Answer:
You are right, ISO 27003 is a guideline that can help you to implement ISO 27001 in your organization. Anyway, we do not have specific information about this standard because we offer basically the same: a guideline to implement the standard -in an easy way- in your organization.
So, from my point of view, there are other ways more relevants that ISO 27003 to implement ISO 27001 in your organization (furthermore, ISO 27003 is a bit complex for small and medium sizes companies).
Answer:
There is no pre-defined way on how to proceed i.e. no-one oblige you what to implement first.
ISO 20000 tells you "WHAT" you must implement in order to establish Service Management System (SMS) and ITIL tells you "HOW" to do it. So, I would suggest you to start ISO 20000 implementation (assuming that is the goal i.e. to set-up the SMS) and use ITIL to get the details.
See how ITIL and ISO 20000 complement in the articles
"ITIL and ISO 20000: A Comparison" https://advisera.com/20000academy/knowledgebase/itil-iso-20000-comparison/
"ISO 20000 and ITIL – How are they related?" https://advisera.com/20000academy/knowledgebase/iso-20000-and-itil-how-are-they-related/
ISO 27001 or AS ISO 27001?
Answer:
Basically ISO 27001 and AU/NZS ISO 27001 are the same standard, although ISO 27001 is the official version for all the world, and AU/NZS ISO 27001 is the Australian version copied from the official version (basically are the same).
Anyway, the current version of the ISO 27001 is the ISO 27001:2013, and the Australian version is the AS ISO 27001:2015 (there is no AU/NZS ISO 27001).
Would you please provide some guidelines on how to start a freelance consulting for InfoSec? As well as what would be the basics that should be included in the document.
Answer:
Regarding the document that you want, I am sorry but I am not sure if I have understood what is exactly you need. If you mean a document to present the information security (and your services as consultant) to any type of organization, we have a free presentation about ISO 27001 and about information security that can help you. You can download this presentation from our free download section “Why ISO 27001 - Awareness presentation” : https://advisera.com/27001academy/free-downloads/
And our project proposal for the ISO 27001 implementation can be also interesting for your potential clients “Project proposal for ISO 27001 implementation” : https://advisera.com/27001academy/free-downloads /
Regarding your information security career as freelance, you can follow these steps:
9.1 - "Is it defined what needs to be measured, by which method, who is responsible, who will analyze and evaluate the results?" Does this refer to the objectives? Also, does there need to be a document that shows each objective, what needs to be measured and who is responsible?
A6.1.2 - "Are duties and responsibilities defined in such a way to avoid conflict of interest, particularly with the information and systems where high risks are involved?" Do these duties include those beyond just IT?
Answer: Information security is not only about IT, it concerns all the functions in your company - therefore, A.6.1.2 is not for IT only - e.g. you can avoid conflict of interest in your finance department by asking for a double signature for signing payments in your bank account.
A16.1.7 - "Do procedures exist which define how to collect evidence that will be acceptable during the legal process?" How detailed does this need to be? Would saying we use a 3rd party to handle these procedures suffice?
Answer: The level of detail depends on what your local courts would find as acceptable - therefore, asking for someone with experience (e.g. consultant with legal experience, or a lawyer with information security experience) would certainly help you with this. It is not enough to say that 3rd party is in charge of something - you need to check whether they are really performing the activities they are hired for.
2. Is there like a roadmap template that I can use to know how to plan the whole project?
Answers:
Regarding the question 1, the time depends by some factors (scope, complex of your company, etc), but generally the time of the implementation of both standards, from my point of view, can be between 6 - 12 months. Anyway, with this free tool you can calculate the time for the implementation of each standard in your organization “Free Calculator - Duration of ISO 27001/ISO 22301 Implementation” : https://advisera.com/27001academy/free-tools/free-calculator-duration-of-iso-27001-iso-22301-implementation/
Regarding the second question, basically these articles can be also interesting for you:
Determining scope of QMS considering context of the organization
Answer:
The requirements from clause 4.3 state that you need to define the scope of your QMS according to the internal and external issues which means that you need to define context of your organization and why you want to implement the standard and to align the scope with your own needs as a company. For example, if you want to apply to tenders with only one of your products, you can cover only one production line with the scope of the QMS and save money on certification because you will only certify this production line and not entire organization.
The same reason is behind the consideration of interested parties. For example, your customer might require you to implement ISO 9001 because he buys one of your products so you can again cover with the scope only this production line to save time and implement the standard faster and meet customer requirements.
Answer:
Yes, the standard that officially defines the maximum period between two surveillance audits is ISO 17021 (standard that defines requirements for bodies providing audit and certification of management system), and in accordance with this standard, surveillance audits shall be conducted at least once a year.
Since both ISO 14001 and ISO 13485 have new versions, it is best to conduct the transition for both standards at the same time. The problem is that the ISO 14001:2015 has adopted High Level Structure (with ten clauses) and ISO 13485:2016 is created according to ISO 9001:2008 so it kept the old clause numbering and this will make the transition and the integration more difficult that it should be.
The best toolkit for you is ISO 14001:2015 Documentation Toolkit (https://advisera.com/14001academy/de/iso-14001-2015-gap-analyse-tool/ 001-documentation-toolkit/) that contains all necessary documents together with some most frequently used ones. You can use your old Quality Manual and combine it with our new Environmental Manual that is a part of above mentioned toolkit. Practically you will need to identify common requirements of ISO 13485 and ISO 14001:2015 and merge them into joint sections and for different requirements you will have separate sections in the manual. We will also publish ISO 13485:2016 Documentation Toolkit soon so if you decide to purchase it later, you will get a big discount as our previous customer.