Although largely known as ISO 27001, to refer to the Standard only as ISO 27001 is inaccurate.
The full official name of this standard is ISO/IEC 27001:2013, because this standard was developed by a joint technical committee (ISO/IEC JTC 1) formed by these two organizations.
The participation of IEC in the development of this standard helps ensure that its content is aligned with standards developed by IEC without participation of ISO personnel, such as IEC 62351 Power System Control and Associated Communications – Data and Communication Security.
Additionally, not using the official name can lead people not used to ISO documents to the misinterpretation that there are more than one 27001 standard, which is not true.
Examples of positive issues
yacht rental praslin
Using a designated hold location for defective product
Answer
Please check ISO 9001:2015 clause 8.7 b). Segregation is one of the possible ways of dealing with a defective product. Sometimes physical segregation to a designated hold area is not possible, for example, the defective product is very big or there is not enough space for a hold location. So, segregation in a designated hold location is not mandatory. What is mandatory is to avoid the unintended use of defective products. For example, sometimes a red label is the way used to warn about product status.
Lo primero que debe de hacer es contar con el apoyo de la dirección de la organización, que será clave durante la implementación de ISO 9001:2015, también para proporcionar los recursos necesarios.
Después lo que puede hacer es un análisis GAP o de brecha, que le va a ayudar a identificar aquellos requisitos que ya cumple y los que le debe aún cumplir. Aquí puede llevar a cabo el análisis de forma gratuita: https://advisera.com/9001academy/iso-9001-gap-analysis-tool/
Luego ya podría empezar con la implementación de la norma: la definición de la política de calidad, los objetivos de calidad y planes para llevarlos a cabo, el contexto de la organización y sus partes interesadas, el alcance del SGC, etc...hasta llegar a la auditoría interna y la revisión por la dirección, que sería el paso previo para certificarse. En este enlace puede descargarse un checklist para la implementación de la norma - Porject checklist for ISO 9001:2015: https://info.advisera.com/9001academy/free-download/project-checklist-for-iso-9001-2015-implementation
I would keep that revision table at the end of the document but would add some kind of revision number, or date, or color to warn users that something in the page was changed. In a QMS we want to avoid the unintended use of obsolete documents. Perhaps these documents could bring more information to the topic "Common mistakes with ISO 13485:2016 documentation control and how to avoid them" https://advisera.com/13485academy/blog/2018/03/14/common-mistakes-with-iso-134852016-documentation-control-and-how-to-avoid-them/
Quality assurance vs quality control
Answer
Quality control is about checking if product or service specifications are being met. You can have a Quality Control Plan that states what to control, when and where, how, by whom, with what specifications and methods. Quality assurance is about the set of processes in place to provide confidence that quality requirements will be met.
This type of ISO standard is out of our field of expertise, but what we can tell you is that ISO standards related to content identification and description are under responsibility of ISO working group ISO TC 46 SC 9 and the current available standards can be found at this link: https://www.iso.org/committee/48836/x/catalogue/p/1/u/0/w/0/d/0
We hope that one or some of these standards can fulfill your needs.
GDPR and inventory of processing activities
1. Does the GDPR standard apply to EU employees or global employees? I’m wondering if we can inventory our processing activities for employees only.
Answer:
The GDPR applies to data of individuals in the Union (EU). This means that it would apply to all processing activities where the personal data of the employees in the EU is involved with regard to which you are acting as a controller. The same applies to the data of the clients' employees for which you perform the reimbursement services as a processor.
2. Data is transferred from the EU to the US and back. This could include a contact name for a customer as well as a business email and phone number. Would inventory of processing activ ities be applicable in this case?
Answer:
Yes, you would need to be compliant with the provisions of art. 30 and to document the processing activities.
3. Is a business email address considered personal data?
Answer:
Usually, business emails are name.surname@companyname.com so it would be considered personal data except for generic email addresses such as office@companyname.com.