A key performance indicator (KPI) is a measurement of a certain type of activity that a company or organization partakes in. When that measurement is a direct reflection on your workforce’s health and well-being that KPI can be used for measuring effectiveness of your OH&SMS (Occupational Health & Safety Management System).
Clause 4.1 Context of the organization will be the most difficult to evidence since there are no requirements to document any part of the context. The best way to audit this clause it through interview with the top management and see if they had used SWOT analysis or some other tool while identifying context but again this is not a mandatory record. For more information, see: How to identify the context of the organization in ISO 9001:2015 https://advisera.com/9001academy/knowledgebase/how-to-identify-the-context-of-the-organization-in-iso-90012015/
Naming the manual for integrated management system
Answer:
ISO 9001:2015 does not say that you cannot mention Quality Manual, the standard only doesn't require it any more. The fact that the manual is not a mandatory document any more doesn't mean that it is forbidden, so you can keep using the manual but you need to update it to fit new version of the standard. For more information, see: The future of the Quality Manual in ISO 9001:2015 https://advisera.com/9001academy/knowledgebase/the-future-of-the-quality-manual-in-iso-90012015/
I'm not sure if I understood your question correctly, but ISO 27001 allows you to classify your information in any aspect you see fit for your company. Most companies classify their information in terms of confidentiality (i.e. how secret it is), and some companies classify their information in terms of availability (i.e. how quickly they need to get it).
Actually, ISO 27001 (nor ISO 27002) do not prescribe the frequency of changing the passwords - what ISO 27001 is saying is that you have to assess the risks related to access to your systems, and then based on the potential incidents decide what frequency would be appropriate.
The clause 8.4.3 d) requires organization to communicate to external providers its requirements for the external provider's interaction with the organization. This includes way of communication, way the product or service will be delivered by the provider, etc. This requirements are usually documented in contract or verbally between the organization and the external provider since documented information for this requirement is not mandatory.
Answer:
I am sorry but I am not sure what you mean. Anyway, with ISO 27001 you can manage the information security, and with ISO 22301 you can manage the business continuity. So, if your question is about how to manage the information security, basically you can implement ISO 27001, and this article can help you to do it “ISO 27001 implementation checklist” : https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/
Answer:
I am not sure if your requirement is about information security risks, because you can also have financial risks, environmental risks, etc. ISO 31000 can help you to develop your own methodology for all risks (information security, financial, etc). So this methodology, aligned with ISO 31000 can be interesting for you “Risk Assessment and Risk Treatment Methodology” : https://advisera.com/27001academy/documentation/Risk-Assessment-and-Risk-Treatment-Methodology/