-A.12.4.1, A.12.4.3 Logs of user activities, exceptions, and security events
This mean, we are required to have a centralized log management system in place e.g. SIEM?
Answer: No. Centralized log management system is one of the solutions that you can use to fulfill these controls if they are applicable, but depending on the size, resources and requirements of your organization, you can manage the logs provided by your applications and systems in decentralized form. Additionally, you also may have situations where you do not use systems to log information, like occurrence books to record physical access.
The procedure manual, context and interested parties
Answer:
The standard has several requirements for documented procedures but, it does not require documented procedure for each clause. For those clauses that require documented procedures, they usually define the content of the procedure and the key requirements that the procedure must cover. For more information, see: 7 steps in writing QMS policies and procedures for ISO 9001 https://advisera.com/9001academy/blog/2015/03/10/7-steps-in-writing-qms-policies-and-procedures-for-iso-9001/
As far as context of the organization is concerned, you need to gather relevant people in the organization and determine internal and external issues that affect Quality Management System. For more information, see: How to define the context of the organization in IATF 16949:2016 https://advisera.com/16949academy/knowledgebase/how-to-define-the-context-of-the-organization-in-iatf-169492016/
Matrix for communication is not really a requirement in ISO 9001, however, if you decide to make it, the best way is to create a table where in one column you will list all relevant roles in the QMS (Quality Management System) and in each row in the table will represent one responsibility for communication, for example communicating Quality Policy. Then you can put check marks to mark which role is responsible for which communication.
I'm not sure what you mean by Quality Reports and what is the content of this record, but according to clause 8.6 in ISO 9001:2015 that defines requirements for production process, the organization must maintain the following documented information:
- characteristics of the product to be produced or service to be provided
- records about customer property
- production/service provision change control records
If the Quality Report serves to meet one or more of the above mentioned requirements, than it is mandatory to have it. On the other hand, if it is used to monitor or measure some of the parameters in the production process and it is mentioned in the production procedure, than it can also be considered as a mandatory document.
Answer: ISO 27001 does not require to write a separate document for roles and responsibilities, that's why there is no specific template in the toolkit defining roles and responsibilities
Besides the general roles and responsibilities defined in the Information Security Policy template, all other detailed responsibilities are defined in each template every time an specific activity is required to be performed. Every time you find the field "[job title]" in a template this means that you have to define who has the responsibility to perform the activity described in the sentence. For example, in the sentence:
"[job title] must document the following in the Statement of Applicability: ...", you have to define which role in your organization has the r esponsibility to fill the Statement of Applicability.
By the way, with the toolkit you bought you also have the access to video tutorial that can help you fill your documentation. You can find these tutorials in Conformio, it the menu "Repository", in folder "Video tutorials" - see what you need to click here: https://www.screencast.com/t/T5rLxMgc3UJz
SoA update
Answer: Yes. The SoA is a living document that must be updated as required to reflect the organization's approach towards information security, but you have to ensure that any modification to the SoA is justified and formally approved and recorded as defined in your document control procedure.
When it comes to changes in documentation, you should follow your existing procedure for document and record control. The changes you are mentioning are related to the clause 6.3 Planning of changes which refers to changes in the processes and the QMS. This clause doesn't required documented information, but it would be beneficial if you would describe in the manual how the changes in the QMS are planned and executed, but you don't have to develop any form and even if you decide to develop it, it doesn't have to cover all requirements of the clause.
Defining responsibilities for ISO 9001 requirements
To be somewhat clear, every other departments (not the HR) of an organization has employees under its control. On the issue of competence Clause 7.2 of the standards it requires to retain documented information as evidence. of competence. Somebody says, I could not make that a part of my audit question since it should be the HR department who must be audited on that matter."
Answer:
There are some requirements that are specific for some processes, like clause 8.5 fro production process, or clause 8.4 for purchasing process. However, there are also requirements that should be applied throughout entire QMS (Quality Management System) such as requirements for control of documented information.
Requirements for competence can be met in different ways in different companies, for example, you can have an HR department that is responsible for the requirements (and this is more common or you can have these requirements met on the level of each department or process. Depending on who is responsible for keeping the records about the competence, you need to required them from appropriate person. If the organization has HR department, they are probably in charge of the competence records.
Since the standard doesn't have any requirements regarding finance and accounting processes, you don't have to document them or even include them in the scope of your QMS (Quality Management System). It is enough to identify them as a supporting processes for your main processes.
El primer paso que se necesita llevar a cabo es obtener el apoyo de la alta dirección. Sin este soporte la implementación de ISO 9001 muy probablemente fallará.
Otro paso crucial para asegurar que la implementación es satisfactoria, es identificar todos los requisitos que existen para el SGC de la organización. Estos incluyen los requisitos de los clientes, así como otros requerimientos como son los regulatorios y las necesidades referidas a la cultura de la empresa. Para hacer esto, es posible realizar un análisis GAP (análisis de brecha) para comparar lo que la empresa ya está cumpliendo con los requerimientos de ISO 9001:2015 y ver qué requerimientos faltan por cumplir.
Para más información, vea los siguientes artículos: