Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
...
3. Any other tips if you think might help me scale up would be appreciated.
ISO 27001 can support part of the Governance, Risk, and Compliance process, so to enhance your skills you also have to consider competences related to COSO and COBIT.
These articles will provide you a further explanation about COSO, COBIT, and Governance:
... /iso-9001-vs-iso-13485/" class="content-link Link" >https://advisera.com/9001academy/blog/2015/01/21/iso-9001-vs-iso-13485/
... p>
... tal audit vs. vertical audit - https://advisera.com/9001academy/blog/2015/03/03/iso-9001-horizontal-audit-vs-vertical-audit/
... rtunities vs. environmental aspects - https://advisera.com/14001academy/blog/2016/03/21/how-does-product-life-cycle-influence-environmental-aspects-according-to-iso-140012015/
I have been following your studies and materials about ISO27001 implementation on your website. You stated on your website at https://advisera.com/27001academy/knowledgebase/iso-27001-gap-analysis-vs-risk-assessment/ that Gap analysis is done only for Annex “A” controls and that, one DOES NOT need to perform gap analysis for clauses of the main part of the standard. I believe you are referring to the mandatory management clauses from clause 4 to 10. ( Please find attached screenshot)
Now, my confusion is coming from the ISO 27001 Gap Analysis tool you provided on your website at https://advisera.com/27001academy/free-iso-27001-gap-analysis-tool/?icn=free-gap-analysis-tool-27001&ici=bottom-iso-27001-gap-analysis-tool-txt. In this Gap Analysis tool, you included the mandatory management clauses (i.e. clause 4 to 10) as part of the Gap Analysis checklist when you stated previously that Gap analysis is not performed for the mandatory management clauses.
Can you please explain why?
... y - Major vs. minor nonconformities in the certification audit - https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
The following material will provide you with information about root cause analysis:
... tal audit vs. vertical audit - https://advisera.com/9001academy/blog/2015/03/03/iso-9001-horizontal-audit-vs-vertical-audit/
... /iso-9001-vs-iso-13485/" class="content-link Link" >https://advisera.com/9001academy/blog/2015/01/21/iso-9001-vs-iso-13485/
Also, the following articles can be helpful in understanding the ISO 13485:2016: