(I would like you to help me understand A 6.1.2 more fully. By my understanding, it concerns access rights to conflicting information, for example: Purchasing department, conflict of access to the financial department. I am creating an array that informs the access rights and control barriers indicated. I'm in the right way?)
Answer: Seu entendimento está correto. A segregação de funções se faz necessárias para que uma única pessoa não tenha controle ou conhecimento de todas as etapas de um processo crítico para o negócio.
(Your understanding is correct. The segregation of functions is necessary so that a single person does not have control or knowledge of all the steps of a process criti cal to the business.)
Lo importante es encontrar la causa raíz de la noconformidad con el fin de establecer las acciones correctivas pertinentes, luego si la causa la encuentras antes de contestar las 5 preguntas no significaría un problema, ni mucho menos una noconformidad.
La técnica de los 5 porqués como bien indica usted, puede ser utilizada para encontrar la causa raíz de la noconformidad, pero se trata sólo de una técnica, ya que existen otras herramientas como la del diagrama del espinazo que pueden ayudar a identificar las causas. Es más, cuando encontramos una noconformidad el origen podría estar en más de una causa raíz.
8.4 Control of externally provided processes, products and services
1) Would this include control of purchased raw materials? In the case of us as a commercial printer: paper, ink, etc.? I can not find another section that specifies raw materials, but thought it might fall under the category of “products”.
2) Also, the the text of sections 8.7 and 10.2 which cover non-conformities seem to focus on final product and not on purchased product or services (including raw materials). Is it correct that the same procedures can be followed for non-conformities on purchased items as well as final outputs?
Answer:
1) Yes, it includes purchased products such as raw materials, components, supplies, machinery and equipment, maintenance, etc.
2) You are correct. Nonconformities can be found not only in final outputs but also in both purchased products and supplier performance, so your controls must be based on the prevention of these possible non-conformities.
Un buen manual de calidad debe de proporcionar una visión global del SGC, tiene que ser breve y claro e incluso facilitar el trabajo del auditor. Aunque el manual de calidad ya no es obligatorio en la nueva versión de la norma, podría incluir: el alcance del SGC, los procedimientos documentados establecidos para el SGC y una descripción de la interacción de los procesos.
El primer paso seguía conseguir la aprobación así como el respaldo de la alta dirección para obtener los recursos necesarios para llevar a cabo el proyecto de implementación. Posteriormente se lleva a cabo un análisis GAP o de brecha para saber con qué requisitos cumple en la actualidad su organización y a cuáles necesita dar cumplimiento. Aquí puede encontrar la herramienta gratuita Herramienta de Análisis de Brecha ISO 9001: https://advisera.com/9001academy/es/herramienta-analisis-de-brecha-iso-9001/
Una vez la organización haya determinado esto, entonces puede realizar un Plan de Proyecto, donde se definen tanto los plazos de cada actividad como las responsabilidades. Aquí puede descargar gratuitamente el Plan de Proyecto - Plan de Proyecto para la Implementación de ISO 9001: https://info.advisera.com/9001academy/es/descarga-gratuita/plan-de-proyecto-para-la-implementacion-de-iso-9001-ms-word
What kind of indicators can be used to evaluate your organization’s performance in proactively meet customer changing expectations and needs?
For example, does your organization develops new products? If yes, what is the commercial performance of those products? If they sell well, your organization knows how to be aware and answer to customers’ changing expectations and needs. Another example, if your organization does not lose customers and/or wins new customers, it can also be used to measure the ability to be proactively aware of changing ex pectations and needs Another example, using customer satisfaction assessment.
The following material will provide you information about meeting quality requirements:
When I work with ISO 9001 I try to be aware of opportunities about products and services, about management system objectives or undesirable effects, or about processes. An opportunity is something that can help an organization meet desired results or avoid undesirable results. Imagine that you are having a meeting about sales or commercial performance and you realize that there is a market need that no one is addressing. There is an opportunity to develop and launch a new product to cater that need. Imagine that you are assessing process performance and realize that you can improve productivity by making some changes in the lay-out. That is another opportunity. Normally, you evaluate those opportunities and their return to decide if they deserve your investment and effort.
Today I worked with a company that is evaluating the opportunity to attend and expose their products at two international fairs. Something that they never tried before. It can be an interesting opportunity to increase sales and sell higher value added producs.
The following material will provide you information about risks and opportunities:
I would advice against generalizing to much because than, most likely, you would end up with no responsible or it might happen that two members of your IT department would do the same task twice.
So, my opinion is to have different tasks either assignment to one individual with sufficient knowledge or to more individuals fulfilling more narrower tasks.
Answer: To perform the measurement, first you need to develop a set of measurable objectives, and you can use the Statement of Applicability to document the objectives for your controls (or groups of controls), and you can document the top-level objectives in your Information security policy.
ISO 9000 is a standard about quality management fundamentals and vocabulary, it is not used in certification. Whoever uses ISO 9001 and has vocabulary issues can use it.
ISO 9001 is used in certification and specifies requirements for a quality management system. It can be used to certify any kind of organization because it is generic.
ISO 9004 is a standard that gives guidelines for enhancing an organization's ability to achieve sustained success, it is not used in certification.
The following material will provide you information about ISO 9001: