Answer:
Clause 5 of ISO45001:2018 gives requirements for what top management of the company needs to do to ensure that the management system is in place and will be successful. This relates to the fact that is top management does not support the OHSMS it will be difficult to maintain if it does not fail completely. The clause starts with a list of what top management needs to demonstrate to show commitment (clause 5.1), then gives the requirements for creating the OH&S policy (clause 5.2) which provides the overall goal for the OHSMS.
Following this are the roles and responsibilities (clause 5.3) of the OHSMS which need to be assigned by top management to ensure that the system works properly, and the requirements to ensure that you have adequate worker participation in the OHSMS (clause 6.4) since workers are one of the key interested parties in the successful OHSMS.
For a better understanding of the ISO 45001:2018 standard, see this whitepaper: Clause-by-clause explanat ion of ISO 45001:2018, https://info.advisera.com/45001academy/free-download/clause-by-clause-explanation-of-iso-45001
Auditor competency
First, it is your organization that has the authority to establish competency requirements for internal auditors. Second, your organization should, as a good practice, update those requirements. Normally, updating includes knowing ISO 9001:2015 and knowing good auditing practices, perhaps considering an update for ISO 19011:2018.
So, if you updated your ISO 9001 training to the 2015 version and you answer to all internal requirements for internal auditors there would be no problem.
The following material will provide you with information about internal audits:
- ISO 9001 – Five Main Steps in ISO 9001 Internal Audit https://advisera.com/9001academy/knowledgebase/five-main-steps-in-iso-9001-internal-audit/
- free online training ISO 9001:2015 Internal Auditor Course
– https://advisera.com/training/iso-9001-internal-auditor-course//
- book - ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
Experiencia en SGC y formación
Respuesta:
Gracias por su pregunta. Experiencia previa en calidad se refiere a la experiencia propiamente dicha, ya sea por ejemplo como consultora, realizando auditorías internas o implementando la norma o como personal dentro del departamento de calidad de una empresa en la que se hace la implementación y el seguimiento de la norma ISO 9001 o incluso la auditoría interna, entre otros.
Para poder tener experiencia obviamente el primer paso es tener conocimientos para lo que es más que recomendable realizar algún curso y si se quieren demostrar esos conocimientos contar con algún tipo de certificado.
El auditor verificará que los recursos de la organización, que son tratados a lo largo de esta cláusula 7.1, incluyen el personal pertinente para poder llevar a cabo un efectivo funcionamiento del sistema de gestión de calidad, la infraestructura necesaria para el eficiente funcionamiento de los diferentes procesos, así como otro tipo de recursos como los necesarios para que exista el ambiente prop icio para la ejecución de los procesos, los recursos para llevar a cabo el seguimiento y medición del sistema, etc.
Para poder demostrarlo, entre otros, la organización puede añadir en las especificaciones de cada uno de los procesos los recursos que va a emplear, tanto humanos, como materiales, económicos, de infraestructura, etc. Por otro lado, vamos a necesitar tener en cuenta los recursos que inicialmente existen dentro de la organización para poder determinar aquellos que debemos obtener de proveedores externos.
ISO 27001 cannot be used to certify products and services, but to certify the processes that support them (e.g. e-mail administration and operation processes).
After getting support for your project (through approval of the ISMS project plan) and approval of the Procedure for Document and Record Control, the steps for ISO 27001 implementation you should consider are:
1) defining ISMS basic framework (e.g., scope, objectives, organizational structure), by understanding organizational context and requirements of interested parties;
2) development of risk assessment and treatment methodology;
3) perform risk assessment and define the risk treatment plan;
4) controls implementation (e.g., policies and procedures documentation, acquisitions, etc.);
5) people training and awareness;
6) controls operation;
7) performance monitoring and measurement;
8) perform internal audit;
9) perform management critical review; and
10) address nonconformities, corrective actions and opport unities for improvement.
During this process you can select and hire the certification body to perform the certification audit.
Si se refiere a la estructura definida de los distintos tipos de documentos del Sistema de Gestión de Calidad por el estándar internacional ISO 10013:2001 se trata únicamente de una recomendación y no coincidiría con algunos de los documentos actualmente obligatorios por la norma ISO 9001:2015.
En concreto el estándar ISO 10013:2001 contiene las siguientes recomendaciones en cuanto al contenido y estructura de ISO 9001:
1) Manual de calidad. Actualmente este documento no es obligatorio en ISO 9001:2015 aunque puede ser mantenido por la organización
2) Política de Calidad. Sigue siendo un documento obligatorio en ISO 9001:2015
3) Procedimientos de calidad. Los procedimientos ya no se tratan de información documentada obligatoria aunque la organización puede definir su necesidad e implantarlos en sus procesos.
4) Instrucciones técnicas. Es la organización la que decide qué instrucciones técnicas podrían ser necesarias para la implementación del estándar.
5) Registros. Puede revisar en este artículo la lista de registros y otra información documentada obligatoria en ISO 9001:2015 - Lista de documentos obligatorios requeridos por la ISO 9001:2015: https://advisera.com/9001academy/pt-br/kit-de-documentacao-da-iso-9001/nowledgebase/lista-de-documentos-obligatorios-requeridos-por-la-iso-90012015/
Once you know which requirements you need to comply with then you can start writing a Project Plan where you assign responsibilities within the company related to the implementation of ISO 9001:2015, define the documented information to be written and determine milestones along the project. Although this is not a mandatory requirement can help you to organize your implementation of the standard. You can download this free document - Project Plan for ISO 9001 implementation: https://info.advisera.com/9001academy/free-download/project-plan-for-iso-9001-implementation-ms-word
After you can start the different steps of ISO 9001:2015 the implementation, from defining the quality policy and objectives, the context of the organization and the scope... until the internal audit and management review.
ISO 27031 is a supporting standard to help implement controls from ISO 27001 Annex A section 17, which basically covers continuity of information security and Information and Communication Technologies. Considering that, ISO 22301 covers the continuity of business as a whole, while ISO 27031 can be seen as a tool to implement the technical part of ISO 22301, so implementing it without ISO 22301 wouldn't be a good approach, because you wouldn't take advantage of the business impact analysis process, which helps optimize resources application.
Answer:
First you must consider nonconformities and its classification of major and minor.
Normally, any minor nonconformities found in an audit will need to be addressed within a certain timeline, but the certification can be granted when the corrective action plan is received, and the audit team will follow up at the next surveillance audit by the certification body. Major nonconformities might mean that your certification will not be granted until the corrective action is in place and the certification body auditors come and verify that it is effective. But I agree with you, there is some subjectivity from certification body to certification body.
Answer:
Being ISO 9001 certified is not an alternative to being ISO 27001 certified.
ISO 9001 is a management system standard for the quality management system, and ISO 27001 is a management system standard for information security management system. While ISO 9001 is about customer satisfaction, ISO 27001 is about information risk reduction.