If it's required,kindly oblige me ways to go about it.
Answer: ISO 22301 does not require the elaboration of a manual, and we do not recommend organizations to adopt one, because:
- merging required documents in a single document makes them no easier to read;
- the longer the documents are, the smaller the chance someone will read them because not every BCMS document is intended for everyone in an organization;
- since individual BCMS documents change rather often, it would be a nightmare to update such handbook so frequently.
Answer:
I have not seen the nonconformance. Looking into clause 10.2 I can guess what the intention of the auditor was. Please, check the first part of clause 10.2 – “When a nonconformity occurs” it is about the occurrence of a nonconformity, not about corrective action. When a nonconformity occurs, your organization should update risks and opportunities determined during planning, if necessary. A nonconformity is the manifestation of a risk that actually happened. Was that risk initially determined? Was that risk correctly classified and evaluated? The nonconformity can be about something that you overlooked during the initial risk determination. Waiting for an annual revision exercise can be too late to act.
The following material will provide you information about risks and opportunities:
If some changes happen in your company, like reorganization, then you will need to redetermine the scope of your organization and you will have to analyse how this will affect your entire QMS, including the context of your organization, risks and opportunities, etc.
You don´t need to put in the ISO since it is just a PDF document published by ISO.
To learn more about changes in the scope you can see these articles:
FSMS stands for Food Safety Management System. FSSC stands for Food Safety System Certification. ISO 22000 is not recognized by GFSI (Global Food Safety Initiative), however a certification scheme that uses ISO 22000 as part of its requirements is. This certification is FSSC 22000, and it is recognized by GFSI.
1 - Does Contractual requirements refer to any contract or service agreement we have made with a supplier; for example telecommunications, web hosting?
Answer: Contractual requirements refer to any contract or service agreement relevant to information security, established not only between your organization and suppliers, but with customers and employees too.
2 - Should the list of re gulatory and legal requirements include those required by our clients? For example the Civil Contingencies Act needed for an emergency service or local council we would be providing a serve to.
We have one office at a single address. However we rent a serverspace at XXXXX, equipped with server racks where we place and maintain our own servers. Electricity, heating/cooling, connectivity etc is supplied by the owner of the facility. We do not have 24/7 access. When we encounter a problem during hours that the facility is closed, we have to wait to gain access until the facility is opened again?
In your experience, does such a facility have to be included in the scope.
Answer: If your organization performs the operation and maintenance of these server racks you must include this location in your ISMS scope. If the operation and maintenance of these server racks are outsourced, then you do not need to include this location in your ISMS scope, but it is important to notice that the rented serverspace (and the outsourced operation of servers, if applicable) must be considered in the risk assessment (the risk assessment will help you to insert applica ble security clauses into the agreement with the service provider).
Answer: Our ISO 27001 Documentation toolkit covers information security in general and it is sufficient also to provide security for cloud environments, but if you have specific requirements for cloud security (e.g., laws, regulations, and customers requirements), then we recommend our ISO 27001 & ISO 27017 & ISO 27018 Cloud Documentation Toolkit. In the links bellow you can access a free demo of both toolkits:
- ISO 27001 Documentation toolkit https://advisera.com/27001academy/iso-27001-documentation-toolkit/
- ISO 27001 & ISO 27017 & ISO 27018 Cloud Documentation Toolkit https://advisera.com/27001academy/iso-27001-iso-27017-iso-27018-cloud-documentation-toolkit/