Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • What if an organization is not interested in surveillance audits?


    Answer: Surveillance audit is performed by certification body, and it is mandatory. Therefore, if you have e.g. ISO 27001 certificate, you cannot avoid this surveillance audit. The only way to stop these audits is to cancel your certification.

    See also: Surveillance visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
  • Evaluation of environmental aspects


    Answer:

    The first step would be to define criteria for evaluation of environmental aspects and define criteria for significance of the environmental aspects. All this is done during definition of methodology for evaluation of environmental aspects.

    Next step would be to conduct identification of the environmental aspects by analysing each process and activity within scope of EMS. Once all environmental aspects are identified, they need to be related to environmental aspects and then the evaluation should be conducted. For each significant environmental aspect you need to establish operational control to decease the impact. For more information, see: 4 steps in identification and evaluation of environmental aspects https://advisera.com/14001academy/knowledgebase/4-steps-in-identification-and-evaluation-of-environmental-aspects/
  • Becoming ISO 9001:2015 certified


    Answer:

    In order to get you company certified against ISO 9001:2015 you need first to implement the standard and then to hire a certification body to conduct the certification audit.

    The implementation consists of two main parts, first you need to develop documentation required by the standard itself and the documents that organization needs to maintain the QMS (Quality Management System) effectively. For more information, see: List of mandatory documents required by ISO 9001:2015 https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/

    The second part of the implementation is to update your processes and develop new ones to meet requirements of the standard regarding different aspects of your business, from purchasing and sales to production and delivery of products and services.

    Once the standard is implemented, the certification body will conduct certification audit and, if the organization is compliant with the standard, issue the organization the cert ificate.

    For more information, see: Checklist of ISO 9001 implementation & certification steps https://advisera.com/9001academy/knowledgebase/checklist-of-iso-9001-implementation-certification-steps/
  • Can we handle ISO 27001 implementation remotely?

    Thank you
  • Risks in ISO 9001

    I have also some question during consulting process but I have to study more on the spirit of ISO 9001-2015. But now I would like to give you question relating to item Risk-based thinking as follows:
    1. Does organization shall address the risk for the realization or for all process or only for critical process ?
    2. Risk-based thinking for all processes of system is described by establishing a documented information under support procedure ?
    3. Does Risk-based thinking is a new thinking to be set in mind for personnel having work affecting quality and then records from problem solving, taking decision, eliminating risk,...can demonstrate that. So that no need to have procedure to analyse risk as well as for risk evaluation ?
    Once again thanks a lot your support.

    Answers:

    1. The organization needs to consider entire context of the organization not only the processes, but it doesn't mean that you need to identify risks for each process. You can conduct a global assessment on the organizational leve l and that can be enough, then again you can go into details, it depends on needs of organization, the standard allows a lot of freedom regarding this requirement.

    2. Documented procedures exist to prevent risk of noncomplying with the activities in the processes and in that sense they are used for avoiding risk. Also some activities like inspection or monitoring certain parameters within the process serve as precaution. But not all processes carry such risk within them so there doesn't have to be a documented procedure for each process.

    3. Addressing risks and opportunities belongs to planning phase of the QMS so it is a requirement related mainly to top and mid management not employees. The management of the company should think about risks and opportunities related to the QMS and take actions to address them.

    For more information, see: How to address risks and opportunities in ISO 9001 https://advisera.com/9001academy/blog/2016/06/21/how-to-address-risks-and-opportunities-in-iso-9001/
  • Design Coordination Manager


    Answer:
    Yes, one of the Design Coordination Manager tasks is to ensure that overall service strategies are reflected in the service design practice and, additionally, that design of the service solution meets business outcomes and customer requirements.
    Read the article "Design coordination process – creating a solid foundation" https://advisera.com/20000academy/blog/2013/07/31/design-coordination-process-creating-solid-foundation/ to learn more.
  • How to integrate ISO 27001: 2013 with HIPAA security rules

    Thank you for explaining. My understanding is HIPAA security rules can be easily accommodated by implementing ISO 27001: 2013 in letter and sprite. Because HIPAA security rules specify three requirements i.e: Security should be managed Administratively, technically and physically and this is pretty much the same concept of ISO 27001:2013 standard.
  • To whom will the auditor speak to?


    Answer: During the ISMS audit both internal and external (certification) auditor has the right to speak to anyone in the company, ​so he can speak to people from IT department, security department, to the CEO or to any business department.

    The point of the audit is to find out whether the employees are complying to the policies and procedures, and these documents are not only applicable to security department.

    This free online training explains the whole audit process: ISO 27001 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
  • Information security board


    Answer: ISO 27001 does not define any requirements for information security boards, this phrase is not even mentioned in the standard. If you wish, you can organize some kind of a body that will coordinate information security activities, but it is not mandatory, and you can organize its work any way you want.

    On the other hand, the role of the top management in a company is strictly defined by ISO 27001 - you'll learn about it in these articles:
    - Roles and responsibilities of top management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/06/09/roles-and-responsibilities-of-top-management-in-iso-27001-and-iso-22301/
    - Why is manag ement review important for ISO 27001 and ISO 22301? https://advisera.com/27001academy/blog/2014/03/03/why-is-management-review-important-for-iso-27001-and-iso-22301/
  • ISO 9001 implementation form scratch


    Answer:

    The first step in the implementation is to conduct GAP analysis to determine to what extent your company has already met requirements of the standard and what needs to be done to achieve the full compliance (Here you can find free GAP analysis tool https://advisera.com/9001academy/iso-9001-gap-analysis-tool/). Once you determine this, you can create the project plan (here you can download free Project Plan for ISO 9001 implementation https://info.advisera.com/9001academy/free-download/project-plan-for-iso-9001-implementation-ms-word) and define activities responsibilities and deadlines for the project.
    After you finish implementing the standard, you need to conduct internal audit and management review and hire a certification body to conduct certification audit. For more information, see: Checklist of ISO 9001 implementation & certification steps https://advisera.com/9001academy/knowledgebase/checklist-of-iso-9001-implementation-certification-steps/
Page 969-vs-13485 of 1128 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +