Considering your demand, I suggest you the ISO 27001 Documentation Toolkit. The templates are almost 80% complete, with comment about hat must be kept and what can be adjusted according your needs.
NIST 800-53 already has a map of its controls to ISO 27001 standard (Annex H), that can help you identify which controls need to be adjusted considering our templates.
NIST CSF and ISO 27001 are closely related, in a sense that they complement each other (CSF provides a structu red framework for controls implementation while ISO 27001 provides a worldwide recognized management framework to ensure the controls pertinence, efficiency and effectiveness), and since CSF controls are mostly based on NIST 880-53 you also can use these to make adjustments on the templates content.
About NYS DFS 500 and GLBA, unfortunately we do not have sufficient information to provide additional guidance.
Exclusions doesn´t apply when the standard has been already implemented. In fact one of the first steps when implementing ISO 9001:2015 is determining the scope of the organization and when defining the scope of your QMS you should also determine if any exclusions apply and justify them. For instance, if a company doesn´t do any design work, but it uses designs already given by a customer, you can say that this requirement doesn´t apply to your organization.
A customer complain log should include the list of complaints received from customers, with its documented response and closure. After receiving a complaint, the organization must evaluate whether the complaint is reasonable or not, and after doing so, the organization will need to suggest a way of resolving the complaint and decide if carrying out a correction or corrective action according to its own organization´s procedure for control of nonconforming product or service.
Efectivamente deberían de ser 3 personas distintas:
- El que elabora el documento: normalmente se trata de un experto en el proceso correspondiente y con conocimientos sobre cómo documentarlo según lo establecido por la organización.
- El que revisa el documento: suele ser un experto en el proceso con las competencias necesarias para poder asegurar los niveles adecuados de calidad del documento con respecto a los procesos y actividades que se pretenden documentar.
- El que aprueba el documento: la persona con máxima autoridad en el proceso, que normalmente designa tanto al creador del documento como al revisor del mismo.
From these sites you can find the location that is closer to you.
Acción de mejora y mejora continua
Respuesta:
Una acción demora es una medida tomada para optimizar el rendimiento de los procesos dentro de la organización. Esta acción de mejora no tiene porqué ser exclusivamente una respuesta ante una situación negativa, sino que simplemente se lleve a cabo con el fin de obtener consecuencias positivas.
A su vez, estas acciones de mejora contribuyen al objetivo de la mejora continua del SGC, que es incrementar la satisfacción del cliente y de las partes interesadas. Esto se refleja en la cláusula 10.3 de la norma ISO 9001:2015 que requiere que las organizaciones mejoren de forma continua la efectividad de la documentación y los procesos del sistema de gestión de calidad. Esta mejora continua se basa en el ciclo PDCA, por sus siglas en inglés, de planificar, hacer, revisar y actuar.
The key here is to perform a Legitimate Interest Balancing Test and you should balance your interest in sending advertisement and the right to privacy of the affected data subjects. One of the key points is to be able to prove that the advertisement would be relevant to the data subjects. For example, if you are a company selling raw materials such as coal, you won’t be able to justify sending advertisement emails to a software company representative.
I want advice on setting up QMS. This is the scenario:
Company A: Has a ISO 13485 QMS for 'Design, Development and Manufacture of patient monitoring device'. Manufacture under non sterile conditions.
Company B: Wishes to set up manufacturing of wound care products. Manufacturing in ISO 7 (Class 10,000) clean room. Is it better (more economical, faster, and less cumbersome viz., documentation) to a. Get a separate certification for Company B or b. Outsource manufacturing for Company A to Company B and have the Scope for Company A's QMS modified.
Answer:
You should set up a separate QMS for Company B since the type of medical devices and scopes of the companies are entirely different.