Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Risk assessment methodology


    Answer:

    The standard does not requires organizations to adopt risk assessment methodology, so there are no requirements on how the organization will define its criteria for probability, consequence or any other element of risk. The organization itself can define the criteria for probability and consequence if it decides to apply them at all since they are not required. All the organization needs to do is to identify risks and opportunities and take actions to address them, how it will be done is not defined by the standard and the organization has full liberty to do it as it finds the most suitable.

    As far as the certification auditor is concerned, he or she can only audit the QMS (Quality Management System) against the requirements of the standard and cannot interfere or require c hanges in the methodology that the organization adopted.

    For more information, see: How to address risks and opportunities in ISO 9001 https://advisera.com/9001academy/blog/2016/06/21/how-to-address-risks-and-opportunities-in-iso-9001/
  • Audit resources and BCM material


    En general es un buen material. la expectativa que no se realmente si sea demasado pedir, es tener un caso practico desarrollado, un modelo basado en un estudio o aplicacion real de auditoria.
    Soy uno de los profesionales que tengo certificacion en iso27001, y mi dia adia no me ha permitido ejercer una auditoria y me da susto equivocarme, es como tener un taller de ejercicios para llevarlos a la practica.
    Aprovecho este oportunidad tambien para comentar la necesidad que tengo de un plan de continuidad del negocio para un servicio de outsourcing en recursos TI. Tema que lo expuesto por sus esquemas de contacto.

    (Overall a good material. The expectation that is not really if it is too much to ask, is to have a practical case developed, a model based on a study or real application of audit.
    I am one of the professionals that I have certification in iso27001, and my day to day has not allowed me to exercise an audit and I get scared to err, it is like having an exercise workshop to take them to the practice.
    I take this opportunity al so to comment on my need for a business continuity plan for an outsourcing service in IT resources. Subject that exposed by their contact schemes)

    Answer: For practical examples of how to perform an internal audit I suggest you to attend our free ISO 27001:2013 Internal Auditor Course at this link: https://advisera.com/training/iso-27001-internal-auditor-course/

    Additionally our knowledge base has very interesting articles that can help you, like:
    - How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
    - How to make an Internal Audit checklist for ISO 27001 / ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/
    - Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/

    Regarding business continuity plan, I suggest you to take a look at the free demo of our Business continuity plan at this link: https://advisera.com/27001academy/documentation/business-continuity-plan/

    This template can help you to define precisely how an organization will manage incidents in the case of a disaster or other disruption of business, and how it will recover its critical activities within set deadlines.

    This article will provide you further explanation about business continuity planning:
    - How to write business continuity plans? https://advisera.com/27001academy/blog/2010/04/08/how-to-write-business-continuity-plans/
    - Business continuity plan: How to structure it according to ISO 22301 https://advisera.com/27001academy/knowledgebase/business-continuity-plan-how-to-structure-it-according-to-iso-22301/

    These materials will also help you regarding Business Continuity Planning:

    - Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/
    - Writing a business continuity plan according to ISO 22301 [free webinar] https://advisera.com/27001academy/webinar/writing-a-business-continuity-plan-according-to-iso-22301-free-webinar-on-demand/
  • CMMi toolkit


    Answer: We work with ISO management standards related documents, so unfortunately we do not have a CMMI Toolkit in our products portfolio.

    2- Do you have any or recommend any CMMI toolkit providers?

    Answer: Unfortunately I do not have much knowledge in this specific market to provide a recommendation, but you can take a look at this link at Carnegie Mellon University (the institutions that developed CMMI): https://seir.sei.cmu.edu/toolkit/PurposesofthisToolkitDocument.html
  • Why is top management important for QMS


    Answer:

    The top management involvement in the QMS is essential for effectiveness of the QMS. Provision of resources, defining Quality Policy and objectives, assigning roles and responsibilities are some of the responsibilities of the top management and cannot be done by someone else. Involvement of the top management is necessary for planning, check and act phase of the PDCA cycle and without them, these phases cannot be properly conducted and the QMS will only be formally implemented and fail to provide any benefit to the organization. For more information, see: To what extent should top management be involved in your QMS? https://advisera.com/9001academy/blog/2016/11/22/to-what-extent-should-top-management-be-involved-in-your-qms/

    The best way to convince the top management to participate in QMS is to present them with benefits that ISO 9001 b rings to the company and explain them that QMS wont work without their active participation. For more information, see: How to get Management Buy-in for ISO 9001 https://advisera.com/9001academy/blog/2014/09/02/get-management-buy-iso-9001/
  • Top management role in QMS


    Answer:

    The top management pays a key role in QMS (Quality Management System), when it comes to planning and maintaining the system. Entire clause 5 is dedicated to the obligations of the top management, such as providing resources, assigning responsibilities, taking accountability for the QMS effectiveness, etc.

    Other clauses as well require involvement of the top management, such as for determining context of the organization, addressing risks and opportunities and, finally, management review. Check phase of the PDCA cycle that is prescribed by the standard includes management review where the effectiveness of the QMS is to be considered and actions for QMS improvement to be proposed. This is impossible to perform without the top management as they are the ones to determine what actions will be taken and to provide resources for these actions and t he entire QMS.

    For more information, see: To what extent should top management be involved in your QMS? https://advisera.com/9001academy/blog/2016/11/22/to-what-extent-should-top-management-be-involved-in-your-qms/
  • Knowing ISO 27001

    Considering also the specification you provided:

    >"In their first response to the forum they suggested:
    >This article will provide further explanations on the integration of management systems:
    > - How to implement integrated management systems / ... / -
    >But I can not open this article. On the other hand in the suggestion they gave I did not realize if the idea of ​​the study is to analyze which organizations is it possible to integrate the 27001?

    >My specific question was to ask for help in the sense that with your broad vision to see a topic that I could take advantage of to do a study and thus be able to make my thesis, here what I wanted to take advantage of is a theme that helps make you see The added value that is the implementation of this regulation 27001 since here in Portugal are very few organizations that have implemented. This article / study is to serve as ramp for which companies have given in bulk."

    First of all. I'm sorry about the problem with the link. Here is the correct link:
    - How to implement integrated management systems https://advisera.com/ 7001academy/blog/2015/10/05/how-to-implement-integrated-management-systems/

    About your question: the point is not to analyse in which organizations it is possible to integrate the 27001 (the standard is designed to be applicable to organizations of any kind or size), but why, so you can evidence the added value ISO 27001 implementation can bring to an organization (what I think is your main interest in your thesis).

    Why would an organization implement an standard if it is not mandatory? The general benefits are:
    - Obtain a competitive edge
    - Improve internal organization
    - Reduce losses due to incidents
    - Assure compliance with legal requirements

    Considering each of these benefits, you could develop a thesis identifying specific points related to a specific organization or industry.

    For more information about ISO 27001 benefits, please see: Four key benefits of ISO 27001 implementation https://advisera.com/27001academy/knowledgebase/four-key-benefits-of-iso-27001-implementation/
  • Auditoria de Certificación

    El manual de funciones estipula las cualificaciones y perfiles de los cargos. Cualquier persona en la organización que esté relacionada con la realización de un producto debe de poseer un perfil del cargo, éste incluye la lista de las responsabilidades y autoridades para cada uno de los cargos. Por lo tanto, la descripción documentada de un puesto o perfil de cargo, debería de contener: título, subordinación, cualificaciones externas requeridas, cualificaciones internas requeridas, lista de responsabilidades y lista de autoridades. Sin embargo, es importante tener en cuenta que la norma ISO 9001:2015 no exige documentación sobre el perfil de los cargos
  • Communication template in ISO 22301 Toolkit


    Answer: Communication is a activity that is performed by many processes in business continuity, with different purposes, so we do not have a centralized communication plan to not overhead people responsible for communication with activities that may not be part of their attributions.

    Instead of that, you will find communication plan elements spread in many documents in the toolkit:
    - Appendix 1 – Incident Response Plan
    - Appendix 2 – Incident Log
    - Appendix 5 – Key Contacts

    In the root folder of the toolkit you bought you can find the List of Documents file that will show you which clause of the standard is covered by each document of the toolkit.
  • ISO 27001 and Artificial Intelligence


    1Does ISO 27001 addresses AI from a human factor in the Annexis and which one?

    Answer: ISO 27001 does not treat requirements and controls in terms of technologies that can be used, but in terms of security objectives to be achieved. So there is no control that explicitly address AI, but this does not prevent AI to be used in any one of them if you can show that the use of AI can fulfil the stated objective (e.g. if you can show that AI can successfully review logs of human activity in search for anomalies, you can address controls A.12.4.1 (Event logging) and A.12.4.3 (Administrator and operator logs)).

    2Shall we add AI as a add on to the ISO27001 ISMS compliance?

    Answer: Using AI is not mandatory for ISO 27001, but you can make such kind of statement if you can demonstrate how AI can fulfil specific requirements or controls of the standard.

    This article will provide you further explanation about s pecific solutions in ISO 27001:
    - The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

    These materials will also help you regarding controls in ISO 27001:
    - ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
    - Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
  • EA 35 code

    EA 33 stands for European Accreditation 33, which is used to assign the scope of an organization’s business in the information technology area. This code is used to help assign a registrar auditor with appropriate experience to a company. For ISO 27k certificate EA 33 you can understand an ISO 27k certified organization which main business is related to information technology.

Page 887-vs-13485 of 1127 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +