Could you please give an advice about how to tackle this problem??
Answer: For such small number of employees, the most efficient way is to include all organization in the scope, because the effort to manage the interfaces and interdependencies with the areas outside the scope will be greater than consider all the areas of the organization. Customers and logistic partners are considered as interested parties that should be considered in the definition of the scope, not included in the scope itself.
The standard does not requires organizations to adopt risk assessment methodology, so there are no requirements on how the organization will define its criteria for probability, consequence or any other element of risk. The organization itself can define the criteria for probability and consequence if it decides to apply them at all since they are not required. All the organization needs to do is to identify risks and opportunities and take actions to address them, how it will be done is not defined by the standard and the organization has full liberty to do it as it finds the most suitable.
As far as the certification auditor is concerned, he or she can only audit the QMS (Quality Management System) against the requirements of the standard and cannot interfere or require c hanges in the methodology that the organization adopted.
En general es un buen material. la expectativa que no se realmente si sea demasado pedir, es tener un caso practico desarrollado, un modelo basado en un estudio o aplicacion real de auditoria.
Soy uno de los profesionales que tengo certificacion en iso27001, y mi dia adia no me ha permitido ejercer una auditoria y me da susto equivocarme, es como tener un taller de ejercicios para llevarlos a la practica.
Aprovecho este oportunidad tambien para comentar la necesidad que tengo de un plan de continuidad del negocio para un servicio de outsourcing en recursos TI. Tema que lo expuesto por sus esquemas de contacto.
(Overall a good material. The expectation that is not really if it is too much to ask, is to have a practical case developed, a model based on a study or real application of audit.
I am one of the professionals that I have certification in iso27001, and my day to day has not allowed me to exercise an audit and I get scared to err, it is like having an exercise workshop to take them to the practice.
I take this opportunity al so to comment on my need for a business continuity plan for an outsourcing service in IT resources. Subject that exposed by their contact schemes)
This template can help you to define precisely how an organization will manage incidents in the case of a disaster or other disruption of business, and how it will recover its critical activities within set deadlines.
Answer: We work with ISO management standards related documents, so unfortunately we do not have a CMMI Toolkit in our products portfolio.
2- Do you have any or recommend any CMMI toolkit providers?
Answer: Unfortunately I do not have much knowledge in this specific market to provide a recommendation, but you can take a look at this link at Carnegie Mellon University (the institutions that developed CMMI): https://seir.sei.cmu.edu/toolkit/PurposesofthisToolkitDocument.html
Why is top management important for QMS
Answer:
The top management involvement in the QMS is essential for effectiveness of the QMS. Provision of resources, defining Quality Policy and objectives, assigning roles and responsibilities are some of the responsibilities of the top management and cannot be done by someone else. Involvement of the top management is necessary for planning, check and act phase of the PDCA cycle and without them, these phases cannot be properly conducted and the QMS will only be formally implemented and fail to provide any benefit to the organization. For more information, see: To what extent should top management be involved in your QMS? https://advisera.com/9001academy/blog/2016/11/22/to-what-extent-should-top-management-be-involved-in-your-qms/
The best way to convince the top management to participate in QMS is to present them with benefits that ISO 9001 b rings to the company and explain them that QMS wont work without their active participation. For more information, see: How to get Management Buy-in for ISO 9001 https://advisera.com/9001academy/blog/2014/09/02/get-management-buy-iso-9001/
Top management role in QMS
Answer:
The top management pays a key role in QMS (Quality Management System), when it comes to planning and maintaining the system. Entire clause 5 is dedicated to the obligations of the top management, such as providing resources, assigning responsibilities, taking accountability for the QMS effectiveness, etc.
Other clauses as well require involvement of the top management, such as for determining context of the organization, addressing risks and opportunities and, finally, management review. Check phase of the PDCA cycle that is prescribed by the standard includes management review where the effectiveness of the QMS is to be considered and actions for QMS improvement to be proposed. This is impossible to perform without the top management as they are the ones to determine what actions will be taken and to provide resources for these actions and t he entire QMS.
>"In their first response to the forum they suggested:
>This article will provide further explanations on the integration of management systems:
> - How to implement integrated management systems / ... / -
>But I can not open this article. On the other hand in the suggestion they gave I did not realize if the idea of the study is to analyze which organizations is it possible to integrate the 27001?
>My specific question was to ask for help in the sense that with your broad vision to see a topic that I could take advantage of to do a study and thus be able to make my thesis, here what I wanted to take advantage of is a theme that helps make you see The added value that is the implementation of this regulation 27001 since here in Portugal are very few organizations that have implemented. This article / study is to serve as ramp for which companies have given in bulk."
First of all. I'm sorry about the problem with the link. Here is the correct link:
- How to implement integrated management systems https://advisera.com/ 7001academy/blog/2015/10/05/how-to-implement-integrated-management-systems/
About your question: the point is not to analyse in which organizations it is possible to integrate the 27001 (the standard is designed to be applicable to organizations of any kind or size), but why, so you can evidence the added value ISO 27001 implementation can bring to an organization (what I think is your main interest in your thesis).
Why would an organization implement an standard if it is not mandatory? The general benefits are:
- Obtain a competitive edge
- Improve internal organization
- Reduce losses due to incidents
- Assure compliance with legal requirements
Considering each of these benefits, you could develop a thesis identifying specific points related to a specific organization or industry.
El manual de funciones estipula las cualificaciones y perfiles de los cargos. Cualquier persona en la organización que esté relacionada con la realización de un producto debe de poseer un perfil del cargo, éste incluye la lista de las responsabilidades y autoridades para cada uno de los cargos. Por lo tanto, la descripción documentada de un puesto o perfil de cargo, debería de contener: título, subordinación, cualificaciones externas requeridas, cualificaciones internas requeridas, lista de responsabilidades y lista de autoridades. Sin embargo, es importante tener en cuenta que la norma ISO 9001:2015 no exige documentación sobre el perfil de los cargos
Communication template in ISO 22301 Toolkit
Answer: Communication is a activity that is performed by many processes in business continuity, with different purposes, so we do not have a centralized communication plan to not overhead people responsible for communication with activities that may not be part of their attributions.
Instead of that, you will find communication plan elements spread in many documents in the toolkit:
- Appendix 1 – Incident Response Plan
- Appendix 2 – Incident Log
- Appendix 5 – Key Contacts
In the root folder of the toolkit you bought you can find the List of Documents file that will show you which clause of the standard is covered by each document of the toolkit.
ISO 27001 and Artificial Intelligence
1Does ISO 27001 addresses AI from a human factor in the Annexis and which one?
Answer: ISO 27001 does not treat requirements and controls in terms of technologies that can be used, but in terms of security objectives to be achieved. So there is no control that explicitly address AI, but this does not prevent AI to be used in any one of them if you can show that the use of AI can fulfil the stated objective (e.g. if you can show that AI can successfully review logs of human activity in search for anomalies, you can address controls A.12.4.1 (Event logging) and A.12.4.3 (Administrator and operator logs)).
2Shall we add AI as a add on to the ISO27001 ISMS compliance?
Answer: Using AI is not mandatory for ISO 27001, but you can make such kind of statement if you can demonstrate how AI can fulfil specific requirements or controls of the standard.