2. Requirements for Quality Manual at a minimum (without copying the AS9100 standard with wording changes to fit the organization.
Answer:
1. For the required documents I would recommend reading our free whitepaper on the documents required for AS9100: https://info.advisera.com/9100academy/free-download/as9100-rev-d-list-of-mandatory-documents
2. As for the quality manual this is no longer a strict requirement of AS9100 Rev D. However, in clause 4.4.2 the standard does mention a list of documented information that can be collected into a single source document and called a quality manual. This includes: description of relevant interested parties, scope of the QMS, description of organization processes and their application, the sequence of processes and the assignment of responsibilities and authorities for processes.
For some further help w ith implementation check out our project checklist: https://info.advisera.com/9100academy/free-download/project-checklist-for-as9100-rev-d-implementation
Multi controllers
Answer:
“Controllers in common” or “independent controllers” are both processing personal data but independently and for different purposes and there is no requirement to have a document stating their obligations as they are both bound by the controller obligations under GDPR. The GDPR only requires to have such document between controllers and processors or between joint controllers.
This is the reason for which we don`t have such a document in the toolkit. Please no te that the Supplier Data Processing Agreement is not suited to be used in a controller to controller situation.
Incident management procedure - treatment of minor events (3.3)
Answer:
ISO 27001 is not specific on how to record the incidents, which means you can do it in any way that you see fit. This means you could log minor incidents that happen the first time in the Incident log, but in such case I would recommend that you mark separately first-time incidents from those that are happening repeatedly.
SoA - A.6.1.3 - Incident Response Plan
Answer:
Incident response plan is a document needed only if you want to become compliant with ISO 22301, it is not needed for ISO 27001. Therefore, it is not part of ISO 27001 Toolkit (it is a part of ISO 27001 & ISO 22301 Premium Toolkit).
To become compliant with ISO 27001 control A.6.1.3 (Contact with authorities) it is enough to specify in your Statement of Applicability who in your company will be in contact with e.g. police, regulatory agencies, etc. - the standard does not require you to have an extra document for that purpose.
Are Annex A.11 controls mandatory?
Answer:
ISO 27001 says that none of the controls are mandatory, and that you have to apply a control only if there is a reason to do so. The reasons could be risk assessment, contractual or regulatory requirement, or e.g. business decision from your management.
So physical and environmental controls are not mandatory, and you should apply them only if the risks are too high, if you have some client asking you to do this, or if there is some other business reason to do so.
Ensuring contractual and regulatory requirements are met
We received these questions:
>1- Is this documentation mandatory?
Answer: According to ISO 27001, clause 7.5.1 b), documents considered by the organization as necessary for the effectiveness of the ISMS must be considered mandatory.
Said that, contracts, regulations, and laws that may be used as inputs to the risk management process or to define requirements for security controls must be considered mandatory.
>2 - Does this need to be stated in the security policy or can it be left out?
Answer: You can include an overall statement about complying with legal and contractual requirements, but I recommend that you keep this information separate from the Information Security Policy, because otherwise you might need to update the Policy too often.
Business continuity documents for ISO 27001
Answer: Yes, this document is completely enough to become ISO 27001 compliant regarding business continuity.
The document: "operating processes for information and communication technology" in folder 12 of the toolkit talks about a business continuity management strategy as an referential document. There isn’t any template about that strategy, right? Can we delete this referential document about the business continuity management strategy?
Answer: There is no Business Continuity Strategy template in the ISO 27001 Toolkit - feel free to delete this reference. This strategy is part of ISO 27001 & ISO 22301 Toolkit, and is needed only if you want to become ISO 22301 compliant.
Duration of the ISO 22301 review
Answer:
The time of the review of ISO standards varies greatly, but this usually takes between 1 and 3 years.
Lead Implementer Course
Answer:
If you want to develop skills to be a future implementer of a QMS I would like to invite you to start a free online training that Advisera will be launching next September. That training is called Lead Implementer Course. That course is for those that want to develop a management system either as consultants or working inside an organization.
In the meantime the following material will provide you information about ISO 9001 foundations: