Estimation of timeline for ISO 13485 certification
Answer:
The implementation process will usually take between 3 months to 18 months depending on the size of the company. You can utilize this link to calculate the time that might be needed: https://advisera.com/9001academy/iso-9001-duration-calculator/ For the certificate stage, you should give yourself around 2 months to prepare.
Since the plastic injected molded clips are a part of the medical device components, you have to maintain a medical device file in order to be compliant with ISO 13485.
ISO 27001 does not prescribe how documents should be developed, so you can chose the approach that best fits your needs.
The main criteria to decide to merge documents or not are if they have similar purposes and if by merging them they would not become a document too big to understand or read. So, in this case, if your single document does not become to big to use and manage it may be best to merge them, so you have one less document to manage in your ISMS.
Points to be considered are:
- Business needs
- License type (even for open source software)
- Know vulnerabilities (you can search on NIST vulnerability database)
- Software reputation on market
- Existence of periodic release of security patches
- Software private policy
This article can provide further information about risk assessment:
In a general manner, security related actions can be driven by these reasons:
- the existence of unacceptable risks (as you already mentioned)
- the existence of legal requirements (e.g., contracts, laws and regulations), demanding a security action
- a top management decision, based on a business need or on a market best practice
The last two bullets do not have to be initially related to risks (but at some point you can identify some), neither do ISO auditors will require every action to be related to risks.
Disaster recovery plan
Answer:
Your toolkit includes an template for Disaster Recovery Plan on folder 8 Annex A controls A.17 Business Continuity
It is important to note that to ISO 27001 a DRP aims to the recovery of IT infrastructure, and since your question refers to a cloud provider, you must align which activities you must to document in your plan, since most is the activities will be responsibility of the provider.
Use of ISO 27001 standard
Answer:
ISO 27001 is an intellectual property of ISO, and it is necessary to buy the standard to use it, otherwise you would incur on intellectual property infringement. Depending on buying conditions you may share a limited number of copies of the standard you bought.
Retraining requirements
Answer
There is no ISO 9001 requirement making that mandatory. Unless there is some important client, or contract, or legislation/regulation making that a requirement it is not mandatory.