Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
As you know, the effectiveness of contingency action plans should be checked by testing or simulation methods according to risk level to customers. When testing and/or simulation is done or when a real event occurs, details should be recorded in the "log" line with the date, time, etc. You can use the ‘’log’’ line for this reason.
Please note that in ISO 27001, the word "media" refers to both electronic and paper, so all these controls can be applied to paper media.
This article will provide you a further explanation about paper media:
This material will also help you regarding ISO 27001 controls:
Because the process approach describes your organization and how it works every day in a way that people understand. Normally, in an organization, people do not know ISO 9001 clauses. It is easier to visualize the flow of work than memorize the clauses:
I became a fan of the process approach before the ISO 9001:2000 version because I used to work based on the clauses of the standard. When working with a service company, an interim work company, I had to always explain the standard to people. One day I decided to do a major flow of how they worked and it was a miracle, they understood it and I've never had to explain the standard content again.
The following material will provide you more information:
The OH&S control measures that need to be put in place for material handling will vary greatly depending on the type of materials handled and the machines used; additionally, the legal requirements for the areas in question need to be taken into account as this can dictate the controls needed.
For instance, if a lift truck is used then the safety considerations of training the driver may need to be considered, as well as the safety considerations for the fuel used (such as propane storage). If, on the other hand, you use only hand powered trucks to move your material then these safety controls would be different, such as PPE for foot injury.
You can learn more about the levels of control that can be considered in the article: 5 levels of hazard controls in ISO 45001 and how they should be applied, https://advisera.com/45001academy/blog/2015/09/02/5-levels-of-hazard-controls-in-iso-45001-and-how-they-should-be-applied/
According to ISO 9001:2015 clause 7.5.2 a) you do not need to number the documents; you need to have a methodology to identify each document. You can use numbers or titles, for example.
The following material will provide you more information:
When you consider desired or expected results and due to uncertainty, you realize that you might not meet those results you are considering the influence of risks. Positive risks, also known as opportunities, help you meet or surpass desired results. Negative risks, risks, hinder your ability to meet those desired results.
ISO 9001:2015 does not require documenting risks and opportunities. So, organizations are free to decide if they document and how to document. I recommend organizations develop a register for risks and opportunities. That register can be global or per product/service, or per process, or per department.
For example, in the purchasing department you can identify risks such as:
For example, in the purchasing department you can identify opportunities such as:
The following material will provide you more information:
Two recommendations:
The following material will provide you more information:
ISO 27001 does not prescribe how to develop documents, so you can record nonconformities and corrections in the same document that you are using to capture risks, but we do not recommend such an approach.
The reason is that, if nonconformities and risks are in the same document, persons looking for one type of information would have unnecessary access to the other and this can compromise confidentiality.
Moreover, risks and nonconformities are very different types of information, and this is also why it makes sense to keep them separate.
This article will provide you a further explanation about records management:
These materials will also help you regarding records management:
As far as I understand your question, you are asking for examples of environmental objectives.
For example, for a Construction company you can think about:
For each objective you have to set clear targets and time frame. For example: Reducing waste sent to landfills, can become – Reuse at least 50% of demolition waste during the year of 2021. – Responsibility – Person A
Please check this information below with more detailed answers:
Clause 6.1 is about determining risks and opportunities and evaluate its importance to decide about the need to develop action plans.
For example, an organization while updating the context analysis (clause 4.1) determined some internal and external issues with positive and negative connotations:
Then, they started to make combinations between:
They determined
You may realize that:
You may evaluate these risks and opportunities based on probability and importance (severity or gain)
I use the interested parties’ point of view to evaluate the importance of risks and opportunities.
For example, one interested party are the owners of the organization. What do they want, what do they need, what do they expect?
So, based on this interested party point of view you can determine if each risk and opportunity is important. For example, because profit is relevant for the owners, you may conclude that all those risks and opportunities are critical to maintain or improve profits during a downturn.
Hope this tip can help you with your clients.
The following material will provide you more information: