Answer: Defining and documenting policies, or procedures, are considered organizational controls because they involve the establishment of behaviours, either in terms of rules, lik e policies, or in terms of activities to be performed, like procedures.
Additionally, I suggest you to take a look at Conformio, our online ISO tool which have many resources to help you implement and manage your ISO 27001 Information Security Management System, including a list of task about what should be considered in the implementation (we have a free plan includes access for 10 users). You can access Conformio at this link https://advisera.com/conformio/
Procedures vs processes
Answer:
The process approach is required by ISO 14001 and it is demonstrated by applying requirements of the standard to appropriate processes. For example, clause 8.1 Operational controls, contains specific requirements for design and development and purchasing among other, more general, requirements for operational control. But, it doesn't mean that you need to create a process model or to document process procedures. If you implement only ISO 14001, you will need to document only operational controls for the processes and that only to the level you determine as necessary.
The ISO 14001 standard requires process-based approach, but it doesn't require organization to describe its processes and write the procedures for them, that is partially a requirement of ISO 9001. In ISO 14001 you demonstrate to process approach by applying the requirements of the standard on your processes. For example, identification and evaluation of environmental aspects should be done process by process and activity by activity, and later when the significant aspects are determined, you will apply the operational controls to appropriate processes, e.g. in sales, design and development,purchasing, production, etc.
Documenting the EMS is only one of the steps in the implementation or transition. The documents cannot be created without process based approach. For example, when you conduct identification and evaluation of environmental aspects, you need to examine all processes and activities to determine where the significant environmental aspects emerge and to define operational controls that will be applied in appropriate activities and processes to decrease or prevent the impact on the environment.
Once the documents are developed, they need to be applied in the organization. For example, document management must be conducted according to the procedure for document management, operational controls that are defined and documented need to be applied, etc. For more information, see: 5 tips to maintain your ISO 14001-based EMS after certification https://advisera.com/14001academy/blog/2016/01/11/5-tips-to-maintain-your-iso-14001-based-ems-after-certification/
Main objective of the EMS
Answer:
The main objectives of the environmental management system are to prevent pollution, meet compliance obligations and enhance conditions of the environment.
A systematic approach to environmental management can provide the organization with information to build success over the long term and create options for contributing to sustainable development by:
- protecting the environment by preventing or mitigating adverse environmental impacts;
- mitigating the potential adverse effect of environmental conditions on the organization;
- assisting the organization in the fulfilment of compliance obligations;
- enhancing environmental performance;
- controlling or influencing the way the organization’s products and services are designed,
manufactured, distributed, consumed and disposed by using a life cycle perspective that can
prevent environmental impacts from being unintentionally shifted elsewhere within the life cycle;
- achieving financial and operational benefits that can result from implementing environmentally
sound alternatives that strengthen the organization’s market position;
- communicating environmental information to relevant interested parties.
Question: Does this mean the competency only needs to be assessed of
Those who put together and manage the ISMS ? I.e. Me as head of Infosec and those who write or approve any policy? Or do we need to assess the competency of anyone who has to follow the policy?
Answer: You need to assess the competency of anyone who has an impact in the performance of the ISMS, i.e. those who put together and manage the ISMS and also of those who have to follow the policies.
Information security profile
Answer: Yes, in the context of the Implementation process diagram, the security profile is exactly the Statement of Applicability, which shows what controls are applicable or not and why.
Answer:
No, ITIL does not have something like statement of applicability.
Starting ISO 9001 implementation
Answer:
First, you need to get familiar with requirements of the standard and than to do a GAP analysis to determine to what extent your company is already compliant with the standard. Here you can find our free GAP analysis tool https://advisera.com/9001academy/iso-9001-gap-analysis-tool/