Improving the quality of ISO 9001 audits in the field of software

Size: px
Start display at page:

Download "Improving the quality of ISO 9001 audits in the field of software"

Transcription

1 Information and Software Technology 40 (1998) Improving the quality of ISO 9001 audits in the field of software A.J. Walker* Software Engineering Applications Laboratory, Electrical Engineering, University of the Witwatersrand, Johannesburg, South Africa Abstract Internal quality system audits are a compliance requirement of ISO 900\2. Requirements of the internal quality audit clause define quality audit outputs in terms of audit planning and scheduling, recording of results and follow-up of audit activities. ISO provides general guidance on the conduct of audits. Where domain specific guidance is required on the audit, little support is available from ISO and national standards bodies. In particular, there is no freely available checklist support questions which probe the compliance requirements of ISO 9001\2, or provide industry specific guidance questions for probing the effectiveness of the implementation of the ISO 9001\2 process clauses. This paper reviews a national project to develop a checklist to probe ISO 9001 requirements for the field of software, and to offer guidance for examining the effectiveness of the implementation of the process clauses in the software domain. It is believed that this project is important for two reasons: the ISO 9001 compliance questions in the checklist are generically applicable, and secondly, the structure of the checklist has been devised to be tailorable to a wide range of application domains Elsevier Science B.V. All rights reserved. Keywords: Assessments; Audits; Checklists; ISO 9001: Quality management; Software engineering standards 1. Introduction There is little in common in the approach to auditing of a company against the compliance requirements of ISO 9001 [1] other than that which may be traced to ISO [2] which is the basis of international schemes for quality system auditor training and certification. Specific arrangements for auditor training and certification are available for the field of software, where the most well-known arrangement is the TickIT Scheme. It is noteworthy that even this well-known scheme is little in the way of specific guidance for compliance testing of the ISO 9001 system clauses and guidance on the implementation of the process clauses of ISO 9001 outside of ISO [3]. A commonly used tool in quality management is a checklist, which may contain a set of criteria against which the efficacy of a process is judged. Quality system auditors and certification bodies frequently assemble their own checklists as handy means for testing compliance, but there are no national or international commonly accepted checklists for testing or probing compliance to the shall requirements of ISO 9001 or which probes the implementation of the process clauses against international good software practices. Furthermore, where such checklists are know to be used by certification * Tel.: ; fax: ; walker@ odie.ee.wits.ac.za bodies, they do not make it a practice of releasing these checklists to their clients. This lack of uniformity in the framework for compliance testing crates a serious problem for companies which seek registration to ISO 9001 since there is a large gap between the ISO 9001 clauses and their interpretation for the field of software. So much so that this creates considerable problems for those who create and maintain software quality management systems against the ISO 9001 standard and those who interpret those requirements for compliance purposes (quality systems auditors). Against this background a project was initiated in November 1994 by the Software Engineering Applications Laboratory (SEAL) to develop a national standard (or, more accurately, recommended practice) under the auspices of the South African Bureau of Standards Technical Committee for Information Technology (TC71.1) for this purpose. At the May 1995 meeting of SABS National Committee for Information Technology (TC71.1) this project was tabled as a New Work Item to support more effective auditing of software quality management systems. The goal of the standard was to provide a common framework for assessments and follow-up audits for companies engaged in the development of software being developed for external or internal customers. Technical development was completed in November 1996, and formally published in August 1997 [12] /98/$ - see front matter 1998 Elsevier Science B.V. All rights reserved. PII: S (98)

2 866 A.J. Walker / Information and Software Technology 40 (1998) Fig. 1. A checklist sample from ISO 9001 clause 4.5. It was believed that such a tool would go a long way to reducing the all too frequent adversarial relationship between the quality assurance manager on the one part, the software developers on another part, and the external quality system auditors on the third part. Although there is a considerable need in this area, an investigation revealed that there were no suitable checklists available for this purpose, either locally or internationally. Current international practice is, however, moving towards encouraging the use of checklists for conducting assessments\audits of ISO 9000 quality management systems largely to harmonise audit and assessment practices. This checklist will be useful to: internal quality system auditors and quality managers; to individuals or bodies who conduct 2nd or 3rd party surveillance assessments/audits of quality management systems in the software industry. This paper presents an overview of this project in terms of: project requirements, process and product quality objectives and quality management practices; participation by industry locally and internationally; the product development and review process; the trialling (or validation) of the product; how this product could be used with good effect in other application domains. 2. Development of the checklist 2.1. Product requirements Functional and non-functional product requirements were identified. Functional requirements are tangible and can be measured, while non-functional requirements can be viewed as desirable goals or objectives for the project nice to have but impossible to measure Product functional requirements The following functional requirements were identified. 1. The requirements of ISO 9001 (as indicated by the shall in each clause) will be probed by a searching question (or series of questions) to test the extent of compliance of the system under review. 2. The checklist will address the domain of software. 3. The development of the checklist questions will be strongly guided by current and emerging international good practices, and will seek to use compliance indicators being used for this purpose elsewhere.

3 A.J. Walker / Information and Software Technology 40 (1998) The checklist shall be easily available in both hardcopy and electronic format. 5. The layout of the checklist will be guided by applicable SABS Recommended Practices, i.e. ARP 013: Drafting and Presentation of Standards [4]. 6. The header of the checklist table will support the conduct of the audit\assessment, and make provision for recording: Client Date Reference number for the assessment/audit Person(s) interviewed (Shown as a table, with the headings of name, initials, function) Auditor(s)\assessor(s) The columns of the checklist table will support the conduct of the audit\assessment by making provision for: auditor initials, assessee\auditee initials, checklist\- compliance result: (Categories A and B: C compliance, N non-compliance); (Categories C F: P present, A absent); X not applicable, implementation/observation/comments, implementation result, expressed in the (Categories A and B: C compliance, N non-compliance); (Categories C F: P present, A absent); X not applicable, reference to findings report. Note: These categories are provided to differentiate between what will be audited for compliance (A,B), and what may be investigated in terms of good practice (C F). (A sample fragment of the implemented checklist is shown in Fig. 1) Product non-functional requirements The following non-functional requirements were identified. 1. The use of the checklist will serve to: enhance customer confidence in the client quality management system improve the effectiveness and efficiency of audits\ assessments improve the objectivity of the assessment\audit. 2. That international recognition of the product will be promoted Project and product quality requirements Besides identifying technical requirements for the product, quality objectives were identified for the process applied to the development of the checklist and extent to which the product met the technical requirements project quality objectives The quality requirements for the process applied to developing the checklist were defined as the following. 1. To manage this product development in compliance with ISO 9001 requirements. 2. The Committee Draft stage will be used to apply the checklist in practical assessment/auditing situations to determine the utility of the questions and to elicit feedback for validation purposes Product quality objectives On the other hand, the quality objectives for the questions comprising the checklist were required to demonstrate the following [5]. 1. Objectivity: a question is objective if it is possible to provide the answer without the opinion of the checklist user. 2. Completeness: a question is complete if all the components needed to specify its meaning are present. 3. Repeatability: a question is repeatable if applied several times by the same checklist user always produces the same answer. 4. Reproducibility: a question is reproducible if applied by different users always produces the same answer. 5. Usefulness: a question is useful if its answer contributes to the evaluation process. 6. Measurability: a question is measurable if it is possible to determine the attributes and their measures. 7. Specific: a question is measurable if it is possible to determine the attributes and their measures. 8. All the shall requirements of ISO 9001 are addressed in the checklist. The extent to which these quality characteristics are exhibited by the checklist questions may be evaluated by field trialling and by the application of formal inspection and review techniques Local and international collaboration The project drew upon the following resources. 1. Core Group Members: (13) Individuals who are software quality system managers in local companies. 2. Extended Core Group Members: These include colleagues overseas experienced in software quality management (9) and a number of individuals locally who have shown interest in trialling the product in their companies (3 at the present time). 3. Organisational Representatives of the SABS TC71.1 Information Technology Committee: This group of individuals is responsible for approving the developed product Project communication Project communication depends heavily upon the use of the Internet for communication and document distribution.

4 868 A.J. Walker / Information and Software Technology 40 (1998) Table 1 Number of questions in each category for each ISO 9001 clause ISO 9001 Checklist category Clause A B C D E F Totals Total number of questions 718 The SEAL File Server is the repository of the project documents and records. All core group members have username and password access to the management products, technical products and records supported on the SEAL file server. The emerging checklist technical products are publicly available and are accessible using anonymous FTP access to the SEAL File Server thereby providing access to the checklist products for trialling and validation. (See Appendix 1) Product development management Developing national or international standards is an unavoidable resource intensive and time-consuming process. The goal is to achieve consensus amongst the various stakeholders on the technical attributes of a new product which may exert a considerable impact on prevailing practices, particularly if the standard affect contractual arrangements or legislation. In view of this management authorisation operates on a number of different levels and is governed by product progress through the Working Draft, Committee Draft and Draft SA Standard stages, which are formally governed by SABS Recommended Practice ARP 017 [6]. These steps are largely similar to those used for the development of ISO\IEC\JTC1 standards. The SEAL has a certified ISO 9001 quality management system and these requirements are applied to all documents and records emanating from this project Product trialling and validation The development path taken by this project is unusual in the emphasis placed on active testing of the product at each stage of the standardisation process. Feedback has been facilitated by providing a review form with the checklist product set. The net result of this review process is: 1. to meet the review requirements of the SABS and to move the product from Committee Draft to Draft National Standard stage; 2. to enhance confidence in the widespread of the checklist. 3. Technical features of the checklist The density of questions for each ISO 9001 clause and category is shown in Table 1 for Revision 0.30 of the checklist. An examination of the number of shalls in ISO 9001 shows a count of 139 instances. In many case the compliance requirement has multiple aspects, i.e. one shall may have number of sub-pars each of which represent a distinct compliance requirement. Not surprising, once a full count reveals 236 distinct shall requirements. An examination of Category B shows a total of 48 compliance requirements but it must be noted that these may overlap with the category A requirements and are not necessarily distinctive. A cursory overview of the Table 1 clearly indicates the areas demanding the heaviest attention, notably clause 4.4 (Design Control), 4.10 (Inspection and Test), and 4.9 (Process Control). Software guidance questions have drawn from: 1. ISO [7]: this standard is currently being revised by TC 176\SC2\WG17 to bring the document in line with ISO 9001 (1994) requirements. The current version of the International Standard (i.e. ISO (1991)) is compliant to ISO 9001 (1987). In view of this the DIS version of this standard was used as the normative reference. A secondary, but significant reason took account of the fact that the order of the clauses is ISO (1996) now follows the clause order in ISO The software guidance drawn from this document largely concerns the implementation of the product process clauses i.e. 4.3, 4.4, 4.7, 4.8, 4.9, 4.10, 4.11, 4.12, 4.13, 4.15 and ISO [8]: this draft international standard has been used as the normative reference on issues related to project management, which has provided some helpful guidance in interpreting the requirements of 4.4 (Design Control). 3. ISO\IEC Software Life-Cycle Processes [9]: this keystone international software engineering standard has provided valuable supplementary software guidance in the same categories as (1). 4. ISO 9127 [10]: this International Standard has provided

5 A.J. Walker / Information and Software Technology 40 (1998) useful guidance specifically on implementation requirements of 4.15 (handling, storage, packaging, preservation and delivery) of software products. 5. ISO\IEC 9126 [11]: this International Standard is used to probe ISO 9001 clause dealing with Design Input. 6. European Auditor s Guide (Rev 3.0) Sept 1995 [3]: this product has been used as an informative reference to the project, but it was found that guidance offered in this guide was almost invariably better supported in the standards listed above. The checklist does not attempt to be a cross reference between ISO 9001 and the Standards and support documents ISO 9001 and the Standards and support documents listed in (1) (6). Rather the approach has been to adopt a minimalist approach in developing the checklist. Questions offering software guidance are only supplied for the ISO 9001 category A and B questions are insufficiently specific to provide clear and unambiguous application in the field of software. Neither is the issue of providing questions forced artificially. In the case of most of the system clauses of ISO 9001 (i.e. 4.1, 4.2, 4.6, 4.14, ) no software related guidance is required. 4. Discussion External auditing of a quality system to determine compliance unavoidably contains elements which give rise to an adversarial relationship between auditor and auditee. Many of the negative aspects of this relationship can be avoided by establishing the framework of that relationship, managerially and technically in advance. Surprising, the quality profession has been slow to apply its own tools to managing a key dimension of its activity notably the testing of compliance to defined requirements. It is believed that the checklist described in this paper can be productively used to manage the auditor\auditee relationship by making the ground rules of scope and extent of compliance well-known in advance. The checklist may be readily applied to other areas by removing the sections with the existing software guidance and substituting guidance for each ISO 901 sub-clause as appropriate for the intended application domain. Since official publication in August 1997, local demand for the checklist has been strong several hundred copies have been sold locally. On the international front, formal steps have been taken to achieve recognition for the product as a recommended practice for quality audits in software engineering. The product is presently under review by the Software Engineering Standards Committee (ISO/IEC JTC1/SC7). Acknowledgements The author gladly acknowledges the strong support from the core and extended group members comprising the checklist development team, and in particular the project leader of SABS TC71.1 (Mr Wotjec Skowronski) for his constant support and encouragement in the development of this national standard. Appendix A. Information about the checklist Information about the checklist is available at URL: seal.ee.wits.ac.za/1995_47/ac1910.htm. This suite of pages provides background information about the project, the project team members, access to the checklist, and a feedback form. References [1] ISO 9001 Quality Systems Model for Quality Assurance in Design/ Development, Production, Installation and Servicing, International Organisation for Standardisation, [2] ISO : Guidelines for auditing quality systems. Part 1: Auditing, Internation Organisation for Standardisation, [3] The TickIT Guide, Appendix 1 European IT Quality System Auditor Guide, Issue 3.0, [4] SABS ARP 013: 1990 Drafting and presentation of standards, South African Bureau of Standards. [5] F. Fabbrini, N. Format, M. Fusani, S. Gnesi, Evaluating evaluation instruments, in: Proceedings Software Quality Management 95, South African Society for Quality and Software Engineering Applications Laboratory, Software Engineering Applications Laboratory, University of the Witwatersrand, Johannesburg, South Africa, [6] Procedures for the Technical Work in the preparation of South African Standards, ARP 017, 1993, GR 14. [7] ISO 9000 (DIS) Quality Management and Quality Assurance Standards, Part 3 Guidelines for the Application of ISO 9001 to the Development, Supply and Maintenance of Software, [8] ISO (DIS) Quality Management Guidelines to quality in project management, Internation Organisation for Standardisation, [9] ISO\IEC Software Life-Cycle Processes, Internation Organisation for Standardisation, [10] ISO 9127 Information Processing Systems User Documentation and Cover Information for Consumer Software Packages, Internation Organisation for Standardisation, [11] ISO\IEC 9126 Information Technology Software Product Evaluation Quality Characteristics and Guidelines for their Use, Internation Organisation for Standardisation, [12] SABS ARP 042: 1997 ISO 9001 Audit Checklist for Software, 1st ed., South African Bureau of Standards, ISBN , Alastair Walker is presently an associate professor in the Department of Electrical Engineering, University of the Witwatersrand. He was responsible for establishing the Software Engineering Applications Laboratory in The SEAL received an ISO 9001 certification for software development in July He is a certified quality analyst and a certified software quality systems auditor.

Objective Measurement of the Extent of Conformity to Management System Standards

Objective Measurement of the Extent of Conformity to Management System Standards Nang Yan Business Journal 1.1 2012 Paper #: 2-10 P- 143 Objective Measurement of the Extent of Conformity to Management System Standards Dr. Alastair Walker CEO, Software Process Improvement Laboratory,

More information

EA IAF/ILAC Guidance. on the Application of ISO/IEC 17020:1998

EA IAF/ILAC Guidance. on the Application of ISO/IEC 17020:1998 Publication Reference EA IAF/ILAC-A4: 2004 EA IAF/ILAC Guidance on the Application of ISO/IEC 17020:1998 PURPOSE This guidance document is for ISO/IEC 17020: General Criteria for the operation of various

More information

QUALITY ASSURANCE GUIDE FOR GREEN BUILDING RATING TOOLS

QUALITY ASSURANCE GUIDE FOR GREEN BUILDING RATING TOOLS World Green Building Council Rating Tools Task Group: QUALITY ASSURANCE GUIDE FOR GREEN BUILDING RATING TOOLS Version 1.0 _ 2013 /(DRAFT_01 /Sept_13) INTRODUCTION This guide has been developed as a part

More information

CP14 ISSUE 5 DATED 1 st OCTOBER 2015 BINDT Audit Procedure Conformity Assessment and Certification/Verification of Management Systems

CP14 ISSUE 5 DATED 1 st OCTOBER 2015 BINDT Audit Procedure Conformity Assessment and Certification/Verification of Management Systems Certification Services Division Newton Building, St George s Avenue Northampton, NN2 6JB United Kingdom Tel: +44(0)1604-893-811. Fax: +44(0)1604-893-868. E-mail: pcn@bindt.org CP14 ISSUE 5 DATED 1 st OCTOBER

More information

CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems

CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems Date(s) of Evaluation: CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems Assessor(s) & Observer(s): Organization: Area/Field

More information

ISO 9001. What to do. for Small Businesses. Advice from ISO/TC 176

ISO 9001. What to do. for Small Businesses. Advice from ISO/TC 176 ISO 9001 for Small Businesses What to do Advice from ISO/TC 176 ISO 9001 for Small Businesses What to do Advice from ISO/TC 176 ISO Central Secretariat 1, chemin de la Voie-Creuse Case postale 56 CH -

More information

IRCA Briefing note ISO/IEC 20000-1: 2011

IRCA Briefing note ISO/IEC 20000-1: 2011 IRCA Briefing note ISO/IEC 20000-1: 2011 How to apply for and maintain Training Organization Approval and Training Course Certification IRCA 3000 Contents Introduction 3 Summary of the changes within ISO/IEC

More information

INFOCOMM DEVELOPMENT AUTHORITY OF SINGAPORE

INFOCOMM DEVELOPMENT AUTHORITY OF SINGAPORE INFOCOMM DEVELOPMENT AUTHORITY OF SINGAPORE Multi-Tiered Cloud Security Standard for Singapore (MTCS SS) Implementation Guideline Report For cross certification from MTCS SS to ISO/IEC December 2014 Revision

More information

IAF Mandatory Document

IAF Mandatory Document IAF MD15:2014. IAF Mandatory Document IAF MANDATORY DOCUMENT FOR THE COLLECTION OF DATA TO PROVIDE INDICATORS OF MANAGEMENT SYSTEM CERTIFICATION BODIES PERFORMANCE (IAF MD15:2014) Issued: 14 July 2014

More information

MANAGEMENT REVIEW FOR LABORATORIES AND INSPECTION BODIES

MANAGEMENT REVIEW FOR LABORATORIES AND INSPECTION BODIES APLAC TC 003 MANAGEMENT REVIEW FOR LABORATORIES AND INSPECTION BODIES Issue No. 4 Issue Date: 09/10 Page 1 of 7 PURPOSE This document gives laboratories and inspection bodies guidance on how to establish

More information

(Draft) Transition Planning Guidance for ISO 9001:2015

(Draft) Transition Planning Guidance for ISO 9001:2015 ISO/TC 176/SC2 Document N1223, July 2014 (Draft) Transition Planning Guidance for ISO 9001:2015 ISO 9001 Quality management systems Requirements is currently being revised. The revision work has reached

More information

COMBINE. Part B. Manual for Marine Monitoring in the. Programme of HELCOM. General guidelines on quality assurance for monitoring in the Baltic Sea

COMBINE. Part B. Manual for Marine Monitoring in the. Programme of HELCOM. General guidelines on quality assurance for monitoring in the Baltic Sea Manual for Marine Monitoring in the COMBINE Programme of HELCOM Part B General guidelines on quality assurance for monitoring in the Baltic Sea Annex B-3 Quality audit ANNEX B-3 QUALITY AUDIT 1. Objectives

More information

ISO 9001 : 2000 Quality Management Systems Requirements

ISO 9001 : 2000 Quality Management Systems Requirements A guide to the contents of ISO 9001 : 2000 Quality Management Systems Requirements BSIA Form No. 137 February 2001 This document is the copyright of the BSIA and is not to be reproduced without the written

More information

Australian Transport Council. National Standard for the Administration of Marine Safety SECTION 5

Australian Transport Council. National Standard for the Administration of Marine Safety SECTION 5 Australian Transport Council National Standard for the Administration of Marine Safety SECTION 5 APPROVAL AND AUDITING OF REGISTERED TRAINING ORGANISATIONS August 2008 First Published: August 2008 Endorsed

More information

Audit Report AS/NZS ISO 9001:2008. RRW and Co Pty Ltd trading as National On Site Training

Audit Report AS/NZS ISO 9001:2008. RRW and Co Pty Ltd trading as National On Site Training Audit Report AS/NZS ISO 9001:2008 RRW and Co Pty Ltd trading as National On Site Training AUDIT D E T A I L S Invoice Reference Number Certificate Number Review Date/s Review Time Hours S12627 158 10 th

More information

International Workshop Agreement 2 Quality Management Systems Guidelines for the application of ISO 9001:2000 on education.

International Workshop Agreement 2 Quality Management Systems Guidelines for the application of ISO 9001:2000 on education. ISO 2002 All rights reserved ISO / IWA 2 / WD1 N5 Date: 2002-10-25 Secretariat: SEP-MÉXICO International Workshop Agreement 2 Quality Management Systems Guidelines for the application of ISO 9001:2000

More information

General Rules for the certification of Management Systems

General Rules for the certification of Management Systems General Rules for the certification of Management Systems Effective from 19/11/2015 RINA Via Corsica 12 16128 Genova - Italy tel. +39 010 53851 fax +39 010 5351000 website : www.rina.org Technical rules

More information

n130910 version of 26 november 2013 sccm Information about performing internal audits

n130910 version of 26 november 2013 sccm Information about performing internal audits Information about performing internal audits sccm Information about performing internal audits 1 We at SCCM are convinced and our experience has proven that any organization, large or small, will achieve

More information

The IAF Multilateral Recognition Arrangement (MLA) Certified Once Accepted Everywhere

The IAF Multilateral Recognition Arrangement (MLA) Certified Once Accepted Everywhere The IAF Multilateral Recognition Arrangement (MLA) Certified Once Accepted Everywhere Supporting the acceptance of goods and services across national borders Accreditation provides an assurance to government,

More information

SUPPLIER ASSESSMENT CHECKLIST

SUPPLIER ASSESSMENT CHECKLIST Sample Pages of SUPPLIER ASSESSMENT CHECKLIST For Standard ISO/IEC 90003:2004 Software engineering: Guidelines for the application of ISO 9001:2000 to computer software ISBN 0-9770309-1-1 7/5/2007 1 Sample

More information

-Blue Print- The Quality Approach towards IT Service Management

-Blue Print- The Quality Approach towards IT Service Management -Blue Print- The Quality Approach towards IT Service Management The Qualification and Certification Program in IT Service Management according to ISO/IEC 20000 TÜV SÜD Akademie GmbH Certification Body

More information

EA-7/01. EA Guidelines. on the application. Of EN 45012. Publication Reference PURPOSE

EA-7/01. EA Guidelines. on the application. Of EN 45012. Publication Reference PURPOSE Publication Reference EA-7/01 EA Guidelines on the application Of EN 45012 PURPOSE The purpose of the document is to provide explanations with a view to harmonise the application of ISO/IEC Guide 62/EN

More information

IAF Informative Document. IAF Informative Document for the Transition of Management System Accreditation to ISO/IEC 17021:2011 from ISO/IEC 17021:2006

IAF Informative Document. IAF Informative Document for the Transition of Management System Accreditation to ISO/IEC 17021:2011 from ISO/IEC 17021:2006 IAF ID 2:2011 International Accreditation Forum, Inc. IAF Informative Document IAF Informative Document for the of Management System Accreditation to ISO/IEC 17021:2011 from (IAF ID 2:2011) The International

More information

QUALITY SYSTEM REQUIREMENTS FOR PHARMACEUTICAL INSPECTORATES

QUALITY SYSTEM REQUIREMENTS FOR PHARMACEUTICAL INSPECTORATES PHARMACEUTICAL INSPECTION CONVENTION PHARMACEUTICAL INSPECTION CO-OPERATION SCHEME PI 002-3 25 September 2007 RECOMMENDATION ON QUALITY SYSTEM REQUIREMENTS FOR PHARMACEUTICAL INSPECTORATES PIC/S September

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 26/10/2015 HSCIC Audit of Data Sharing

More information

Guideline. Records Management Strategy. Public Record Office Victoria PROS 10/10 Strategic Management. Version Number: 1.0. Issue Date: 19/07/2010

Guideline. Records Management Strategy. Public Record Office Victoria PROS 10/10 Strategic Management. Version Number: 1.0. Issue Date: 19/07/2010 Public Record Office Victoria PROS 10/10 Strategic Management Guideline 5 Records Management Strategy Version Number: 1.0 Issue Date: 19/07/2010 Expiry Date: 19/07/2015 State of Victoria 2010 Version 1.0

More information

Competency Unit: Exemplar Global AU Management Systems Auditing

Competency Unit: Exemplar Global AU Management Systems Auditing Please visit: www.exemplarglobal.org for your region s Principal Office contact details. Email: info@exemplarglobal.org Competency Unit: Exemplar Global AU Management Systems Auditing How to use this document

More information

CQI briefing note. Annex SL

CQI briefing note. Annex SL CQI briefing note Annex SL The most important event since ISO 9001? A quarter of a century ago, in December 1987, ISO 9001 Quality systems Model for quality assurance in design/development, production,

More information

Gap Analysis of ISO 15189:2012 and ISO 15189:2007 in the field of Medical Testing

Gap Analysis of ISO 15189:2012 and ISO 15189:2007 in the field of Medical Testing Gap Analysis May 2013 Issued: May 2013 Gap Analysis of and in the field of Medical Testing Copyright National Association of Testing Authorities, Australia 2013 This publication is protected by copyright

More information

OHSAS 18001 OCCUPATIONAL HEALTH AND SAFETY MANAGEMENT SYSTEMS

OHSAS 18001 OCCUPATIONAL HEALTH AND SAFETY MANAGEMENT SYSTEMS , Certification & Training Services , Certification & Training Services , Certification & Training Services , Certification & Training Services WHAT MAKES YOUR OCCUPATIONAL HEALTH AND SAFETY SYSTEMS BEST-IN-CLASS?

More information

BS 25999 BUSINESS CONTINUITY MANAGEMENT

BS 25999 BUSINESS CONTINUITY MANAGEMENT BS 25999 BUSINESS CONTINUITY MANAGEMENT AUDIT, CERTIFICATION & training services HOW CAN YOU ENSURE BUSINESS CONTINUITY? BS 25999 AUDITS & CERTIFICATION FROM SGS Most organisations will, at some point,

More information

GCERT BALTIC JSC. Tel.: +370 682 16 335 info@gcert.lt, www.gcerti.com www.gcert.eu Vilnius, Lithuania GCERT BALTIC JSC. ISO certification and training

GCERT BALTIC JSC. Tel.: +370 682 16 335 info@gcert.lt, www.gcerti.com www.gcert.eu Vilnius, Lithuania GCERT BALTIC JSC. ISO certification and training Tel.: +370 682 16 335 info@gcert.lt, www.gcerti.com www.gcert.eu Vilnius, Lithuania GCERT BALTIC JSC GCERT BALTIC JSC - certification and training service provider. We provide Auditors and Management Systems

More information

Certification Process Requirements

Certification Process Requirements SAAS Certification Process Requirements SAAS Procedure 200 and ISO/IEC 17021 Social Accountability Accreditation Services, June 2010 Accreditation Process and Policies SAAS Normative Requirements SAAS

More information

General Guidance for Developing, Documenting, Implementing, Maintaining, and Auditing an SQF System. Module 2: System Elements. SQF Code, Edition 7.

General Guidance for Developing, Documenting, Implementing, Maintaining, and Auditing an SQF System. Module 2: System Elements. SQF Code, Edition 7. General Guidance for Developing, Documenting, Implementing, Maintaining, and Auditing an SQF System Module 2: System Elements SQF Code, Edition 7.1 M A Y 2 0 1 3 2013 Safe Quality Food Institute 2345 Crystal

More information

Translation Service Provider according to ISO 17100

Translation Service Provider according to ISO 17100 www.lics-certification.org Certification Scheme S06 Translation Service Provider according to ISO 17100 Date of issue: V2.0, 2015-11-15 Austrian Standards plus GmbH Dr. Peter Jonas Heinestraße 38 1020

More information

FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT

FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT November 2003 Laid before the Scottish Parliament on 10th November 2003 pursuant to section 61(6) of the Freedom of Information

More information

An Overview of ISO/IEC 27000 family of Information Security Management System Standards

An Overview of ISO/IEC 27000 family of Information Security Management System Standards What is ISO/IEC 27001? The ISO/IEC 27001 standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), is known as Information

More information

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYSTEMS Most organisations will, at some point, be faced with having to respond

More information

Preparation of a Rail Safety Management System Guideline

Preparation of a Rail Safety Management System Guideline Preparation of a Rail Safety Management System Guideline Page 1 of 99 Version History Version No. Approved by Date approved Review date 1 By 20 January 2014 Guideline for Preparation of a Safety Management

More information

Preparing yourself for ISO/IEC 27001 2013

Preparing yourself for ISO/IEC 27001 2013 Preparing yourself for ISO/IEC 27001 2013 2013 a Vintage Year for Security Prof. Edward (Ted) Humphreys (edwardj7@msn.com) [Chair of the ISO/IEC and UK BSI Group responsible for the family of ISMS standards,

More information

Sector Development Ageing, Disability and Home Care Department of Family and Community Services (02) 8270 2218

Sector Development Ageing, Disability and Home Care Department of Family and Community Services (02) 8270 2218 Copyright in the material is owned by the State of New South Wales. Apart from any use as permitted under the Copyright Act 1968 and/or as explicitly permitted below, all other rights are reserved. You

More information

Pursuant to Convention No. 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data;

Pursuant to Convention No. 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data; Decision No. 2011-316 dated 6 October 2011 adopting a standard for delivering privacy seals in audit procedures covering the protection of persons with regard to the processing of personal data The French

More information

IAF Mandatory Document for the Transfer of Accredited Certification of Management Systems

IAF Mandatory Document for the Transfer of Accredited Certification of Management Systems IAF MD 2:2007. International Accreditation Forum, Inc. IAF Mandatory Document IAF Mandatory Document for the Transfer of Accredited Certification of Management Systems (IAF MD 2:2007) IAF MD2:2007 International

More information

International Standards on Auditing (ISA) and their Use for Second Level Control of European Territorial Cooperation Programmes

International Standards on Auditing (ISA) and their Use for Second Level Control of European Territorial Cooperation Programmes International Standards on Auditing (ISA) and their Use for Second Level Control of European Territorial Cooperation Programmes by Susanne Volz, Financial Control Expert The Programming Period 2007-2013

More information

World Tourism Organization RECOMMENDATIONS TO GOVERNMENTS FOR SUPPORTING AND/OR ESTABLISHING NATIONAL CERTIFICATION SYSTEMS FOR SUSTAINABLE TOURISM

World Tourism Organization RECOMMENDATIONS TO GOVERNMENTS FOR SUPPORTING AND/OR ESTABLISHING NATIONAL CERTIFICATION SYSTEMS FOR SUSTAINABLE TOURISM World Tourism Organization RECOMMENDATIONS TO GOVERNMENTS FOR SUPPORTING AND/OR ESTABLISHING NATIONAL CERTIFICATION SYSTEMS FOR SUSTAINABLE TOURISM Introduction Certification systems for sustainable tourism

More information

Systems and software engineering Lifecycle profiles for Very Small Entities (VSEs) Part 5-6-2:

Systems and software engineering Lifecycle profiles for Very Small Entities (VSEs) Part 5-6-2: TECHNICAL REPORT ISO/IEC TR 29110-5-6-2 First edition 2014-08-15 Systems and software engineering Lifecycle profiles for Very Small Entities (VSEs) Part 5-6-2: Systems engineering Management and engineering

More information

A Guide to the Business Analysis Body of Knowledge (BABOK Guide) Version 2.0

A Guide to the Business Analysis Body of Knowledge (BABOK Guide) Version 2.0 A Guide to the Business Analysis Body of Knowledge (BABOK Guide) Version 2.0 www.theiiba.org International Institute of Business Analysis, Toronto, Ontario, Canada. 2005, 2006, 2008, 2009, International

More information

"Your career as a project manager begins here!"

Your career as a project manager begins here! CHECK-LIST Audited project phases: Auditor: Project name: Prepared by: Date: Project completion Instructions for completion: When filling in the Checklist think about the actual contents of the audited

More information

Chain of Custody of Forest Based Products - Requirements

Chain of Custody of Forest Based Products - Requirements PEFC INTERNATIONAL STANDARD Requirements for PEFC scheme users PEFC ST 2002:2013 2012-12-04 Enquiry Draft Chain of Custody of Forest Based Products - Requirements PEFC Council World Trade Center 1, 10

More information

Quality Management Systems for Seed Testing Laboratories: Presented to the 2010 CSAAC Meeting. Valerie Martz Senior Laboratory Accreditation Officer

Quality Management Systems for Seed Testing Laboratories: Presented to the 2010 CSAAC Meeting. Valerie Martz Senior Laboratory Accreditation Officer Quality Management Systems for Seed Testing Laboratories: Presented to the 2010 CSAAC Meeting Valerie Martz Senior Laboratory Accreditation Officer Outline 1. Quality Management Systems (QMS): Generic

More information

ETSI TS 119 403 V2.1.1 (2014-11)

ETSI TS 119 403 V2.1.1 (2014-11) TS 119 403 V2.1.1 (2014-11) TECHNICAL SPECIFICATION Electronic Signatures and Infrastructures (ESI); Trust Service Provider Conformity Assessment - Requirements for conformity assessment bodies assessing

More information

Navigating ISO 9001:2015

Navigating ISO 9001:2015 Navigating ISO 9001:2015 Understanding why the new ISO 9001 revision matters to everyone White paper Abstract This whitepaper takes a concise, yet detailed look at the ISO 9001:2015 revision. Published

More information

Quick Guide: Meeting ISO 55001 Requirements for Asset Management

Quick Guide: Meeting ISO 55001 Requirements for Asset Management Supplement to the IIMM 2011 Quick Guide: Meeting ISO 55001 Requirements for Asset Management Using the International Infrastructure Management Manual (IIMM) ISO 55001: What is required IIMM: How to get

More information

Access Control Policy. Document Status. Security Classification. Level 4 - PUBLIC. Version 1.0. Approval. Review By June 2012

Access Control Policy. Document Status. Security Classification. Level 4 - PUBLIC. Version 1.0. Approval. Review By June 2012 Access Control Policy Document Status Security Classification Version 1.0 Level 4 - PUBLIC Status DRAFT Approval Life 3 Years Review By June 2012 Owner Secure Research Database Analyst Retention Change

More information

Achieving ISO 9001 Certification for an XP Company

Achieving ISO 9001 Certification for an XP Company Achieving ISO 9001 Certification for an XP Company Graham Wright Development Team Coach Workshare 20 Fashion Street London, E1 6PX (44) 020 7539 1361 graham.wright@workshare.com Abstract It is generally

More information

Need a system to deliver consistent, efficient and reliable IT services? Use an ISO/IEC 20000 compliant management system.

Need a system to deliver consistent, efficient and reliable IT services? Use an ISO/IEC 20000 compliant management system. Need a system to deliver consistent, efficient and reliable IT services? Use an ISO/IEC 20000 compliant management system. Deliver a quality IT service to your stakeholders with ISO/IEC 20000. Information

More information

IAF Mandatory Document

IAF Mandatory Document IAF-MD 11:2013 IAF Mandatory Document IAF MANDATORY DOCUMENT FOR THE APPLICATION OF ISO/IEC 17021 FOR AUDITS OF INTEGRATED MANAGEMENT SYSTEMS (IAF MD 11: 2013) 2013 Page 2 of 12 The (IAF) details criteria

More information

A WEB-BASED PORTAL FOR INFORMATION SECURITY EDUCATION

A WEB-BASED PORTAL FOR INFORMATION SECURITY EDUCATION A WEB-BASED PORTAL FOR INFORMATION SECURITY EDUCATION JOHAN VAN NIEKERK and ROSSOUW VON SOLMS Port Elizabeth Technikon, johanvn@petech.ac.za rossouw@petech.ac.za Key words: Abstract: Information Security,

More information

Requirements for Certification as an. IRCA Auditor (All Schemes)

Requirements for Certification as an. IRCA Auditor (All Schemes) Requirements for Certification as an IRCA Auditor (All Schemes) Requirements for Certification as an IRCA Auditor (All Schemes) Contents Note: This contents is hot-linked. Click on a section to be taken

More information

Scheme rules for thermal insulation products for building equipment and industrial installations - VDI certification scheme

Scheme rules for thermal insulation products for building equipment and industrial installations - VDI certification scheme Scheme rules for thermal insulation products for building equipment and industrial installations - certification scheme April 6, 2011 1. Introduction This document presents the rules of the product certification

More information

For the latest information on VHP publications, visit our website: www.vanharen.net.

For the latest information on VHP publications, visit our website: www.vanharen.net. Other publications by Van Haren Publishing on IT Management Van Haren Publishing specialises in titles on Best Practices, methods and standards within IT and business management. These publications are

More information

to whether that scope should be increased further up the settlement chain to CSD participants clients.

to whether that scope should be increased further up the settlement chain to CSD participants clients. BUSINESS JUSTIFICATION FOR THE DEVLOPMENT OF NEW UNIFI (ISO 20022) FINANCIAL REPOSITORY ITEMS A: Name of the request: Market Claims and Automatic Transformations. B: Submitting organization: Euroclear

More information

Rules for the certification of Environmental Management Systems

Rules for the certification of Environmental Management Systems Rules for the certification of Environmental Management Systems Effective from November 19 th, 2015 RINA Via Corsica, 12 16128 Genova - Italy Tel.: +39 01053851 Fax: +39 0105351000 Web site: www.rina.org

More information

A Review ISO 9001:2015 Draft

A Review ISO 9001:2015 Draft A Review ISO 9001:2015 Draft ISO 9001 Why is it changing? Disclaimers Verbal statements made by the presenter may represent personal opinions and/or interpretations. The presentation includes information

More information

ISSAI 1300. Planning an Audit of Financial Statements. Financial Audit Guideline

ISSAI 1300. Planning an Audit of Financial Statements. Financial Audit Guideline The International Standards of Supreme Audit Institutions, ISSAI, are issued by the International Organization of Supreme Audit Institutions, INTOSAI. For more information visit www.issai.org. Financial

More information

Monitoring records management. Catherine Robinson Senior Project Officer, Government Recordkeeping

Monitoring records management. Catherine Robinson Senior Project Officer, Government Recordkeeping Monitoring records management Catherine Robinson Senior Project Officer, Government Recordkeeping Monitoring framework Available at http://www.records.nsw.gov.au/recordkeeping/state-records-act-1998 Outlines

More information

Procedure PS-TNI-001 Information Security Management System Certification

Procedure PS-TNI-001 Information Security Management System Certification Table of Contents 1. Purpose 2. Scope 3. Definitions 4. Responsibilities 4.1 Head of the Certification Body 4.2 QM Manager / Management Representative 4.3 Auditors 4.4 Order Service 4.5 Certification Service

More information

Certification Procedure of RSPO Supply Chain Audit

Certification Procedure of RSPO Supply Chain Audit : 1 of 19 Table of Contents 1. Purpose 2. Scope 3. Unit of Certification 3.1 Identity Preserved, Segregation, Mass Balance, 3.2. Book and Claim 4. Definitions 5. Responsibilities 5.1 Head of the Certification

More information

FINANCIAL REPORTING COUNCIL FRC STUDY: ACCOUNTING FOR ACQUISITIONS

FINANCIAL REPORTING COUNCIL FRC STUDY: ACCOUNTING FOR ACQUISITIONS FINANCIAL REPORTING COUNCIL FRC STUDY: ACCOUNTING FOR ACQUISITIONS JANUARY 2010 Contents Page One Introduction 1 Two Summary of results 3 Three Review of compliance by area 3.1 Business review commentary

More information

How To Implement International Standard For Service Excellence (Tisse2012)

How To Implement International Standard For Service Excellence (Tisse2012) THE 5P s SERVICE QUALITY MODEL The key differentiator in an increasingly competitive world is more often than not the delivery of a consistently high standard of customer service. Customer satisfaction,

More information

ISO/IEC 27001:2013 Your implementation guide

ISO/IEC 27001:2013 Your implementation guide ISO/IEC 27001:2013 Your implementation guide What is ISO/IEC 27001? Successful businesses understand the value of timely, accurate information, good communications and confidentiality. Information security

More information

COMMITTEE ON STANDARDS AND TECHNICAL REGULATIONS (98/34 COMMITTEE)

COMMITTEE ON STANDARDS AND TECHNICAL REGULATIONS (98/34 COMMITTEE) EUROPEAN COMMISSION ENTERPRISE AND INDUSTRY DIRECTORATE-GENERAL Regulatory Policy Standardisation Brussels, 9 th November 2005 Doc.: 34/2005 Rev. 1 EN COMMITTEE ON STANDARDS AND TECHNICAL REGULATIONS (98/34

More information

IAF Informative Document for the Transition of Food Safety Management System Accreditation to ISO/TS 22003:2013 from ISO/TS 22003:2007

IAF Informative Document for the Transition of Food Safety Management System Accreditation to ISO/TS 22003:2013 from ISO/TS 22003:2007 IAF Informative Document IAF Informative Document for the Transition of Food Safety Management System Accreditation to ISO/TS 22003:2013 from ISO/TS 22003:2007 (IAF ID 8:2014) Page 2 of 6 The (IAF) details

More information

AUDITOR GUIDELINES. Responsibilities Supporting Inputs. Receive AAA, Sign and return to IMS with audit report. Document Review required?

AUDITOR GUIDELINES. Responsibilities Supporting Inputs. Receive AAA, Sign and return to IMS with audit report. Document Review required? 1 Overview of Audit Process The flow chart below shows the overall process for auditors carrying out audits for IMS International. Stages within this process are detailed further in this document. Scheme

More information

The IP3 accreditation process. Bob Hart Chief Assessor September 2008

The IP3 accreditation process. Bob Hart Chief Assessor September 2008 Pr The IP3 accreditation process Bob Hart Chief Assessor September 2008 Stages of assessment 1. Association responds to the guidelines in the form of a self evaluation 2. Consultation on Panel membership

More information

Comparison ISO/TS 16949 (1999) to VDA 6.1 (1998)

Comparison ISO/TS 16949 (1999) to VDA 6.1 (1998) 1 APPLICABILITY VDA 6.1: Section: 3.1; 7 new: In addition to the applicability for supplier sites for production, services and their subcontractors for: products and production materials, or services like

More information

IAS ACCREDITED INSPECTION AGENCIES: GUIDELINES FOR CONDUCTING INTERNAL AUDITS AND MANAGEMENT REVIEWS. Revised January, 2016

IAS ACCREDITED INSPECTION AGENCIES: GUIDELINES FOR CONDUCTING INTERNAL AUDITS AND MANAGEMENT REVIEWS. Revised January, 2016 IAS ACCREDITED INSPECTION AGENCIES: GUIDELINES FOR CONDUCTING INTERNAL AUDITS AND MANAGEMENT REVIEWS Revised January, 2016 IAS has found that inspection agency personnel are often confused by the requirements

More information

DCA metrics for the approval of Auditing Firms for Certifications Scheme VERSION 1.0

DCA metrics for the approval of Auditing Firms for Certifications Scheme VERSION 1.0 DCA metrics for the approval of Auditing Firms for Certifications Scheme VERSION 1.0 2013, Data Centre Alliance Limited (www.datacentrealliance.org). All rights reserved. This publication may not be reproduced

More information

GUIDE 62. General requirements for bodies operating assessment and certification/registration of quality systems

GUIDE 62. General requirements for bodies operating assessment and certification/registration of quality systems GUIDE 62 General requirements for bodies operating assessment and certification/registration of quality systems First edition 1996 ISO/IEC GUIDE 62:1996(E) Contents Pag e Section 1: General 1 1.1 Scope

More information

AQTF Audit Handbook. This publication remains current and applicable to the VET sector.

AQTF Audit Handbook. This publication remains current and applicable to the VET sector. AQTF Audit Handbook The following publication was endorsed by the former Standing Council for Tertiary Education Skills and Employment (SCOTESE). On 13 December 2013, COAG agreed that its council system

More information

INFOCOMM DEVELOPMENT AUTHORITY OF SINGAPORE

INFOCOMM DEVELOPMENT AUTHORITY OF SINGAPORE INFOCOMM DEVELOPMENT AUTHORITY OF SINGAPORE Multi-Tiered Cloud Security Standard for Singapore (MTCS SS) Audit Checklist Report For cross-certification from MTCS SS to Cloud Security Alliance (CSA) Security,

More information

Selection and use of the ISO 9000 family of standards

Selection and use of the ISO 9000 family of standards Selection and use of the ISO 9000 family of standards ISO and international standardization ISO/TC 176, Quality management and quality assurance ISO is the International Organization for Standardization.

More information

The Centre for Environmental Management (CEM) offers the following Environmental and Occupational Health & Safety Management Courses

The Centre for Environmental Management (CEM) offers the following Environmental and Occupational Health & Safety Management Courses Schedule 2016 Course dates 2016 Rev 2016-40 Page 1 of 10 Course Dates 2016 Internal Box 150, Private Bag X6001, Potchefstroom, South Africa 2520 Centre for Environmental Management Tel: +27 (0) 18 299-2714

More information

Table of Contents. Preface 1.0 Introduction 2.0 Scope 3.0 Purpose 4.0 Rationale 5.0 References 6.0 Definitions

Table of Contents. Preface 1.0 Introduction 2.0 Scope 3.0 Purpose 4.0 Rationale 5.0 References 6.0 Definitions Table of Contents Preface 1.0 Introduction 2.0 Scope 3.0 Purpose 4.0 Rationale 5.0 References 6.0 Definitions 7.0 Objectives and User Needs of a Regulatory Audit Report 7.1 Audit report objectives 7.2

More information

Document Reference APMG 15/015

Document Reference APMG 15/015 Information technology service management Requirements for bodies providing audit and certification of IT service management systems under the APMG Certification Scheme Document Reference APMG 15/015 Introduction

More information

ISO 9001 Quality Management Systems. Tips for Internal Auditing

ISO 9001 Quality Management Systems. Tips for Internal Auditing ISO 9001 Quality Management Systems Tips for Internal Auditing ...taking steps to improving your internal auditing. ISO 9001 Tips for Internal Auditing If you are developing or modifying your internal

More information

HKCAS Supplementary Criteria No. 8

HKCAS Supplementary Criteria No. 8 Page 1 of 12 HKCAS Supplementary Criteria No. 8 Accreditation Programme for Information Security Management System (ISMS) Certification 1 INTRODUCTION 1.1 HKAS accreditation for information security management

More information

ISO 9001: 2008 Boosting quality to differentiate yourself from the competition. xxxx November 2008

ISO 9001: 2008 Boosting quality to differentiate yourself from the competition. xxxx November 2008 ISO 9001: 2008 Boosting quality to differentiate yourself from the competition xxxx November 2008 ISO 9001 - Periodic Review ISO 9001:2008 Periodic Review ISO 9001, like all standards is subject to periodic

More information

Guidelines on the Reporting of Compliance with Specification

Guidelines on the Reporting of Compliance with Specification Guidelines on the Reporting of Compliance with Specification ILAC-G8:03/2009 Copyright ILAC 2009 ILAC encourages the authorized reproduction of this publication, or parts thereof, by organisations wishing

More information

Security Risk Management and Assessment System

Security Risk Management and Assessment System ABSTRACT SAGEPOT: A TOOL FOR SECURITY ASSESSMENT AND GENERATION OF POLICY TEMPLATES K. Saleh, A. Meliani, Y. Emad and A. AlHajri American University of Sharjah, Department of Computer Science Box 26666,

More information

Methods Commission CLUB DE LA SECURITE DE L INFORMATION FRANÇAIS. 30, rue Pierre Semard, 75009 PARIS

Methods Commission CLUB DE LA SECURITE DE L INFORMATION FRANÇAIS. 30, rue Pierre Semard, 75009 PARIS MEHARI 2007 Overview Methods Commission Mehari is a trademark registered by the Clusif CLUB DE LA SECURITE DE L INFORMATION FRANÇAIS 30, rue Pierre Semard, 75009 PARIS Tél.: +33 153 25 08 80 - Fax: +33

More information

Data Protection Audit Manual Part 1: Introduction. Section Title Page. Part 1 Introduction 1.3. 1. Aims of Data Protection Compliance Audits 1.

Data Protection Audit Manual Part 1: Introduction. Section Title Page. Part 1 Introduction 1.3. 1. Aims of Data Protection Compliance Audits 1. Data Protection Audit Manual Part 1: Introduction Part 1: Introduction Section Title Page Foreword 1.2 Part 1 Introduction 1.3 1. Aims of Data Protection Compliance Audits 1.3 2. Why Should We Audit? 1.3

More information

Need a system to deliver consistent, efficient and reliable IT services? Use an ISO/IEC 20000 compliant management system.

Need a system to deliver consistent, efficient and reliable IT services? Use an ISO/IEC 20000 compliant management system. Need a system to deliver consistent, efficient and reliable IT services? Use an ISO/IEC 20000 compliant management system. ISO/IEC 20000 your first choice for IT service management. BSI is the business

More information

General Rules for the Certification of Management Systems Code: RG

General Rules for the Certification of Management Systems Code: RG General Rules for the Certification of Management Systems Code: RG Drafted on: 1 April 2012 Effective from: 1 October 2012 TABLE OF CONTENTS CHAPTER TITLE PAGE CHAPTER 1 GENERAL 3 CHAPTER 2 REFERENCE STANDARD

More information

Certification Process Requirements

Certification Process Requirements SAAS Certification Process Requirements SAAS Procedure 200 Social Accountability Accreditation Services, June 2010 Accreditation Process and Policies SAAS Normative Requirements SAAS maintains a set of

More information

IAF Informative Document. Transition Planning Guidance for ISO 9001:2015. Issue 1 (IAF ID 9:2015)

IAF Informative Document. Transition Planning Guidance for ISO 9001:2015. Issue 1 (IAF ID 9:2015) IAF Informative Document Transition Planning Guidance for ISO 9001:2015 Issue 1 (IAF ID 9:2015) Issue 1 Transition Planning Guidance for ISO 9001:2015 Page 2 of 10 The (IAF) facilitates trade and supports

More information

ISO/IEC/IEEE 29119 The New International Software Testing Standards

ISO/IEC/IEEE 29119 The New International Software Testing Standards ISO/IEC/IEEE 29119 The New International Software Testing Standards Stuart Reid Testing Solutions Group 117 Houndsditch London EC3 UK Tel: 0207 469 1500 Fax: 0207 623 8459 www.testing-solutions.com 1 Stuart

More information

IRCA Certificated QMS Lead Auditor Training Course. Programme

IRCA Certificated QMS Lead Auditor Training Course. Programme IRCA Certificated QMS Lead Auditor Training Course Programme Day 1 08.30 Registration 09.00 Introductions / Course overview / Delegate assessment IRCA and the Auditor Certification Scheme 09.45 An Overview

More information

EUROPEAN COMMISSION ENTERPRISE AND INDUSTRY DIRECTORATE-GENERAL. Space, Security and GMES Security Research and Development

EUROPEAN COMMISSION ENTERPRISE AND INDUSTRY DIRECTORATE-GENERAL. Space, Security and GMES Security Research and Development Ref. Ares(2011)193990-22/02/2011 EUROPEAN COMMISSION ENTERPRISE AND INDUSTRY DIRECTORATE-GENERAL Space, Security and GMES Security Research and Development Brussels, 17 th February 2011 M/487 EN PROGRAMMING

More information