The standard itself doesn't require procedure for determining context of the organization to be documented, but if you choose to do so, the best way is to explain in the procedure how determining of the context will be conducted, who will participate, what elements of the context will be considered and so on. Here you can download a free preview of our Procedure for Determining Context of the Organization and Interested Parties https://advisera.com/14001academy/documentation/procedure-for-determining-context-of-the-organization-and-interested-parties/
Answer: What ISO 27001 requires is that an organization considers its context and assesses its risks to implement proper controls to bring risks to acceptable levels. So the decision for immediate removal of users access is up to each organization, based on its risk assessments, legal or contractual requirements.
Answer: There will be no problem as long as you ensure all that people who needs to access both, the policy and the related SOP can do that, and they are aware on how to handle the information regarding their respective classification. You should note that ISO 27001 does not prevent this kind of situation, but can help handle related risks.
Answer:
That depends what kind agreement you have with third party (if you have one). If it's an IT issue I would rather let support guys report issues. If you have an ITSM tool - even more important to have it in scope of the support desk.
QMS effectiveness and customer satisfaction
Answer:
Effectiveness of the QMS can be demonstrated through achievement of the quality objectives, improving quality performance and customer satisfaction.
My company as you know is presently ISO 9001:2008. I was in the process of transitioning to ISO 9001 2015. My company decided to change over to TS 16949-2016 instead. At this time I am having to start over. My question to you is, can I use any of the templates that I purchased from you? Or would I have to purchase new templates for TS?
Answer:
IATF 16949 is practically ISO 9001:2015 plus requirements for automotive industry. If you take a look at the text of IATF 16949, you can see that it refers to requirements of ISO 9001 but due to copyrights it doesn't quote the ISO 9001.
Also, some of requirements of IATF 16949 are completely the same as in ISO 9001 and in these cases you can use the documentation of ISO 9001 Documentation Toolkit as is (for example context of the organization), in other cases you only need to amend the documentation to meet additional requirements of IAT F 16949.
Answer: ISO 17799:2005 is the previous version of ISO 27002:2007. The standard was renumbered as ISO 27002 to align with the other information security standards, under the ISO/IEC 27000-series. Its current version was released in 2013.
Basically ISO 27002 (formerly ISO 17799) provides details and implementation guidelines regarding the controls described in ISO 27001 Annex A, which is helpful for organizations who decided to implement ISO 27001 practices. The main part of ISO 27001 defines the requirements for an Information Security Management System.