Only auditors working for certification bodies (certification auditors) can certify business as ISO 27001 compliant.
The lead auditor course is the first step to become a certification auditor.
The process to become an ISO 27001 Lead Auditor, and a certification auditor, is the same all around the world, and this article will provide you further explanation about becoming a certification auditor:
- How to become ISO 27001 Lead Auditor https://advisera.com/27001academy/knowledgebase/how-to-become-iso-27001-lead-auditor/
Quality manual and ISO 9001:2015
Answer:
Two things:
First, just because ISO 9001: 2015 no longer requires the existence of a quality manual does not mean that its existence is not allowed. All the companies I have worked with have maintained the quality manual despite the transition to ISO 9001: 2015. You can keep your quality manual after updating it.
Second, you can create a Formats/Records register, a kind of master list of all Formats/Records in use in your organization
The following material will provide you information about the quality manual:
Answer:
Each organization has the authority to set the requirements for their internal auditors. Only your organization has the legitimacy to set the requirements applicable to your internal auditors. Even ISO 19011 removed the word competence from the definition of auditor. That said, it is wise to set as minimum requirements for internal auditors that they should know the standard (ISO 9001:2015) and they should know auditing practices. Your organization can ask for any evidence that they know, or studied ISO 9001:2015.
The following material will provide you information about internal audits:
Respuesta: El principal objetivo de ISO 27001 es la protección de la información, por tanto, cualquier empresa, de cualquier sector, puede implementar y certificar este estándar, porque todas las compañías tienen información y tienen que protegerla, incluyendo las empresas de servicios y soporte. ¿Por qué? Pues porque este estándar puede proporcionar beneficios a tu negocio, algunos de ellos, por ejemplo: Cumplimiento, marketing, reducción de costes, estándarización de procesos. Para más información sobre los beneficios que aporta este estándar, puedes leer este artículo “Four key benefits of ISO 27001 implementation” : https://advisera.com/27001academy/knowledgebase/four-key-benefits-of-iso-27001-implementation/
You don´t need to follow any format, just comply with the requirements of the standard regarding the policy document, among them to be appropiate to the purpose and context of the organization and aligned with the strategic direction of the organization.
2nd one is, should i maintain individual files for each policy??
Answer:
Policy for ISO 9001:2015 should be just one for the whole organization, unless you implement other standards, so you can have a policy for each one.
3rd one is, for risk-based thinking, will I also preserve the papers of the meetings, we attended to discuss on RBT???
You can keep the minutes of the meetings as a record that validates that you carried out a risk-ba sed assessment, athough this is not a mandatory requirement in ISO 9001:2015.
ISO 9001:2015 doesn´t require a Business Continuity Plan to the organizations. That being said, a BCP can help organizations to recognize, mitigate and address risks to your business. Also some customers may require a BCP to their suppliers so it will depend on the company to satisfy this expectation/need.
If you already are a qualified ISO 9001 lead auditor you only have to evidence competence on ISO 27001 to be able to audit an ISMS, and implementing an ISMS is one way to evidence such competency.
Validation and Verification of Design and Development
The previous provided answer is still applicable in your case.
Use of ISO 45001 Toolkit in transition
Should we use the document sequentially when we have some procedures existing?
Answer:
If you are migrating from OHSAS 18001 to ISO 45001 using our toolkit then you are correct, if you already have existing procedures in place then reviewing these first before using the toolkit procedures. There is a helpful whitepaper on the transition process that can help you to organize the steps you will go through during the transition, including review of existing documents.