Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... icable to testing and calibration. Both ISO 17025 and ISO 13485 are competency-based standards with some overlap. Typically an medical device manufacturer does not need ISO 17025 accreditation, however when it comes to testing medical devices many of the ISO 71025 practices are beneficial.
For some more information on ISO 17025 see this Q&A reply and links within: https://community.advisera.com/topic/17025-vs-13485/
... ... ormation in the form of peopleâs knowledge), while the IT team is also responsible for running recovered systems and networks.
As you can see, in terms of a BCP, a better strategy would be for the infosec team to help define IT-related information security objectives to be achieved by the IT team.
For further information, see:
... in the Statement of Applicability are those from the 2022 version of ISO 27001.
This 2017 version refers to the British version of ISO 27001:2013 (this version's official name is BS EN ISO/IEC 27001:2017).
The 2022 version of ISO 27001 has 93 controls in its Annex A, against 114 controls from the 2013 version.
For further information, see:
ISO 27001 does not prescribe risk assessment to be performed over identified nonconformities, so a company is not obliged to perform it.
This article will provide you with further explanation about handling non-conformities:
... 7001 2013 vs. 2022 revision – What has changed? https://advisera.com/27001academy/blog/2022/02/09/iso-27001-iso-27002/
This material can also help you:
HI there, I have been qualified as a Lead Auditor on 2013 objectives, can 2013 objectives still active and organisation can be certified with that objectives?
Please note that the standard does not require a gap analysis between two versions of the standard to be performed.
For analysis between these two versions, we suggest you these documents:
This tool can also help you:
You can continue with the surveillance audit according to the ISO 27001:2013 standard by 10 August 2023.
But please note that you need to make the transition to the 2022 revision of the standard by October 31, 2025.
For further information, see:
... analysis vs internal audit and the different perspectives of each. Is the checklist the same? With additional column in the case of internal audit to write what is actually being found and observed. Is this right?
C) I was also interested in the different ways to organize an internal audit: department by department, process by process or clause by clause. I am wondering when it is best to choose which anda whether there is such a thing a department x clause and process x clause matrices.