Respuesta: El principal objetivo de ISO 27001 es la protección de la información, por tanto, cualquier empresa, de cualquier sector, puede implementar y certificar este estándar, porque todas las compañías tienen información y tienen que protegerla, incluyendo las empresas de servicios y soporte. ¿Por qué? Pues porque este estándar puede proporcionar beneficios a tu negocio, algunos de ellos, por ejemplo: Cumplimiento, marketing, reducción de costes, estándarización de procesos. Para más información sobre los beneficios que aporta este estándar, puedes leer este artículo “Four key benefits of ISO 27001 implementation” : https://advisera.com/27001academy/knowledgebase/four-key-benefits-of-iso-27001-implementation/
You don´t need to follow any format, just comply with the requirements of the standard regarding the policy document, among them to be appropiate to the purpose and context of the organization and aligned with the strategic direction of the organization.
2nd one is, should i maintain individual files for each policy??
Answer:
Policy for ISO 9001:2015 should be just one for the whole organization, unless you implement other standards, so you can have a policy for each one.
3rd one is, for risk-based thinking, will I also preserve the papers of the meetings, we attended to discuss on RBT???
You can keep the minutes of the meetings as a record that validates that you carried out a risk-ba sed assessment, athough this is not a mandatory requirement in ISO 9001:2015.
ISO 9001:2015 doesn´t require a Business Continuity Plan to the organizations. That being said, a BCP can help organizations to recognize, mitigate and address risks to your business. Also some customers may require a BCP to their suppliers so it will depend on the company to satisfy this expectation/need.
If you already are a qualified ISO 9001 lead auditor you only have to evidence competence on ISO 27001 to be able to audit an ISMS, and implementing an ISMS is one way to evidence such competency.
Validation and Verification of Design and Development
The previous provided answer is still applicable in your case.
Use of ISO 45001 Toolkit in transition
Should we use the document sequentially when we have some procedures existing?
Answer:
If you are migrating from OHSAS 18001 to ISO 45001 using our toolkit then you are correct, if you already have existing procedures in place then reviewing these first before using the toolkit procedures. There is a helpful whitepaper on the transition process that can help you to organize the steps you will go through during the transition, including review of existing documents.
ISO 45001, like all ISO management system standards, does not cover the specifics of what legal requirements are to be met, or how to meet them. That being the case the requirements of ISO 45001 are that you identify what compliance obligations your organization has (including legal obligations), and then to determine how to comply with these obligations. So, your first step is to determine what are the legal compliance obligations in the dental college environment.
The Standard requires a documented procedure for the Management Review. It will be recommended to supplement the Management Review procedure with a SOP if the procedure stated in the Quality Manual is brief.
Answer:
Implementing ISO 9001 in a consulting business is very similar to implementing it in any service business. The trick is applying the process approach and seeing the business as a set of processes. What does the business do to be known by potential customers? How does the business understand customer requirements and develop an offer? How does the business set a project team to handle a consultancy appointment? How does the business develops, controls and terminates a consultancy project? And so on…
The following materials will provide you more information about implementing a quality management system: