Posts

Showing posts with the label ISOlaonlinetraining&certification

ISO 27001 Clause 10.2 Continual Improvement

Image
Required Activity ISO 27001 Clause 10.2 Continual Improvement, The organization continually improves the suitability, adequacy and effectiveness of the ISMS. Why organization needs to have continual improvement? Organizations are never static, nor their contexts. In addition, the threats to the information systems, and the ways in which they can be compromised, are rapidly changing. At the end of the day, there’s no ISMS which remains perfect; it always needs to be set on continual improvement; however, the organization and its context are not changing. Here at  Infosavvy  we are continually talking about how the ISMS is a systematic approach consisting of processes, technology and people that helps us to protect and manage our organisation’s information through effective risk management. It is a topic of discussion in all of our training and we make sure that our trainees also imbibe the same understanding. It has become a second nature. We are constantly looking...

ISO 27001 Clause 10.1 Non conformity and corrective action

Image
Required activity ISO 27001 Clause 10.1 Non conformity and corrective action, Clause 10 containing sections 10.1 and 10.2 covers the “Act” part W. Edwards Deming’s Plan-Do-Check-Act (PDCA) cycle. This clause helps an organisation react to nonconformities, evaluate them and take corrective actions with the end goal of continually improving how it runs its daily activities. Explanation Nonconformity may be a non-fulfilment of a  requirement  of the ISMS. Nonconformity cannot always be avoided, because mistakes do happen in an organisation; however, what is important is that the issue is identified and handled accordingly when it presents itself. Requirements are needs or expectations that are stated, implied or obligatory. There are several types of nonconformities such as: Failure to fulfil a requirement (completely or partially) of  ISO/IEC 27001  within the ISMS; Failure to properly implement or conform to a requirement, rule or control stated by the ...

ISO 27001 Clause 9.3 Management review

Image
Activity ISO 27001 Clause 9.3 Management review, Top Management conducts management review for  ISO 27001  at planned intervals. What is ISO 27001 Clause 9.3? ISO 27001 Clause 9.3 Management review, clause highlights the significance of management review which helps to ensure continuing suitability, adequacy, and effectiveness of  Information Security  Management System in the organization, where  Suitability  refers to the continuous alignment with the objectives of the organization,  Adequacy  and  Effectiveness  call for appropriate design and organizational embedding respectively. It is a process which  is administered at various levels of the organization where the activities could range from daily, weekly or monthly organization unit meeting to simple reporting discussions. It is the responsibility of the top management to evaluate this review with contributions from all the levels of the organization.  Manage...