Answer:
An organization can purchase a product (a raw material, for example), a service or an outsourced process. Normally, calibration is not considered an outsourced process, unless the certification scope is providing calibration services. Please check clauses 8.4.1 a) b) and c) about what is mandatory to include. Plating can be considered an outsourced process if it is carried out following the decision of the organization.
Answer:
Design and development is by the rule the most complex part of IATF and similar standards like ISO 9001. In requirement 8.3.3.3 standard is referring to special characteristics that can be defined by the customer or by the organization.
Most important part is that all special characteristics (product/process) must be thoroughly documented and marked on drawings (if required), risk analyses (FMEA), control plans and work instructions.
Also, the request is that a conversion table of internal definitions and symbols and symbols to the definitions and symbols defined by the customer must be submitted to the customer on request.
That basically means that all symbols and internal de finitions in conversion tables that organization is using must be submitted to the customer on their request. This is important for the mitigation of risk that an organization is using a different conversion table. It can be a case if, for example, OEM is from Europe and supplier is from the USA or vice versa.
Answer:
I have one problem with your question: What is an audit observation? ISO 19011:2018 does not define what is an audit observation. So, I would ask your certification body how do they define audit observation and what kind of answer do they request, or not. For example, I am reading a certification body audit report where they include this statement in the audit report template: “The Observations are formulated with the purpose of improving the Management System and its effectiveness; do not require a response or notification from the Organization; and will be subject to re-evaluation in the next audit.”
Answer:
If you believe you need ISO 9001 certification, perhaps you could benefit from attending a course about ISO 9001:2015 content, another about implementing a quality management system, and another one about performing internal audits. In my experience with hotels with restaurants, they look for kitchen consistency independently of the shift working.
Labeling can be adapted to organization needs, so you can remove it, but you have to consider that without label the risks may increase, because it will be more difficult for people to identify the sensitivity of information and how to handle them properly. An alternative may be to have only two classification levels and label only the most sensitive information. This way you will reduce the need to label information.
2. About document “A.9 access control “ in 08 annex A, can you guide us how to fill user profile section?
Answer:
Here is an example for user profile:
Name of system: Payroll module
User rights: Include records and edit records
Job titles have access rights according to this profile:
• Payroll analyst
Name of system: Payroll module
User rights: Delete records
Job titles have access rights according to this profile:
• Payroll manager
Name of system: Payroll module
User rights: View records
Job titles have access rights according to this profile:
• All employees
Network: Internal network
User rights: Upload and download files
Job titles have access rights according to this profile:
• All employees
ISO 9001 in hospitals
Answer:
Several studies published in technical magazines show that quality management system implementation, according to the ISO 9001 standard, is useful for the hospitals as it can help to improve the operational efficiencies, to reduce errors, increase patient safety and develop a more preventive approach instead of a reactive environment. Perhaps you can develop a value proposition around these topics:
Three topics: knowledge of ISO 9001, project management skills and leadership skills.
There is no mandatory requirements concerning a particular function in an organization. Anyone can lead an ISO 9001 implementation project as long as he or she have:
- knowledge of ISO 9001 in order to understand what is at stake about each clause;
- project management skills in order to be able to plan, monitor and control a project involving different people with different priorities and motivations, together with scarce resources;
- leadership skills in order to be able to overcome barriers, to handle conflicts, to get resources and get top management attention. The need for these particular skills can be balanced with the existence of a Project Sponsor, someone not directly involved in the project but with authority and influence within the organization that can help the the Project Manager.
Answer: The information security risk assessment is about how to identify, analyse and evaluate risks, while the information security audit is about evaluation by which degree requirements are being fulfilled.
The information security audit is one of the means to assess if the information security risk assessment and risk treatment were performed as required (considering the ISO 27001 standard and other non-standard related requirements), and if its results (prioritized risks and implemented treatments) are achieving the expected results regarding the information security and business objectives.
2. What are an advantage and a disadvantage of an external as compared to an internal audit?
Answer: Second party audits (audits performed by ext ernal personnel with non certification purposes) can bring more expertise and unbiased view for the audit process than internal audits, but on the other hand they are more expensive and the lack of internal specific knowledge may let the external auditors miss situations that are clear for internal auditors.
Third party audits (audits performed by certification bodies with certification purposes) can bring independent and word wide recognized confidence that organization fulfils the standard requirements (through certification issuing), which internal audits cannot provide, but it involves costs for certification maintenance.
In Advisera's toolkit you purchased you have all templates you need to perform risk assessment according ISO 27001. They are located in folder 05 Risk Assessment and Risk Treatment Methodology:
- Risk_Assessment_and_Risk_Treatment_Methodology
- Appendix_1_Risk_Assessment_Table
- Appendix_2_Risk_Treatment_Table
- Appendix_3_Risk_Assessment_and_Risk_Treatment_Report
Also included in your toolkit you have access to video tutorials that can help you fill in the templates, with real data, and provide training for your team.
Inventory of assets table
Answer:
In case multiple risks are associated with an asset, then you must use the highest impact level associated to these risks. The purpose of the impact column is to give the organization a compr ehensive view of the most relevant assets of the organization regarding information security. This can help you prioritize and allocate resources to protect information.