Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Article 5 (c) GDPR requires processing personal data according to the principle of data minimization which means that organization shall require as few as possible personal data. However, you should check the privacy notice of the company and their refund policy. Sometimes additional data may be required by antifraud company process or required by law.
Here you can find some information:
You may also consider enrolling in this online EU GDPR Foundations Course:
In this kind of situations, you can use a model to help you describe the situation and get ideas about what can help you in promoting change.
Normally, people don’t change just because they don’t want to change. Look for what can motivate them to change and act on what can block the change.
As an example of anxiety, they may want to be afraid of any finger pointing to individual cases due to a better traceability around nonconformities. As an example of inertia, they may have genuine difficulties in using the NCR tool. Train them on its use.
Please find below more detailed information:
1. In ‘06 Statement of Applicability’ > ‘Implementation method’ is [Business Continuity Plan] while In the ‘List of Documents ISO 27001 ISO 22301’ there is marked that
’Appendix 6 – Disaster Recovery Plan’ is mandatory document for A.17.1.2.
The document choice will depend on the ISO standards implemented.
If you are implementing only ISO 27001, the Disaster recovery document is sufficient to cover the standard requirements. In case you are implementing ISO 22301, of ISO 22301 and ISO 27001 at the same time, you need to use the business continuity plan (please note that the disaster recovery plan is an annex of the BCP).
For further information, see:
2. Second, if one should seem that Disaster recovery should be in place in the Company but A.17 Information security aspects of business continuity management are not applicable, should one use only ’Appendix 6 – Disaster Recovery Plan’ to document recovery?
The purpose of Disaster Recovery Plan is to document how your IT infrastructure is to be recovered, it does not have the purpose of recovery of business parts of the organization. By the way, from our experience, a large majority of companies find controls from section A.17 applicable.
Implementing an environmental management system is not about solving all environmental problems with a magic trick.
ISO 14001:2015 is based on the PDCA cycle:
ISO 14001:2015 invites us to invest our scarce resources where their environmental return is bigger. Organizations should not try to solve all problems at the same time, there will never be enough resources and the results will be minimal.
In the first turning of the cycle, organizations act upon the first set of significant environmental aspects. In a second turning of the cycle, organizations should update the significance classification and update the investment priorities. That way we can ensure the best use of available resources.
Please check this information below with more detailed answers:
1. Do you consider that IATF 16949 is sufficient to evaluate the QMSs of OEMs?
Yes, IATF 16949:2016 standard is sufficient for customer-specific requirements evaluation due to the IATF 16949: 2016 standard addresses customer-specific requirements at many points.
2. If so, why are there supplementary audits like VDA6.3 or ASES of Renault-Nissan? Thank you.
As you know, customer-specific requirement means automotive customer expectations. This issue is addressed in Article 4.3.2 of the IATF 16949: 2016 standard. In addition, in annex B, section’’ Bibliography-supplemental automotive’’ of the same standard, customer-specific requirements of all OEM customers are shown and explained.
For example, if the organization's customer is VW, in this case, it is stated that it should comply with special requirements such as VDA 6.3-6.4-6.5.
For more information, please read the following articles:
If your medical devices are already certified according to the MDD 93/42/EEC, first you need to check is there a change in the classification of your medical devices. In MDD there were 18 rules, in MDR 2017/745 there are 22 rules, so some medical devices have been changed to a higher class.
You can find Classification rules in EU MDR Annex 8 Classification rules: https://advisera.com/13485academy/mdr/classification-rules/
The next requirement that needs to be fulfilled is the requirement for the Post-market surveillance system.
This system is in detail explained in following MDR chapters:
For more information about MDR, please see the following articles:
1. How and which Executives need to get involved in ISO 27001.
The executives to be involved will depend on the ISMS scope. In case all the organization is in the ISMS scope, then the CEO is the top executive to be involved, as well as the other executives, representing their areas. In case the ISMS scope is limited to part of the organization, then the highest executives in the defined scope must be involved.
The executives' involvement basically covers:
For more information about the roles and responsibilities of executives in information security I suggest these materials:
2. Which documents need to be overseen by them specifically?
Considering the mentioned responsibilities, the most common documents you will find are:
To see how these documents look like, please access these links:
No, you need to know what data you will keep (maybe personal details in suppliers/customers invoices), how long you will keep them (usually bookkeeping periods are defined by law) and how you will protect and then you need to develop your own privacy notice to inform in a transparent manner how you will process personal data. If you do not keep projects data, you will write so to inform individuals about it. You need also to protect data with some security measures.
Here you can find some information:
You may also consider enrolling in this online EU GDPR Foundations Course: EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
You can draw the process flow where those companies interact with your organization and then determine possible risks. Evaluate those risks and for the most significant include the topics in your rating scheme.
Please find below more detailed information:
You can follow exactly the same procedure as for internal audits. Where you should invest more time is in the audit scope definition and in the audit objective definition. Please check Annex “A.12 Audit of supply chain” in ISO 19011:2018.
Please find below more detailed information: