Answer
First, ISO 9001:2015 no longer mandates the existence of a quality manual. So, organizations have a lot of freedom to decide what do they want to include if they decide to write a quality manual.
The corporation has a purpose, has a mission, each business unit work on its own way to contribute to that purpose. One of the big advantages of corporations is the synergy among different business units, like the case you mention: sharing common processes.
Start with a description of the corporation, then describe the business units and their processes and underline the existing synergies.
Answer:
First, a clarification: ISO 14001:2015 does not ask for an internal compliance audit. ISO 14001:2015 asks for a complete verification and several actions if needed (clause 9.1.2).
In my country auditors want to check the actual Environmental Compliance Register. Certification auditors are bounded by confidentiality. Some organizations prepare a kind of legal document for the auditor(s) to reinforce that confidentiality. If an organization has any non-compliance that will appear, for example, in the management review record, a basic document for any certification audit.
Answer:
ISO 14001:2015 has no specific requirements for shipboard waste oil incinerator. You have to check which national or international legislation your organization has to comply. Different countries have different air emission limits for each chemical.
First it is important to note that it is not mandatory to implement ISO 27001 to implement and get certified against ISO 22301.
Regarding performing BIA complaint with ISO 22301 you need:
- to identify activities that support the products or services you want to ensure the continuity
- to assess the impact over time in case these activities are disrupted
- to define prioritized timeframes for returning these activities
- to identify dependencies and supporting resources
What do you suggest please? Lead Auditor or Implementer, and is you provider have better reputation than IRCA?
Answer:
You must consider your personal and business objectives to define the proper approach. If you plan to implement an ISMS, then you should go for Lead Implementer certification, but if you plan to work as an auditor, then Lead Auditor would be probably better for you.
Regarding reputation, both Examplar Global and IRCA are well seen in the market, the difference being that Exemplar Global is more recognized in North America, Pacific and Australia; IRCA is more popular in Europe.
BS25999 and ISO 22301
Answer:
BS 25999 is the British standard from which ISO 22301 was developed, and we decided to leave both references in the toolkit's name to make it easier for customer that it can cover a Business Continuity Management System based on both standards.
I received a further related question:
>Risk Mitigation techniques like PFMEA and DFMEA are deployed for which category of risks? Usually they are for a manufacturing process or design of a product.
Answer:
It is important to note that the AS9100 Rev D standard does not include requirements of how you will perform your risk assessments or risk management. As such, it does not specify the use of FMEA in any risk mitigation activities, how you do this is up to you. As you have stated FMEA can be used for many different implementations such as product design (operational risk) or process design (could be management risk or operational risk). You should use the tool where you find it useful, and of course where it is a requirement of the customer.
Procesos en empresa de servicios
Aunque la producción de agua potable se realice bajo normativa, si su organización ha introducido nuevos servicios en los últimos cinco años, o si se publicaran nuevas especificaciones o requisitos en la legislación su organización deberá de planificar e introducir esos cambios. En ese caso la cláusula 8.3 sería aplicable. Si esto no ocurriera, entonces podría excluir esta cláusula.
This policy normally defines the rules for use of cryptographic technologies, so due to its technical nature, and the risks associated to non IT personnel having access to its content, it is normally given a classification which restricts its assets to IT personnel (normally it is not necessary for regular users to have access to this policy).
Difference between Risk Treatment Plan and Corrective Actions
Answer:
Risk Treatment Plan and Corrective Actions fulfill different purposes and requirements, that's why we provide different documents.
You use the Risk Treatment Plan to define actions to treat risks, i.e, actions to prevent them to happen, or to minimize their impact in case they occur.
On the other hand, you use Corrective actions to treat controls or processes that failed to fulfill their objectives, or are not performing as planned.
For example, to treat a risk of data loss you can define the implementation of a backup process in the Risk Treatment Plan.
Now consider that this backup process is implemented, and it was identified that for some reason the backup was not performed as scheduled, or that the process has failed (in both situations the original data wasn't lost). To treat this situation you have to open a Correcti ve Action.