ISO27001 and the Documented Information Requirements
ISO27001 Information Security Management Systems

Like all ISO Management Systems your ISO 27001:2013 Information Security management System is going to need some documentation. The requirements of exactly what to document however are spread throughout the standard in each clause as requirements for documented evidence or records, typically prefaces with the words shall. Clause 7.5 documented info...

  2944 Hits
The One Critical KPI
Operational Excellence

There are a few things you need to know about Business Metrics or KPI's (Key Performance Indicators), firstly its that they are important, anyone who says any different clearly does not really understand how businesses work. KPI's help you understand how your organisation is performing, if you are winning or losing, getting better or getting worse....

  3998 Hits
5 Steps to Effective Annual Objectives and Organisational Alignment
Leadership

With the year almost over a friend of mine got an email from his with a sheet of paper attached asking him to put together his 5 objectives for 2021 and remember they must be SMART! Smart being a SMART Goal which is about being Specific Measurable Achievable Realistic and Time bound. I hate this he said, what is the point, what the heck am I suppos...

  2801 Hits
ISO27001 and the Awareness and Communication Requirements
ISO27001 Information Security Management Systems

The great thing about ISO27001:2013 is that it follows the high-level structure set out by ISO as their preferred way of working through a standard. What that means it that pretty much all the new ISO standards follow the same list of 10 clauses in the same order. It is designed to help you align your various management systems. That's really helpf...

  4955 Hits
List of mandatory documents required by ISO 27001:2013
ISO27001 Information Security Management Systems

It has been a fair while since ISO27001:2013 for Information Security Management Systems was published yet it's adoption is only really now starting to gain some traction, just in time for the work on the next revision to really get underway. Like all ISO standards there are set requirements about what you must do, ISO list these as "shall" , part ...

  28463 Hits
ISO27001 and the Resources and Competence Requirements
ISO27001 Information Security Management Systems

ISO2001:2013 clause 7 is all about Support, what do you need, what have you got, does everyone know what they should be doing, have you documented it and a few other things besides that. In this post we are going to cover the first two clauses, clause 7.1 Resources and Clause 7.2 Competence because we think they pretty much go hand in hand, hopeful...

  5635 Hits
Getting an Understanding of the Critical Elements in Your Lean Journey
Operational Excellence

Recently I had the chance to catch up with Craig from Mango QHSE to talk about lean. More specifically Understanding of the Critical Elements in Your Lean Journey, what things need to be in place if you are going to have a successful lean transformation for your organisation.  When it comes to lean people get hooked on the tools, forgetting th...

  2196 Hits
The 5 lean steps to stopping fire-fighting at work
Operational Excellence

The phone is ringing and you know it is going to be another unhappy customer, the only question is what are they going to complain about? Their product is late, there are defects in what they got, they got the wrong thing, there were too many or not enough. Every time the phone it is a complaint, another fire to be put out, another thing that you n...

  3306 Hits
ISO27001 - Information Security Objectives and Planning to Achieve Them
ISO27001 Information Security Management Systems

Having objectives is pretty important if you want to achieve something or get somewhere. Organisations (hopefully) have objectives for most things like profitability, sales per year, marketing and even their ISO9001 Quality Management System. It makes sense then that there should be some objectives linked to your ISO27001 Information Security Manag...

  7861 Hits
If you want better engagement and alignment, then its time to kill the Annual Review
Organisational Health

The working year has many milestones that are marked on the wall or outlook calendars. Some are looked on with excitement and some, well not so much. The annual break and long weekends would be the big positives, on the other side we have things like monthly budget reviews and of course the annual employee reviews. It does not matter if you are the...

  2432 Hits
ISO27001 and the Actions to Address Risk & Opportunities
ISO27001 Information Security Management Systems

Like many of the latest ISO standards ISO27001 for Information Security Management Systems takes a risk-based approach to things. That makes sense, since it is hard to make something secure, if you do not understand the risks. Clause 6.1 of the standard – Actions to address risk and opportunities is where this risk-based thinking really kicks into ...

  3966 Hits
Building the Lean Muscle
Operational Excellence

Last month I was having a chat with a friend about a problem they were having at their organisation. They had been trying to get their people involved in doing some continuous improvement, or any improvement work. They had sat everyone down and told them that they needed to find ways to get products out quicker. The issue was that their order book ...

  1903 Hits
Organisational Inductions - you are doing them wrong
Organisational Health

Recently I was talking to a group of people (all from different organisations) about Standard Work. That is when organisations have a method of doing things, just one method, everyone does it the same way so you can get repeatable results. However, the important thing about these standard work routines or practices is that they do have to change ov...

  2083 Hits
ISO27001 & The Roles, Responsibilities and Authorities Clause
ISO27001 Information Security Management Systems

If you have already obtained ISO9001 you will recognise the name of this clause because of course they are both aligned to the same high-level structure. The other bonus with already having obtained 9001 is that you are already mostly the way there with achieving the requirements of this clause for your Information security management System. The i...

  6747 Hits
How to Create a Lean Layout
Operational Excellence

The other day I watched the movie The Founder with Michael Keeton who plays Ray Kroc the "founder" of the McDonalds restaurant chain. It is a great movie and it is pretty factual as biopics go, and as it turns out technically, he is not the founder of McDonalds, the McDonald brothers were (hence the name) and certainly worth a watch. It brought bac...

  4980 Hits
ISO27001 & The Information Security Policy
ISO27001 Information Security Management Systems

Clause 5.2 of ISO27001:2013 is all about your Information Security Management Policy and it is pretty insistent that you have one, in fact its Mandatory. That is a pretty good thing since everything else in your entire Information Security Management System happens because of this policy which make sense if you think about it. Policies sit at the t...

  6509 Hits
Fractured – Waste in the Medical Clinic
Operational Excellence

Earlier this week I had to take my daughter to the fracture clinic to get her leg checked out. She had broken it 4 weeks ago and it was check up time. It was interesting when she 1st went to get it check out when it happened. On the original visit hey had asked all sorts of questions, decided on an outcome then thought, actually we should Xray it j...

  5410 Hits
How Does ISO Define Traceability?
ISO 9001 Quality Management

One of the questions I get asked a lot (and it really is a lot!) is "How does ISO define traceability?" that's always accompanied with: what do they want, what things do I need put in place, will it be expensive and but my customer doesn't care about it! The answer, initially at least is, "It depends!" Obviously, this is not overly helpful, so we n...

  9736 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.test.manycaps.com/

Subscribe to Our Newsletter

To Get Regular Updates on ISO | Lean | Free Resources
Sorry we need your name
Invalid Input - Sorry we need your last name here
Sorry Can you just check your email address as well

We Support

Trees That Count
Special Childrens Xmas Party

Proud To Be

Canterbury Trusted