Answer: As a BCM manager your main role would be ensuring that the results of Business Impact Analysis and the chosen strategies for business continuity are considered in the construction of the new datacenter. This may mean location definition, infrastructure features (e.g., redundant electrical circuits, use of fire proof material, etc.). Additionally, you have to ensure the documentation and testing of business continuity plans related to the most probable disruption incidents.
Specifically about datacenters I'd suggest the standard TIA 942. It can provide you recommendations regarding datacenter features to ensure different levels of availability that can fulfill your needs. You can buy this standard at this link: https://global.ihs.com/doc_detail.cfm?&input_search_filter =TIA&item_s_key=00414811&item_key_date=860905&input_doc_number=942&inp ut_doc_title=&org_code=TIA#product-de tails-listse of fire proof material, etc.). Additionally, you have to ensure the documentation and testing of business continuity plans related to the most probable disruption incidents.
Specifically about datacenters I'd suggest the standard TIA 942. It can provide you recommendations regarding datacenter features to ensure different levels of availability that can fulfill your needs. You can buy this standard at this link: https://global.ihs.com/doc_detail.cfm?&input_search_filter =TIA&item_s_key=00414811&item_key_date=860905&input_doc_number=942&inp ut_doc_title=&org_code=TIA#product-details-list
BCM awareness
Thanks but I want to know if you have awareness for end users
Service desk escalaton
Answer:
Service Desk is, actually, heavily involved in Incident Management process. In Incident Management - there are two kinds of escalations:
- hierarchical
- functional.
What you are mentioning is - functional. That means - to the group with more expert knowledge. However, there is no requirement i.e recommendation that there must be e.g. three levels of escalation. Adopt it to your own organization. You can have more, as well as less than three.
Read the article "Incident Management in ITIL – solid foundations of operational processes" https://advisera.com/20000academy/blog/2013/05/21/incident-management-itil-solid-foundations-operational-processes/ to learn more about it.
Modification of the Quality Manual in IATF 16949
Answer:
ISO/TS 16949 didn't have any additional requirements for Quality Manual other the ones stated by ISO 9001:2015. Although new ISO 9001 is foundation for IATF 16949 and does not require the manual, IATF 16949 kept this requirement and added basically two requirements to the ones existing in the previous version of the standard:
1. to include extent and type of controls for outsourced processes in description of sequence and interaction of processes; and
2. document indicating where in the QMS the customer specific requirements have been met.
Thanks a lot. Your response has been very helpful.
Internal team for penetration and vulnerability tests
Answer: Yes, the penetration testing and vulnerability tests can be performed by internal employees. Regarding ISO 27001, there is no mandatory requirement demanding that these tests must be performed by a third party. What happens is that you should ensure that these tests are performed by people not directly involved with the process, so you can ensure impartiality since, like internal audits, no one should audit their own work.
We are thinking about certifying our core process – sighttest provided by our stores. Our company has a franchise-structure. Thus each store is its own company. We also have a country support office providing all support processes (eg product, finance, marketing, etc) to our stores. My question is if we can certify the core business provided by the store only, or if we need to include all subprocesses also (of course, it's something we would like to add at least in a second stage). If we then get the ISO 9001:2015 certification, will it then be one per store?
Many thanks for your reply,
Answer:
You can limit the scope of your QMS on only one store only and core processes but in that case, the certificate will apply to this store only since it is assigned to the scope of the QMS. Since every store is a separate legal entity, it is better to certify them all separately, it can cost more in total but it will allow you to go step by step and to create multiple simple systems instead of one complex QMS.
Also, you wont be needing t he consultant help in every store because you can copy the QMS to the similar stores and processes and basically, the only expense will be the certification.
Metodologías aplicación cláusula 4
De la misma manera busco metodologías que ayuden a cumplir con el apartado 4.4 de la norma que hace referencia a la gestión de calidad y sus procesos, por ejemplo una metodología que encontré aquí es el mapeo de procesos.
Mi respuesta:
Antes de determinar el alcance de la organización es necesario abordar las cláusulas 4.1 y 4.2. Por lo tanto, podría seguir estos pasos:
- Para las cuestiones internas y externas se puede usar un análisis DOFA.
- Para determinar las partes interesadas se puede utilizar un análisis PEST.
- Definir cuáles son los productos y servicios de la organización. Por ejemplo, mediante un mapa de procesos.
- Determinar las exclusiones.
- Escribir el alcance: incluyendo las distintas localizaciones de la organización, productos y servicios que han sido identificados, procesos dentro del SGC, exclusiones y su justificación.
- Mantener el alcance co mo una información documentada.
- Revisar periódicamente el alcance
Además del mapa de procesos, en referencia a la cláusula 4.4, se podría usar un diagrama de tortuga. Este esquema contiene todos los elementos de un proceso y adopta la forma de una tortuga con:
- Un cuerpo o caparazón: donde se escribe el nombre del proceso.
- Una cabeza: que representa las entradas del proceso.
- Una cola: que serían los resultados o salidas del proceso.
- Cuatro patas: que son las preguntas que serán contestadas por la organización - con qué, con quién, cómo, y cuántos.
Auditor de certificación
Academy: ISO 90001, ISO 14001, ISO 27001.
Mi respuesta:
No existen unos requisitos específicos para llegar a ser auditor, aunque los organismos de certificación tienen que demostrar que sus auditores son competentes. Esto es una tarea difícil de alcanzar y por ello los organizamos de certificación han establecido una serie de métodos y documentación para poder cumplirlo.
El esquema más ampliamente extendido es el esquema de calificación, que requiere aprobar una clase de auditor jefe de 5 días (con 2 horas de examen), demostrar con un curriculum vitae que se tiene una experiencia de unos 4 años, una experiencia más específica de unos 2 años (por ejemplo, en el sector de la calidad o medio ambiente que se va a auditar) y luego participar en auditorias para demostrar esa experiencia.