Answer: Our ISO 27001 & ISO 27017 & ISO 27018 Cloud Documentation Toolkit templates can help you cover the requirements from CSA Star certification related to ISO 27001, ISO 27017, and ISO 27018 standards identified in the Cloud Controls Matrix (CCM).
ISO 9001:2015 gives a lot of freedom in treating risks and opportunities. So, you will see different possible approaches.
First, what is a risk or an opportunity? A negative/positive deviation from an expected due to uncertainty is a risk/opportunity. The expected are desired results, are the outcomes of a QMS.
Second, ISO 9001 mentions risks/opportunities at three levels (clause 5.1.2b – risks about products and services. Clause 4.4.1f – risks about process outcomes. Clause 6.1.1 – risks about QMS over all results)
Third, with FMEA, with a conversation/discussion about internal and external issues, or with performance analysis one organization can determine relevant risks and opportunities and then evaluate them and decide what to do with them.
The following material will provide you information about risks and opportunities
Respuesta: Basicamente ISO 27001 trata sobre riesgos relacionados con la información, y en tu caso, algunos riesgos están en el lado del proveedor (como por ejemplo ataques DoS, fallos hardware, fallos de suministro eléctrico, etc), por lo que tendrías que transferir estos riesgos. Pero también existen otros riesgos en tu lado, que también tienes que tratar, por ejemplo riesgos relacionados con la conexión remota a la nube, con los PCs usados para la operación de los servicios en la nube, las aplicaciones que estás usando, la concienciación de los empleados en materia de seguridad de la información, etc.
También este otro sobre riesgos “Evaluación y Tratamiento del riesgo en ISO 27001 - 6 pasos básicos” : https://adv isera.com/27001academy/es/knowledgebase/evaluacion-y-tratamiento-del-riesgo-en-iso-27001-6-pasos-basicos/
ISO 9001:2015 considers two types of documented information: documentation to maintain – they give instructions about how to act in the future; and documentation to retain – they are records about what happened.
Organizations should consider mandatory documented information required by ISO 9001:2015 and non-mandatory documented information that can be decided as necessary or useful for the effectiveness of the quality management system. The first link below gives a complete answer.
The following material will provide you information about documented information:
Regarding to the part of the auditors -There are two types of auditors:
Internal auditors, who carry out internal audits, and lead auditors, who work for certification bodies and perform the certification audits.
Regarding internal auditors - There are not mandatory qualifications to become an internal auditor, but certain skills, competencies, and qualifications can help a person become an internal auditor. A combination of knowledge of the ISO 9001:2015 internal process knowledge and attention to detail remain the primary attributes.
Regarding the Lead auditor - To become a Lead Audito r first you need to have experience in applying ISO principles, procedures and techniques in the auditing. The next thing a candidate needs to become a lead auditor is to pass the Certified ISO 9001 Lead Auditor exam. This Lead Auditor course ISO 9001 is offered by many accredited bodies like certification bodies or approved training organizations. The scheme more widely offered by the main auditor registration organzations is a qualification scheme that requires you to pass a 5 day lead auditor class, demonstrate with a resume that you have work experience of about 4 years, that you have more specific work experience of about 2 years (e.g. in environmental sectors that you want to audit in) and then participate in audits to demonstrate audit experience.
If you are interested in working as a consultant implementing ISO 9001:2015 you can attend a Lead Implementer Course, since that course can help you to understand and implement the standards and then get the Lead Implementer certificate in order to prove your competence. Also, a Project Manager Certificate can be helpful because you will learn how to run projects.
We have aavailable this free on-line course – ISO 9001:2015 Foundations Course: https://advisera.com/training/iso-9001-foundations-course/ After attending the course you can obtain a certificate that proves that you passed the exam.
7.5.1 b) Información documentada determinada por la organización como necesaria
Muchas gracias por las aclaraciones!
Procedure for Document and Record Control
This is what the Paragraph states:
Each external document, which is necessary for the planning and operation of the ISMS, must be recorded in the incoming mail register. The incoming mail register must contain the following information: (1) document number, (2) sender, (3) document name, (4) date of receipt, (5) name of the person whom the document has been forwarded.
Answer:
An incoming mail register is a record used to identify any information received by the organization from external parties, either on physical or electronic media. Examples of incoming mail are hard copies of equipment manuals you use or standards you must comply with, or a customer e-mail requiring changes in a project's specification.
Your understanding is right about not all mail coming into the organization need to be in the incoming mail register. Examples of external documents necessary for the planning and operation of the ISMS are the ISO 27001 standard, customer requirements for service delivery, and audit reports from your certification body.
BYOD policy
Answer:
In section 3.4, I understand that you are referring to the Information Classification Policy in the text "classified information must be additionally protected according to the [Information Classification Policy]". Considering that, this template can be found in folder 08 Annex A A.8 Asset management.
Incident Management Procedure
Answer:
The Incident Management Procedure only covers requirements of ISO 27001, and for the EU GDPR & ISO 27001 Integrated Documentation Toolkit, the incident management process also must cover GDPR requirements (Articles 4(12), 33, 34), so for this toolkit yo can use the template A.16 Data Breach Response and Notification Procedure, located in folder 11 Security Controls of your toolkit.