environmental impacts. Then, invite your suppliers and customers to work with you in order to develop action plans that can improve the relationship with the environment.
You can find more detailed information below:
What are OEM doing during Covid?
OEM customers are in the process of COVID-19; They stopped production for 2 to 3 months. Some companies still work at home, with the exception of the manufacturing process. Production capacities are also low. They also took many measures to protect against COVID 19.
What are the plans for internal audit?
Internal audits are often postponed, some process internal audit (except for the production process) were done online, in online environments such as zoom or skype. After the COVID process, internal audit plans will be prioritized according to risk and importance.
To fulfill ISO 27001 mandatory requirements (e.g., defining the ISMS scope, the Information security policy, performing an internal audit, etc.) and keep required controls to a minimum, you should follow these principles:
These articles will provide you a further explanation about ISO 27001 implementation:
These materials will also help you regarding ISO 27001 implementation: