Answer:
ISO 9001:2015 considers tests requirements for:
Approval of new products and services performance (clause 8.3.4)
Approval of materials and services acquired to external providers (clause 8.4.2)
Approval of final product or service (clause 8.6)
Answer: Please note that "organizational units for information and communication technology" is only an example to consider for users of this document. You can change it for whatever users you see are relevant for your organization.
2 - Should the policy not be relevant to all employees of the company? Especially when the type of information (for which the communication channel will be defined) represent all assets of the organization? (Means the assets we chose for the risk assessment). So far I made a matrix about the allowed communication channels depending on the information type.
Answer: Please also note that for ISO 27001 this policy covers external parts and electronic communication, so for employees that do not use electronic communication nor have contact with external par ts this policy would have no sense for them. Of course, if these scenarios do not occur in your organization you can state that this policy is applicable to all your employees.
ISMS processes for personnel security
Answer:
ISO 27001 ISMS processes are the same regardless to where they are applied once the ISMS scope is defined:
- Risk assessment and risk treatment, for identification of risks relevant to personnel security and definition of proper controls
- Controls implementation and operation, to effectively reduce risks to acceptable levels
- Performance evaluation, to check and verify if expected results are being achieved
- Improvement, by means of non conformities, corrective actions and continual improvement
Specifically for personnel security, main controls applied are terms and conditions of employment, and awareness and training.
How does Annex A related to the risks ? I understand there are 114 security controls (?) that the standard defines on Annex A. Do we need to refer to all of them and for each one indicate if that is relevant? And if relevant - then I fill the relevant doc? What table do I use to do that ?
Actually, if I put it in other words, I would appreciate a clarification of the process between folders 5,6, and 8 (Annex A). For me there is too much info and videos in the site. It is overloaded and I can't find what is relevant and I do not want to spend to much time on viewing all of that. Can you list the process in few sentences in regards to the risk and security controls? What do I need to do and what tables to use ?
Answer:
Basically you are referring to the risk assessment and risk treatment processes, where relevant risks are identified and proper treatment actions and controls from ISO 27001 Annex A are chosen.
For a view of these processes, with the use of real data as examples, you can see these video tutorials included in your toolkit:
- #105 How to implement risk assessment
- #106 How to implement risk treatment
Records in Service Desk tools
Answer:
Some records may be needed to be retained for longer if the processing is necessary for the establishment, exercise or defense of legal claims.
Supportive documents for Total Productive Maintenance
Answer:
There are no specific supportive documents required under the Total Productive Maintenance clause.
It is common practice to have supportive documents with data about OEE (Overall equipment effectiveness), MTBF (Mean time between failures) and MTTR (Mean time to repair (MTTR) as inputs for management review.
Also, for preventive and predictive maintenance, as well as for periodical overhaul, you should have some records about it.
For parts and service management you should have some kind of documents such as instructions for use and similar.
Con respecto a la documentación que tiene que existir en una organización conforme a la norma ISO 9001:2015, puede divirse en dos tipos: los registros y los documentos (políticas, procedimientos). Los registros son referidos en la norma como información documentada que debe retenerse, mientras que los documentos son referidos en la norma como documentación que debe mantenerse. Por otro lado, existe un tipo de documentación que es obligatoria por la norma y otra, como los procedimientos, que la organización puede decidir si desarrollarla o no. Aquí puede ver un artículo sobre la documentación obligatoria y la más comúnmente usada - Lista de documentos obligatorios requeridos por la ISO 9001:2015: https://advisera.com/9001academy/pt-br/kit-de-documentacao-da-iso-9001/nowledgebase/lista-de-documentos-obligatorios-requeridos-por-la-iso-90012015/
Es importante que sepa que no existe ningún formato obligatorio a seguir por la organización en cuanto a la documentación, sino que es la propia compañía la que decide cómo lo hace siempre y cuanto .
Answer:
An organization determines internal and external issues (clause 4.1).
When those external and internal issues are analyzed from the perspective of strategic direction, they can gain a positive or a negative connotation. That way those issues can be classified as:
Positive internal issues are strengths;
Negative internal issues are weaknesses;
Positive external issues are opportunities;
Negative external issues are threats.
Now you can organize that information with a SWOT matrix.