Quite clear now. Appreciate your response. Thanks.
ISO 9001:2015 documentation level
Answer:
Not all processes need to be documented and this version of the standard aims to decrease the amount of documentation. The documentation should be a balance between the competence of employees and complexity of processes. If you have competent employees you don't have to document every singe activity, the same is for the simple processes. Instead of writing procedures, sometimes it can be much easier to develop process flowchart or Quality Plan. For more information, see: New approach to document and record control in ISO 9001:2015 https://advisera.com/9001academy/blog/2015/06/30/new-approach-to-document-and-record-control-in-iso-90012015/
Gaining competence for ISO 9001:2015
Answer:
There is no requirement for the top management to get training in ISO 9001 requirements. The auditors, on the other hand, must get familiar with the standard requirements in order to be able to audit the system. They can get familiar with the standard by themselves or take some in-house or external course, but they do not have to have the certificate.
For example, I have a flow-down list of document numbers, however it only lists one form number for a calibration list, using F-715-001. Currently we have a calibration form for each piece of lab equipment. Same form just, individual form for each thermometer, balance, etc. Would this form then be F-715-002?
Answer:
New version of the standard doesn't change the coding system, so you can keep the existing one and there is no reason for change. What will change during the transition are the documents themselves and their version number should be changed but they can have the same identification code.
How to address life cycle perspective in providing services?
The life cycle perspective is not relevant for every type of business in the same way, the service companies will have far less difficulties meeting this requirement. In case of logistic company, you will basically examine the steps you go through when delivering the product and determine that environmental aspects regarding each step and it will overlap with your processes such as transportation and storage.
I'm not sure what ISO principles do you mean, but I assume your thinking of ISO 9001 principles. New version of the standard has 8 principles instead of 7 in the previous version. The principles are translated into requirements of the standard and by meeting the requirements, you will apply the quality principles.
Please can you assist me with a presentation on introduction to ISO 9001:2015 Transition slide to be presented for my staff and the management entirely.
Thank you for always there for always there for me.
Answer: I assume you are referring to security practices from IT applicable to SCADA (Supervisory Control and Data Acquisition). Information Technology (IT) and Industrial Control System (ICS), which embraces SCADA, have different business requirements, implementation architectures, and security goals, which makes direct application of security solutions from IT to SCADA unpractical. But in terms of concepts and high level approaches, they are highly compatible (you can also consider for SCADA security approaches like harden the perimeter, defense in depth and securing remote access). Considering ISO standards, ISO 27002 may help with some approaches (for remote access you have control 6.2.2 - Teleworking, and 13.1.2 - Security of network services), but ISO 27019:2013, wh ich provides guiding principles based on ISO/IEC 27002 for information security management applied to process control systems used in the energy utility industry, can provide more related information regarding Industrial Control Systems in general.