<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Documentation | UK ISO Consultants</title>
	<atom:link href="https://isoconsultants.co.uk/tag/documentation/feed/" rel="self" type="application/rss+xml" />
	<link>https://isoconsultants.co.uk</link>
	<description>Leadership and guidance preparing you for ISO auditing</description>
	<lastBuildDate>Tue, 28 Jul 2026 09:23:06 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://isoconsultants.co.uk/iso2023wp/wp-content/uploads/2023/09/cropped-iso-fab-icon-32x32.png</url>
	<title>Documentation | UK ISO Consultants</title>
	<link>https://isoconsultants.co.uk</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>ISO 27001 Certification Cost. Hopefully Less Than £400,000&#8230;</title>
		<link>https://isoconsultants.co.uk/iso-27001-certification-cost-hopefully-less-400000/</link>
					<comments>https://isoconsultants.co.uk/iso-27001-certification-cost-hopefully-less-400000/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Fri, 07 Oct 2016 08:52:17 +0000</pubDate>
				<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[BYOD Dangers]]></category>
		<category><![CDATA[BYOD Threats]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[ISO 27001 Certification Cost.]]></category>
		<category><![CDATA[ISO 27001 pdf download template]]></category>
		<category><![CDATA[ISO 27001 PDF Template Download]]></category>
		<category><![CDATA[ISO 9001 Requirements]]></category>
		<category><![CDATA[ISO audit preparation]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[ISO Consultant]]></category>
		<category><![CDATA[ISO Consulting]]></category>
		<category><![CDATA[ISO local Derby]]></category>
		<category><![CDATA[ISO local Leicester]]></category>
		<category><![CDATA[ISO local Nottingham]]></category>
		<category><![CDATA[ISO PDF Download]]></category>
		<category><![CDATA[IT outsourcing problems]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[Requirements]]></category>
		<category><![CDATA[West Midlands]]></category>
		<category><![CDATA[What is ISO27001]]></category>
		<guid isPermaLink="false">http://www.independentqualityservice.com/?p=4097</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/iso-27001-certification-cost-hopefully-less-400000/">ISO 27001 Certification Cost. Hopefully Less Than £400,000&#8230;</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">I&#8217;m told that ISO 27001 Certification Cost is one of the most searched terms relating to ISO 27001 on the internet.</p>
<p>How much does certification cost? It&#8217;s worth reflecting on the cost of <em>not</em> having it. For TalkTalk in October 2016, the “failure to implement the most basic cyber security measures” <a href="http://www.bbc.co.uk/news/business-37565367" target="_blank" rel="noopener">cost around £400,000 in fines.</a></p>
<p>Some of TalkTalk&#8217;s IT security measures were probably very good indeed. But they were probably the wrong ones for the threat. And it&#8217;s highly likely that they even held <a href="https://isoconsultants.co.uk/standards/iso-27001/">ISO 27001 certification.</a><br />
<span id="more-4097"></span></p>
<h5><strong>Risk and Compliance; Welcome to The Future!</strong></h5>
<p>ISO standards are changing. A key focus is now “risk”, rather than &#8220;compliance&#8221;. On crucial questions being asked, such as “what if this fails?” or of “if X gains access to Y”.</p>
<p>Back in the old days it was all about compliance, that is, “how do you know your products and services are any good, have you met this regulation, or that customer requirement”. It&#8217;s that dreaded man with the brown dustcoat, clip-board and attitude. Measuring and criticizing.</p>
<p>To be truly effective, <a href="http://www.iso.org/iso/home/standards/management-standards/iso27001.htm" target="_blank" rel="noopener">ISO 27001</a> needs to start “where you are” as a business, rather than enforcing a vast system of parameters and procedures, only 20% of which have any relevance, but are vital in gaining that framed certificate in your reception area.</p>
<p>Hence, <em>the ISO 27001 certification cost depends on what actually needs protecting</em>. <a href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much/">Many companies pay too much&#8230;</a></p>
<h5><strong>Risk &#8211; Have You Locked The Right Doors?</strong></h5>
<p>Imagine your business as a building. Rather than spending a fortune securing it against any but the most talented of 007 types, why not give some considered thought to “who is likely to want to break in anyway? And where?”</p>
<p>This “risk-based” approach can make a huge difference ISO 27001 certification cost; preventing James Bond gaining access to your Server Room might be very difficult and expensive, but are you holding anything he’d actually want anyway ?</p>
<h5><strong>Risk, Laptops, and The Cloud. An Example</strong></h5>
<p>An example of the “risk-based” approach:- I&#8217;m highly sceptical of the current fashion of putting everything into “The Cloud”. I&#8217;m almost ashamed to admit, however, below is a situation where The Cloud works rather well.</p>
<p>A laptop is stolen. If you are using purely cloud-based software, with reasonably secure log on and complex password, chances are all you’ve lost is a £500-600 asset which may even be covered by insurance. Your data will remain safely in the cloud and you can just pick up another laptop, log into your account and carry on. Based on this, the vital focus would therefore be on the security of cloud access, rather than laptops being chained to desks and guarded by a Rottweiler. And a procedure being written around this, including type of dog biscuits.</p>
<h5><strong>And, Once More For Those Googling ISO Certification Cost?</strong></h5>
<p>I suspect I have not answered the key question about ISO 27001 certification cost. Well, not in a day rate and number of days. Because it will depend on how <em>you</em> work as a business. But hopefully I have destroyed the myth that ISO 27001 is a very large and blundering, paperwork-heavy, expensive, hoop-jumping exercise.</p>
<p><a href="https://isoconsultants.co.uk/contact/">Please feel free to give me a call or drop me a line.</a> I promise to start where you are and see where you want to go to protect your business. And avoid the headlines.</div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_1    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_0 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-1" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-1" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/iso-27001-certification-cost-hopefully-less-400000/">ISO 27001 Certification Cost. Hopefully Less Than £400,000&#8230;</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/iso-27001-certification-cost-hopefully-less-400000/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>An Insider&#8217;s View of ISO 27001 Certification</title>
		<link>https://isoconsultants.co.uk/insiders-view-iso-27001-certification/</link>
					<comments>https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comments</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Thu, 07 Jul 2016 14:06:31 +0000</pubDate>
				<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[BYOD Dangers]]></category>
		<category><![CDATA[BYOD Threats]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[ISO 27001 Certification]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[ISO Consultant]]></category>
		<category><![CDATA[ISO Consulting]]></category>
		<category><![CDATA[ISO local Derby]]></category>
		<category><![CDATA[ISO local Leicester]]></category>
		<category><![CDATA[ISO local Nottingham]]></category>
		<category><![CDATA[ISO PDF Download]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[What is ISO27001]]></category>
		<guid isPermaLink="false">http://www.independentqualityservice.com/?p=3864</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/">An Insider&#8217;s View of ISO 27001 Certification</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_1 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_2   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p class="western" style="text-align: left;" align="CENTER"><span style="font-family: 'Trebuchet MS', sans-serif;">Our Lead Consultant, Colin Brown, has worked with clients seeking <a href="https://isoconsultants.co.uk/standards/iso-27001/">ISO 27001</a> Certification since it&#8217;s infancy. He has seen a recent rise in interest in the standard. Marketing Consultant Rob Govier asked some questions, taking advantage of his “insider” knowledge.<br />
<span id="more-3864"></span></span></p>
<h6><span style="font-family: 'Trebuchet MS', sans-serif;">You&#8217;ve noticed a spike in ISO 27001 Certification. Is this due to high-profile data breaches? Or are clients finally waking up to it&#8217;s value?</span></h6>
<p><i><span style="font-family: 'Trebuchet MS', sans-serif;">The high profile breaches have certainly had an impact. Our clients are realizing that a regular and systematic review of security risks isn&#8217;t just a “nice to have” item.</span></i></p>
<p><span style="font-family: 'Trebuchet MS', sans-serif;"><i>But the main driver are clients&#8217; own customers. They are insisting that they control their security risks. So customers are putting pressure on their suppliers. Pressure is applied to gain an ISO 27001 certification. Also, buyers are using ISO 27001 as a differentiator in procurement. Therefore, waiting until you are driven may be an option, but could also mean lost bids and tenders.</i></span></p>
<h6 class="western"><span style="font-family: 'Trebuchet MS', sans-serif;">Do you think that the whole cyber security issue will get worse before it gets better? The whole BYOD issue seems to be a major threat. </span></h6>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;"><i><a href="https://www.gov.uk/government/news/two-thirds-of-large-uk-businesses-hit-by-cyber-breach-or-attack-in-past-year" target="_blank" rel="noopener">Cyber security is not going to cease to be a problem in the near future.</a> As long as software companies can save money by reducing their pre-release testing, there will be products with vulnerabilities. Link that with the fact that<a href="https://en.wikipedia.org/wiki/Hacker_culture" target="_blank" rel="noopener"> hackers are as clever as software developers</a>, its pretty obvious that every now and then there’s going to be failure. And someone is going to be caught out.</i></span></p>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;"><i><a href="https://www.ncsc.gov.uk/guidance/byod-executive-summary" target="_blank" rel="noopener">BYOD</a> is not such a problem as feared. But I&#8217;m always surprised at how many companies tolerate staff (particularly sales staff) wandering around with confidential sales and pricing strategies on private smart phones. At one time, salesmen had to secretly photocopy information useful to competitors in order to get them their next job. Now they don’t need to bother. The information they need is probably in their phone anyway.</i></span></p>
<h6 class="western"><strong><span style="font-family: 'Trebuchet MS', sans-serif;">What do you normally find when you do an initial analysis for ISO 27001 certification? Are you often shocked at what you find? What are the common weak spots?</span></strong></h6>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;"><i>It’s not unusual to find that <a href="http://www.computerweekly.com/news/1369092/Data-backup-vs-archiving-Whats-the-difference" target="_blank" rel="noopener">data backups</a> never leave the site As a result, they would burn with the rest of the premises. It’s also very common that nobody has ever tried to actually test a backup. So even though your failure might not be as catastrophic as a burnt down factory it’s always worth checking that precautions do actually work.</i></span></p>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;"><i>I often see a tendency to “trust” rather than positively verify. –“The MD of the IT service company goes to Rugby matches with the Sales Director, he’s a really good guy. A great laugh, talks about software and servers all the time. He must know what he’s doing.  He’s the expert after all…..”. I wish I had a pound for every time I’ve been told this.  I could also talk about “IT Maintenance” companies run from a garage Server “farms” which turned out to be a single server, with broadband but no fire alarm.  Neither UPS back-up power nor staff to monitor them.</i></span></p>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;"><i>It&#8217;s always worth asking your “outsource partner” a few very basic probing questions. You could even visit their premises.</i></span></p>
<h6 class="western"><strong><span style="font-family: 'Trebuchet MS', sans-serif;">How often do you find that clients are already using “best practice” anyway? </span></strong></h6>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;"><i>I would say most companies are 70% of the way there already. However, with security, the extra 30% is often crucial, but expensive. Having an unchecked security leak is like having an undetected illness.  The ignorance might stop you worrying but sooner or later it could also kill you.</i></span></p>
<p class="western"><span style="font-family: 'Trebuchet MS', sans-serif;">There&#8217;s a “part two” of this interview on the way soon! Meanwhile, Colin Brown is happy to share more of his forthright insights on ISO 27001 Certification. <a href="https://isoconsultants.co.uk/contact/">You&#8217;re welcome to drop him a line.</a>.</span></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_1 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_3    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-2" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-2" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/">An Insider&#8217;s View of ISO 27001 Certification</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/insiders-view-iso-27001-certification/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>ISO 27001 Documentation Requirements. And The “ISO 27001 PDF Download Checklist”</title>
		<link>https://isoconsultants.co.uk/iso-27001-documentation-requirements-and-the-iso-27001-pdf-download-checklist/</link>
					<comments>https://isoconsultants.co.uk/iso-27001-documentation-requirements-and-the-iso-27001-pdf-download-checklist/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Wed, 29 Apr 2015 14:30:25 +0000</pubDate>
				<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO PDF Free Download]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[Business Continuity Management]]></category>
		<category><![CDATA[BYOD Dangers]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[ISO 27001 PDF]]></category>
		<category><![CDATA[ISO Audit]]></category>
		<category><![CDATA[ISO Auditor]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[ISO Consulting]]></category>
		<category><![CDATA[ISO local Derby]]></category>
		<category><![CDATA[ISO local Leicester]]></category>
		<category><![CDATA[ISO local Nottingham]]></category>
		<category><![CDATA[ISO PDF Free Checklist Download]]></category>
		<category><![CDATA[IT outsourcing problems]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[PDF Download Free Checklist]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[Requirements]]></category>
		<category><![CDATA[West Midlands]]></category>
		<category><![CDATA[What is ISO27001]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=3249</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/iso-27001-documentation-requirements-and-the-iso-27001-pdf-download-checklist/">ISO 27001 Documentation Requirements. And The “ISO 27001 PDF Download Checklist”</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_2 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_4   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_2">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>It seems that many people look for an ISO 27001 PDF Download Checklist on the web.</p>
<p>We&#8217;ve created our own. <a href="https://isoconsultants.co.uk/contact/">Contact us for details.</a> However, it shows how wide the scope of <a href="http://www.iso.org/iso/home/standards/management-standards/iso27001.htm" target="_blank" rel="noopener">ISO 27001</a> is.</p>
<p>We are not in favour of the approach behind an ISO 27001 PDF Download Checklist  as we wrote <a href="https://isoconsultants.co.uk/iso-27001-implementation-basic-guide/">here</a>. Like most ISO standards, successful approval will involve <em>the whole business</em>. Not a checklist in the IT department. Or anywhere else.</p>
<p>We do, however, make our key ISO 27001 PDF download templates available for sale via our shop page. These are not checklists, but the solid foundations for system design.  And they are fully remote-supported by our staff .</p>
<p>However, as an ISO Consultant, I&#8217;m frequently asked the same question about <a href="http://www.bsigroup.co.uk/en-GB/iso-27001-information-security/" class="blc-broken-link" data-blc-broken="1">ISO 27001</a>:-</p>
<p><strong><em>&#8220;So ISO 27001 is all about IT Security isn&#8217;t it ?”</em></strong></p>
<p><em>Well, “yes”. But mainly “no”.</em><span id="more-3249"></span></p>
<h6><strong>What Is It About, Then?</strong></h6>
<p>The standard is about installing a quality management system.  This manages the security of <em><strong>all information held by the organisation</strong></em> (IT security does, of course, play a part in this), As a result has a <a href="https://isoconsultants.co.uk/make-iso-standards-work-iso-consultant-shares-thoughts/">significantly wide wide reach across a business.</a></p>
<h6><strong>But just how wide?</strong></h6>
<p>Here’s a list of the documentation used by us for a recently approved company. Are you sitting comfortably?  And this isn&#8217;t even the complete version.</p>
<h6><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: medium;"><b>Policy for all Staff</b></span></span></span></h6>
<p class="western"><span style="font-size: small;"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;">Information Security Policy Statement &#8211; </span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;">Statement of system requirements</span></span></span></p>
<p class="western"><span style="font-size: small;"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;">Information Security &#8211; Objectives Table &#8211; </span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;">Progress in implementing the IS Policy Statement</span></span></span></p>
<p class="western"><span style="font-size: small;"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;">Information Security Management System Manual &#8211; </span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;">System explanation &amp; responsibilities for all staff</span></span></span></p>
<h6 class="western"><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: medium;"><b>Supporting Documentation</b></span></span></span></h6>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Company Organisation Chart</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Management Responsibility Statements and Job Descriptions &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Documented responsibility statements for those holding security responsibilities</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Network and Server Architecture Diagram &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Diagram of all the IT network and services covered by the Information Security Management System</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Approved Software &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Software which can be installed on PS’s as required</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Network Capture/Analysis/Scanning Tools &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">List of network </span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">tools that can only be used by IT Support staff</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Control of Non-Conformance and Corrective Action Procedure &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">What to do if you think there is a security breach,and what will be done subsequently.</span></span></span><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;"> </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">.</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Use of Email, Internet, and Social Media &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">S</span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">pecifics on use of email, social media etc.</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">( Possible Addition to the Employee Handbook) </span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">IT Support Procedure &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">How to log security breaches or any other IT issues you need help with.</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Control of Documented Policy &amp; Procedures, &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">How to update/get a policy or procedure updated</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Data and Records</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Human Resources Index &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Staff Handbook and HR related procedures</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Information Security Risk Assessment &amp; Treatment Plan &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">W</span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">hat the risks are to our information</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Statement of Applicability for ISO 27001 &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">R</span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">esponses with evidence for the Appendix Compliance Questions</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Register of Legislation and Handling &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Register of applicable legislation </span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Business Continuity Plan &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">How to keep the business running if an emergency occurs.</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Supplier and Sub-Contractor Management &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">How to select sub-contractors and suppliers and what security practices affecting them should be in place </span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Purchasing Procedure </span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Approved suppliers and sub-contractors list-  </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">List of those who have confirmed acceptance of your security practices.</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Internal and External Audit Procedure &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">How to complete </span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">ISO audits</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">ISO 27001 Audit Plan &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Schedule/</span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Plan for audits</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Audit Report Form Template &#8211; </span></span></span><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Template for audit results</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Preventive Action and Management Review- </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;"> Planning the development of the security system and implementing a full review of the system by management.</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Management Procedure for Training and Competence    &#8211;</span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Description of how staff are trained and make themselves familiar with the management system and competent with security issues<span style="color: #0000ff;">.</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Information Systems Continuous Improvement plan</span></span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Data Protection Registration</span></span></span></p>
<h6 class="western"><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: large;"><b>Requirements for Specific Roles</b></span></span></span></h6>
<h6 class="western"><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: medium;"><b>IT Support</b></span></span></span></h6>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">IT Network Managers Security Procedures &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Security procedures specific to the Network Management Role</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Backup Procedures &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Procedures for backing up information and records</span></span></p>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Assets and Services &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">List of all IT and Information Assets</span></span></p>
<h6 class="western"><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: medium;"><b>New Joiners</b></span></span></span></h6>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Induction Checklist </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Evidence that new joiners are made aware of information security system practices and requirements.</span></span></p>
<h6 class="western"><span style="color: #000000;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: medium;"><b>Marketing</b></span></span></span></h6>
<p class="western"><span style="color: #0000ff;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">PR process &#8211; </span></span></span><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="font-size: small;">Process to ensure press releases etc. are suitable approved prior to release.</span></span></p>
<p>Phew!  Yes, it really is that involved. I think that this is outside the scope of most ISO DIY-ers with their ISO 27001 PDF Download Checklist . We&#8217;ve even left some things out of this.</p>
<p>However, this is simply a “to-do list”. A<em> “how to do”</em> approach is what is really needed.</p>
<p>All ISO standards should be bespoke to the business. Otherwise, they don&#8217;t “fit” it&#8217;s aims, activities, and culture. And, if they don&#8217;t fit, they don&#8217;t work. Hence why you need an ISO consultant to help.</p>
<p>Successful approval to ISO 27001 and it&#8217;s is way more than what you&#8217;d find in an ISO 27001 PDF Download Checklist. If you think we could help, <a href="https://isoconsultants.co.uk/contact/">please drop us a line!</a>.</p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_2 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_5    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_2 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-3" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-3" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/iso-27001-documentation-requirements-and-the-iso-27001-pdf-download-checklist/">ISO 27001 Documentation Requirements. And The “ISO 27001 PDF Download Checklist”</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/iso-27001-documentation-requirements-and-the-iso-27001-pdf-download-checklist/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Seven Tips on Tenders. And A Free ISO Certification Tenders PDF Download</title>
		<link>https://isoconsultants.co.uk/seven-tips-on-tenders-free-iso-certification-tenders-pdf-download/</link>
					<comments>https://isoconsultants.co.uk/seven-tips-on-tenders-free-iso-certification-tenders-pdf-download/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Mon, 13 Apr 2015 16:33:07 +0000</pubDate>
				<category><![CDATA[ISO PDF Free Download]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification ISO 9001]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[ISO 9001]]></category>
		<category><![CDATA[ISO 9001 Requirements]]></category>
		<category><![CDATA[ISO Approval Tender]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[ISO Consultant]]></category>
		<category><![CDATA[ISO Consulting]]></category>
		<category><![CDATA[ISO local Derby]]></category>
		<category><![CDATA[ISO local Leicester]]></category>
		<category><![CDATA[ISO local Nottingham]]></category>
		<category><![CDATA[ISO PDF Download]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[QMS]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[Requirements]]></category>
		<category><![CDATA[West Midlands]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=3223</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/seven-tips-on-tenders-free-iso-certification-tenders-pdf-download/">Seven Tips on Tenders. And A Free ISO Certification Tenders PDF Download</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_3 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_6   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>We&#8217;re often contacted by companies wanting to bid for a tender, but faced with the requirement for ISO Certification. To make life easier, we&#8217;ve put together an ISO Certification Tenders PDF that answers the main points. <a href="https://isoconsultants.co.uk/contact/">Contact us for details.</a></p>
<p>However, we thought we&#8217;d expand this a little, looking at some background, plus wider benefits for your business. (And yes, I&#8217;ve struggled with tender responses myself, too.)<span id="more-3223"></span></p>
<p><strong><em>ISO Certification for a Tender is Not a “Nice To Have”</em>.</strong> Some companies seem to believe that holding a particular standard such as<a href="https://isoconsultants.co.uk/iso9001-best-practice-common-sense/"> ISO9001</a> will give the tender issuer a &#8220;warm feeling&#8221; about their company, rather like charity and community involvement, sponsorship of a donkey sanctuary, brass band etc, etc. It indicates in a vague sense that the company has a “conscience” about quality, a vague intention.</p>
<p>Quite the opposite is true. Tendering bodies now place a huge weight on an organisation holding ISO Certification, for reasons I&#8217;ll outline below, so holding the appropriate approval needs to be given serious consideration. This is more than a framed certificate on the reception wall, or a logo on a letterhead. ISO Certification is taken very seriously indeed by those wishing to place, long-term business, and seeking a reliable supplier. Understandably so.</p>
<p><strong><em>ISO Certification Makes The Tender Process Easier For All.</em> </strong>Quite simply, if you hold a specific and current approval, it immediately benchmarks your company in the eyes of the procurement department. There&#8217;s not always a need to go into detail about some of your key quality structures and routines – they are already implicit in the the standard, because that&#8217;s what the standard is about. And an external verifier has checked that you&#8217;re actually telling the truth, too. Approvals can be hard-won, but once in place, are regarded as significant by those wishing to trade with your company.</p>
<p>And conversely, if you don&#8217;t hold ISO9001 or similar, it is highly likely that, even if it&#8217;s not explicit in the pre-tendering requirements, your bid, (however well-written), will be put to the back of the queue, or worse. Faced with a heap of bid documents to process, staff will look for the easiest excuse to exclude bidders.</p>
<p><strong><em>You Can&#8217;t Do-It-Yourself and Beat The System.</em> </strong>In theory, you could try and impress the procurement person with your own framework of quality, and even still be successful. However, the heart of ISO Certification is risk management, and the key control measure is the <a href="https://isoconsultants.co.uk/iso-standards/bs-en-iso-9001-quality-management-systems/">Quality Management System</a> (QMS). This is the document (and process!) that determines <em>what</em> you do, <em>why</em> you do it, and <em>how</em> this is measured in respect of quality.</p>
<p>Sadly, most organizations would not know where to start in putting a QMS together. Even the ones working within classic ISO guidelines still sometimes struggle! And, in my previous life as an ISO assessor, I could spot a “downloaded from the internet” or D.I.Y. attempt instantly. If you plan to devote some staff management resource at all to the subject of quality within the company, then you might as well do it within the ISO framework, helped by a friendly consultant, and gain a recognised approval at the end of your hard work.</p>
<p><strong><em>Beyond The Tender, ISO Certification is A Jolly Good Investment! </em></strong> Once installed and working, the approval simply needs revalidating, amending to the changing needs of your business. Furthermore ISO9001, contains elements and frameworks that can be used in other, more specific standards, such as ISO 14001, and ISO 27001. Seeing it as a tool to win a single bid will make certification seem very expensive and risky in terms of potential return. Longer-term, you have all the benefits of an internationally-recognised, independently-verified standard of working.</p>
<p><strong><em>And It Might Actually Do Your Business Good!</em> </strong>I fight a continuing battle to convince managers of all levels that this is more than a “paper exercise”. In the rush to try and compete on a major tender bid, the key fact that ISO Certification is actually highly beneficial to daily business life is often lost. Less waste, more productivity, greater customer satisfaction, all results of working smarter, based on a bespoke Quality Management System.</p>
<p><em><strong>And Next Time, You&#8217;ll be Ready&#8230;</strong> </em> Sadly, companies often approach me in a bit of a panic in order to comply with a deadline, and have a chance of winning a highly lucrative bid. Sadly, there&#8217;s no “Approval Wizard” in the style of a Microsoft Word application that will achieve your certification in five days. Approval takes time. But it then opens up many new opportunities.</p>
<p><em><strong>And The The Major Point Is&#8230;?</strong> </em> Start Now. <a href="https://isoconsultants.co.uk/contact/">Drop us a line.</a> We&#8217;d love to help.</p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_3 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_7    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_3 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-4" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-4" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/seven-tips-on-tenders-free-iso-certification-tenders-pdf-download/">Seven Tips on Tenders. And A Free ISO Certification Tenders PDF Download</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/seven-tips-on-tenders-free-iso-certification-tenders-pdf-download/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Five Things to Consider Before Going for  ISO 9001 or ISO 14001 Certification</title>
		<link>https://isoconsultants.co.uk/five-questions-before-applying-for-an-iso-9001-or-iso-14001-certificate/</link>
					<comments>https://isoconsultants.co.uk/five-questions-before-applying-for-an-iso-9001-or-iso-14001-certificate/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Fri, 10 Oct 2014 13:26:14 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[ISO 14001]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification ISO 9001]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[EN ISO 9001]]></category>
		<category><![CDATA[Get ISO9001 Fast]]></category>
		<category><![CDATA[ISO 9001 Requirements]]></category>
		<category><![CDATA[ISO Auditor]]></category>
		<category><![CDATA[ISO Consultant]]></category>
		<category><![CDATA[ISO Consulting]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[West Midlands]]></category>
		<category><![CDATA[What is ISO]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=2992</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/five-questions-before-applying-for-an-iso-9001-or-iso-14001-certificate/">Five Things to Consider Before Going for  ISO 9001 or ISO 14001 Certification</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_4 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_8   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><a href="https://www.iso.org/standard/62085.html" target="_blank" rel="noopener">https://www.iso.org/standard/62085.html</a>So, before going for <a href="http://www.iso.org/iso/iso14000" target="_blank" rel="noopener">ISO 14001</a> or<a href="http://www.iso.org/iso/qmp_2012.pdf" target="_blank" rel="noopener"> ISO9001</a> certification, I&#8217;d recommend asking some challenging questions. Twenty-five years&#8217; experience in this industry has taught me that the following issues are foundational.<span id="more-2992"></span></p>
<p><em><strong>Step 1 – “Why”?</strong> </em>Do you want to win a tender, or is a profitable customer pushing you for ISO 9001 or ISO 14001 ? If you business has grown rapidly, Perhaps many of your staff might not understand how the overall business works. So you need properly defined processes and procedures for them to follow, and discipline to make and do things well.</p>
<p>Whatever the reason, (and all the above are perfectly acceptable drivers for introducing an ISO standard), make sure you understand <em>why</em> you&#8217;ve made the decision. Getting an ISO certificate can be rapid and inexpensive. For instance, I have implemented ISO 9001 in small, basic businesses with only 2-3 days of my time, where the priority was to respond to a tender which mandated approval of a certain standard.</p>
<p>However, the processes put into place under these circumstances are very basic, and unlikely to be very helpful if the aim is to tighten internal processes and improve consistency throughout the business. Under these circumstances more time is required for a consultant to work with staff and gain their buy-in to the new ways of working. So, a quick fix and a certificate on the wall, or something more?</p>
<p><strong><em>Step 2 – A Matter of Time</em>.</strong> I&#8217;m frequently surprised by the number of customers who pay for my services, and then don’t have the time to listen to what I have to say, or adopt the “best practice” which they tell me they want in their businesses. Even if you have excellent, disciplined processes already in place within your business, gaining certification WILL need some of your time, as what you put in really does have a bearing on what you get out.</p>
<p><strong><em>Step 3 – Take Up Modelling</em>.</strong> Are you ready to be  SEEN to support and apply the system? If you pay mere lip service to the new <a href="http://en.wikipedia.org/wiki/Quality_management_system" target="_blank" rel="noopener"> Quality Management System</a>, then revert to your old ways of working (whenever your consultant or auditor isn’t looking), your staff will notice. They will not take something seriously if you don’t “model” it. If you want the correct process followed, make sure you do yourself. If you want something checking before you ship it, don’t push your staff to despatch everything they can find on the last day of the month just to get the figures up.</p>
<p><strong><em>Step 4 – What Gets Measured Gets Done</em>.</strong> What do you want to achieve in terms of Quality or the Environment? Your policy MUST be underpinned by measurable objectives, which, I&#8217;ve observed, most senior management teams struggle with. Reflect on whether your business is getting too many customer complaints, or too many returned products. Have your neighbours moaned about the noise from your machines or the Environment Agency your emissions? What are your big issues? And how can you measure improvement? This is a great driver for real measures within a “standards” framework. No consultant will be able to dream up such actions &#8211; it needs a knowledge of the business, and the real problems which it faces every day. Which only you have.</p>
<p><strong><em>Step 5 – Give me a call! </em></strong>( I understand there are other consultants but you should really go for the best&#8230; ), I’ve been working in ISO systems for over 25 years, with some of the largest employers in the UK, and many of the smallest. In many different industries, from telecoms to pharmaceuticals, nuclear power generation to web site production, software engineering and basic fabrication. And I began my <a href="https://isoconsultants.co.uk/about/">career</a> on the shop floor in Nottingham, so know industry literally from the ground up. There&#8217;s much to tell, and <a href="https://isoconsultants.co.uk/contact/">I&#8217;d love to help</a>.</p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_4 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_9    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_4 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-5" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-5" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/five-questions-before-applying-for-an-iso-9001-or-iso-14001-certificate/">Five Things to Consider Before Going for  ISO 9001 or ISO 14001 Certification</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/five-questions-before-applying-for-an-iso-9001-or-iso-14001-certificate/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>20 Common Mistakes of an Internal Audit.  Plain Speaking From an ISO Consultant</title>
		<link>https://isoconsultants.co.uk/20-common-mistakes-of-an-internal-audit/</link>
					<comments>https://isoconsultants.co.uk/20-common-mistakes-of-an-internal-audit/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Tue, 22 Jul 2014 16:03:01 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Internal Audit]]></category>
		<category><![CDATA[Internal Auditor Training]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Cost effective]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[ISO 9001 Requirements]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[ISO Consultant]]></category>
		<category><![CDATA[ISO Internal Audit]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[West Midlands]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=2911</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/20-common-mistakes-of-an-internal-audit/">20 Common Mistakes of an Internal Audit.  Plain Speaking From an ISO Consultant</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_5 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_10   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_5">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_5 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_5  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">In my role as an ISO Consultant, I&#8217;ve been delighted to observe many an <a href="http://en.wikipedia.org/wiki/Quality_audit" target="_blank" rel="noopener">ISO internal audit</a> done very well indeed. The value added to the business, both by doing better business, and not having to engage a consultant to sort out messes, is significant. When <a href="http://www.iso.org/iso/home/about.htm" target="_blank" rel="noopener">Internal Auditing</a> works, it works very well indeed.</p>
<p>Yes, you&#8217;ve guessed it. When it becomes dysfunctional, it really does do some damage to the long-term willingness of the enterprise to engage with the standard. And it wastes staff time simply due to a task being conducted badly. Then there&#8217;s the cost of additional days of an <a href="http://isoconsultants.co.uk">ISO Consultant&#8217;s</a> time in putting things right. Now, I don&#8217;t really mind the latter, as it helps to underwrite my wife&#8217;s shopping habit, but it certainly does distress my professional conscience. It really does not have to be like this.</p>
<p>So, some points on what goes wrong.<span id="more-2911"></span></p>
<ol>
<li>Utilising staff that do not believe in the value of the standard (and need for audit) value.</li>
<li>Not making senior Management aware that you add value.</li>
<li>Simply reiterating old audits to “tick boxes&#8221;. Audits need to change with the business.</li>
<li>Issuing out of date, over-long, factually-incorrect, over-detailed and generally non-user-friendly reports.</li>
<li>Focussing on insignificant problems, rather than broader, more business-critical issues.</li>
<li>Lack of quality communication (minimal rapport, outward suspicion) with those audited. This includes lack of informal socialising!</li>
<li>Audit team not truly understanding the areas of the business they are auditing, including technical, regulatory and current industry sector issues.</li>
<li>Re-auditing after an external audit, again to tick an (irrelevant) box (No need to redo work that has been done by others.)</li>
<li>Lack of professional standards in punctuality, dress, protocol, use of time.</li>
<li>A “hit and run” approach – not following through on actions. Not being available or responsive.</li>
<li>Not sharing and explaining audit tools, such as flow charts, walk-through documentation, key performance indicators, etc.</li>
<li>Having reports that are negative and destructive in approach and tone.</li>
<li>Not attending business strategy meetings.</li>
<li>Transferring blaming, declining to take ownership of issues.</li>
<li>Finishing audits even if they don&#8217;t need finishing, such as when you have already determined key controls are working.</li>
<li>Having no team personnel turnover. No new blood – or thinking. Or&#8230;</li>
<li>Having too little experience or continuity.</li>
<li>Hiding behind distance and independence and not adding value via “team participation”</li>
<li>Monitoring the wrong <a href="http://management.about.com/cs/generalmanagement/a/keyperfindic.htm" target="_blank" rel="noopener">KPIs</a> (key performance indicators).</li>
<li>Not continually educating Senior Management about the top inherent areas of exposure, as well as residual risks.</li>
<li>Being a data-provider not knowledge-provider. An Internal audit adds value through application of findings, not just by supplying findings alone.</li>
<li>Not “selling” the audit across the organization via every possible means. Talk to key stakeholders!</li>
</ol>
<p>&nbsp;</p>
<p>And I pose the following tough but revealing question; if you had been a client, would you have paid for your last audit?</p>
<p>It really does not need to be this way. <a href="http://isoconsultants.co.uk/about/">We have some experience in this area</a> If you need help,<a href="http://isoconsultants.co.uk/contact/"> please drop us a line</a></p>
<p>Written by <a title="Colin Brown" href="https://plus.google.com/u/1/109135308302240162318?rel=author" target="_blank" rel="noopener">Colin Brown</a> of ISO Consultants</div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_5 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_11    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_5 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-6" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-6" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/20-common-mistakes-of-an-internal-audit/">20 Common Mistakes of an Internal Audit.  Plain Speaking From an ISO Consultant</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/20-common-mistakes-of-an-internal-audit/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>An ISO Consultant Reveals Ten Myths and Legends of ISO Certification</title>
		<link>https://isoconsultants.co.uk/an-iso-consultant-reveals-ten-myths-and-legends-of-iso-certification/</link>
					<comments>https://isoconsultants.co.uk/an-iso-consultant-reveals-ten-myths-and-legends-of-iso-certification/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Tue, 02 Jul 2013 14:53:06 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[ISO 9001]]></category>
		<category><![CDATA[The Diary of an ISO Consultant]]></category>
		<category><![CDATA[Audit Failure]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification ISO 9001]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[EN ISO 9001]]></category>
		<category><![CDATA[ISO 9001 Requirements]]></category>
		<category><![CDATA[ISO audit preparation]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[ISO Consultancy]]></category>
		<category><![CDATA[ISO Consultant]]></category>
		<category><![CDATA[ISO Consultants]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[West Midlands]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=2198</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/an-iso-consultant-reveals-ten-myths-and-legends-of-iso-certification/">An ISO Consultant Reveals Ten Myths and Legends of ISO Certification</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_6 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_12   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_6">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_6 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>What can you compare the job of ISO Consultant to? Occasionally, it seems a very strange job, running an <a href="https://isoconsultants.co.uk/">ISO Consultancy</a>. There are parallels with being a vicar, priest, or miscellaneous other minister of religion. Now, I wouldn&#8217;t say that being an <a href="https://isoconsultants.co.uk/about/">ISO Consultant</a> is a holy calling of The Almighty. However, in trying to interpret rules and standards from &#8220;on high&#8221; to a practical, workable scheme of things, like <a href="http://www.lrqa.co.uk/standards-and-schemes/ISO-9001/" target="_blank" rel="noopener">ISO 9001</a>, and getting folks to embrace it in their daily working lives, there are great similarities.</p>
<p>And then there are the continual challenges of common misconceptions. Put simply, &#8220;myths and legends&#8221; that don&#8217;t really have much to do with the true essence of what <a href="http://www.iso.org/iso/home/standards.htm" target="_blank" rel="noopener">ISO Standards</a> are all about. Here are ten of them:<span id="more-2198"></span></p>
<h6><strong>1. You can tell a good Quality/Environmental/Health and Safety System document by its weight/thickness.</strong></h6>
<p>No. “Less” is often “more”, providing it makes a difference to your business.  It helps you meet your business objectives. Usually, concise systems are more effective.  Because people are more likely to read, understand, and follow them.</p>
<h6><strong><em>2. Implementing an ISO based system, <a href="http://www.iso.org/iso/home/standards/management-standards/iso_9000.htm" target="_blank" rel="noopener">such as ISO 9001</a>, is a major project and means you have to change the way you run the business.</em></strong></h6>
<p>Generally “No”,  but there are usually a few things to be changed. All companies have “processes” , even if these aren’t documented. A good ISO-Based <a href="https://en.wikipedia.org/wiki/Quality_management_system" target="_blank" rel="noopener">Quality Management System </a>should be written around how you already do business, not consist of alien practices inflicted to get you through the certification. Your business is unique, and the ISO system needs to be based around that uniqueness. Protecting, nurturing and helping it grow. In short, it&#8217;s purpose is to support and formalise the good bits of what you&#8217;re already doing well, rather than impose badly-fitting bureaucracy.</p>
<h6><strong><em>3. The Quality/Environment/Health and Safety Manager is responsible for Quality/Environment/Health and Safety, and lives in their own world. Meanwhile, the rest of us get on with running the business profitably.</em></strong></h6>
<p>No. This might be acceptable if we lived in a world with no fines for breaking laws, and accidents never happened. However, in this area there are very serious implications for non-compliance. So ideally, there shouldn&#8217;t be anybody in an organisation whose operations aren&#8217;t affected by them. In successful companies, with well-designed ISO systems, no-one should be able to notice that they are actually working to a standard. They should truly be part of “business as usual”. It&#8217;s safer (and cheaper) that way, too.</p>
<h6><strong><em>4. All these quality systems are just government bureaucracy and don’t do anything for the business.</em></strong></h6>
<p>This is closely related to myth three (above) Although backed by governments internationally, properly-written business-focused standards should help, not hinder companies. A good <a href="http://en.wikipedia.org/wiki/Quality_management_system" target="_blank" rel="noopener"> Quality Management System</a> should help you be more efficient and consistently meet your customer’s requirements. <a href="https://isoconsultants.co.uk/iso-standards/ohsas-18001-occupational-health-and-safety-management-systems/">Environmental health and safety systems</a>, although protecting your staff and surroundings, should also help you avoid large fines, some of which could be large enough to threaten the whole future of your business. Properly-implemented, they should lead to contented customers, more efficient activity, and better business.</p>
<h6><strong><em>5. Quality systems are really just about controlling documents. Therefore, if in doubt, sign everything.</em></strong></h6>
<p>Perhaps in the past, quality systems in particular were over- focussed on documentation. But changes over the last 10-15 years have aimed them much more at improving effectiveness and efficiency. That said, the control of information within a business remains important, and for good reasons. You can&#8217;t manage without documentation, but it should serve the business, rather than the business serving it.</p>
<h6><strong><em>6. We can hide our problems areas. If you <a href="http://dilbert.com/strips/comic/1995-09-27/" target="_blank" rel="noopener">manage the auditors properly</a>, you can keep them in the Quality Managers office all day. </em></strong></h6>
<p>Being clever with the auditors and keeping them away from problem areas may be a crafty and useful tactic in the short-term. But if your systems are really any good, then you shouldn&#8217;t have problem areas that you aren&#8217;t addressing. However, if you do have weak areas, <a href="http://dilbert.com/strips/comic/1996-10-01/" target="_blank" rel="noopener">then honesty really is the best policy</a>. If you are taking action to improve things, then auditors should respond positively, and letting them see what you’re doing can be positive for two reasons. Firstly, they know you are committed to improvement. Secondly, having seen lots of similar situations before, they may actually be able to offer advice. This is the “auditor as business improvement consultant” approach, and is highly effective.</p>
<h6><strong><em>7. It’s always best to keep your mouth shut and only give the minimum of information to the auditors.</em></strong></h6>
<p>Yes, but don’t expect to get a lot out of the audit if you don’t put much in. Make some more words up !</p>
<h6><strong><em>8. The auditors are only looking for reasons to fail you.</em></strong></h6>
<p>Funnily enough, in over 20 years’ experience of this environment I&#8217;ve rarely found an auditor who just wants to fail people. This is their job, day-in, day-out, and very few people can be so negative for so long. However, if you really don’t get on with your auditor, then change him. If the certification body aren&#8217;t helpful with this, then change them too. There are around 120 certification bodies in the UK so you have plenty of choice, and they all take very kindly to people changing from their competitors, so you might even find a lower cost alternative.</p>
<h6><strong><em>9. Environmental systems just increase your operating costs.</em></strong></h6>
<p>An Environmental Management System (EMS), such as <a href="http://www.iso.org/iso/home/standards/management-standards/iso14000.htm" target="_blank" rel="noopener">ISO 14001</a>, should not be about tree hugging and love for little furry animals. It&#8217;s no longer a PR-friendly “nice-to-have” marketing tool, but should be make very sound business sense. And why? Breaking environmental law now has very expensive consequences. It could even be enough to push you into liquidation. Ignorance of the legislation affecting your operations is no defence, so having a good environmental system which is properly maintained should keep your business lawful, and you out of jail. <i>Yes, and I really do m</i><i>ean &#8220;jail&#8221;</i></p>
<h6><strong><em>10. If you get one well written set of risk assessments, then you’ve addressed your Health and Safety requirements, and the staff can carry on as normal with their everyday jobs.</em></strong></h6>
<p><a href="http://www.bsigroup.com/en-GB/ohsas-18001-occupational-health-and-safety/" target="_blank" rel="noopener">Health and safety systems</a> are now a commodity like most other things. If you just want some <a href="http://www.hse.gov.uk/risk/record-your-findings-and-implement-them.htm" target="_blank" rel="noopener">risk assessments</a> then you could buy them in. But the value of such systems is in them being applied to real business life. Do you really want your staff knocking holes in walls without checking if there are mains cables hidden in the plaster, or driving stacker trucks without being trained ? Health and Safety isn&#8217;t a matter of documentation. It should be a matter of practice, though documentation and records are, unfortunately, required.</p>
<h6>If you&#8217;ve read this far, then you&#8217;ve got a good idea of how I work.</h6>
<p>Hopefully, you will get some idea of the challenges of being a ISO Consultant. There is an art in keeping compliance and business success in tension, which involves large amounts of both technical comprehension and hard-won common-sense. After over <a href="https://isoconsultants.co.uk/about/">twenty years in the industry</a>, and having advised many types and “flavours” of enterprise, I suspect that I may have at least a few things to offer to your organisation. And I&#8217;d be happy to “bust” a few more myths that I&#8217;ve not mentioned here.</p>
<p>So, if you need more plan-speaking from an ISO consultant, <a href="https://isoconsultants.co.uk/contact/">please be in touch!</a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_6 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_13    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_6 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-7" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-7" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/an-iso-consultant-reveals-ten-myths-and-legends-of-iso-certification/">An ISO Consultant Reveals Ten Myths and Legends of ISO Certification</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/an-iso-consultant-reveals-ten-myths-and-legends-of-iso-certification/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ISO 9001 &#8211; How to Make it Work</title>
		<link>https://isoconsultants.co.uk/iso-9001-how-to-make-it-work/</link>
					<comments>https://isoconsultants.co.uk/iso-9001-how-to-make-it-work/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Wed, 27 Mar 2013 14:40:52 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[ISO 9001]]></category>
		<category><![CDATA[The Diary of an ISO Consultant]]></category>
		<category><![CDATA[Cost effective]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[EN ISO 9001]]></category>
		<category><![CDATA[Get ISO9001 Fast]]></category>
		<category><![CDATA[ISO 9001 failure]]></category>
		<category><![CDATA[ISO 9001 Quality]]></category>
		<category><![CDATA[ISO 9001 Requirements]]></category>
		<category><![CDATA[ISO 9001 worth it]]></category>
		<category><![CDATA[ISO audit preparation]]></category>
		<category><![CDATA[ISO Certification]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[Requirements]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=1998</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/iso-9001-how-to-make-it-work/">ISO 9001 &#8211; How to Make it Work</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_7 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_14   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_7">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_7 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">I received a call from a prospective customer. who explained that he’d bought a business which held an ISO 9001 certificate from a reputable certification body.</p>
<p>However, he&#8217;d identified that discipline within the business wasn’t good, and that most of the staff were unaware of their operating processes. But although business had a “sloppy” feel, the product range had potential and sales were reasonable.</p>
<p>He had a discussion with the company’s Quality Manager, who tried to quell his fears, proudly producing a set of internal audits. So everything seemed fine. The certification body visited the next week, audited through the business, gave it an all clear and left. So all was well. Or was it?<span id="more-1998"></span></p>
<p>“But I know the system doesn’t work and the staff don’t know what’s in their operating procedures so can’t be following them ! ” he said to me.</p>
<p>Yes indeed. I often ponder why don’t other people ask this. How do we make ISO9001 truly work?</p>
<p>ISO 9001 provides tools that ensure consistent products and services are provided to a set cost and standard. It offers a process for managing longer term business improvement, helps to change cultures and can instil disciplines and consistent processes. However, many ISO certified companies see their newly-acquired standard as an end, not a beginning. Having the tools does not get the job done. Only using them does.</p>
<p>So back to my prospective customer and his “approved” company with little sign of “Quality”. He&#8217;d probably just managed to escape having the ISO 9001 certificate removed by the certification body if things were really as bad as he suggested. But if the system wasn&#8217;t delivering because the tools had stayed in the box.</p>
<p>There is overwhelming evidence that the processes which ISO 9001 encourages WILL deliver business improvement, so if they aren&#8217;t doing it in your business then it must be something to do with the way you are using them – a saw is always a saw, it will always cut, though if you leave it hanging on your shed wall, it might as well be a blunt pen knife.</p>
<p>An ISO 9001 management system WILL, for example, provide a certificate which should get you through many high-value tender adjudications. Beyond that, it will also provide a framework for continual improvement, encourage the establishment of business measures and metrics, formalise internal processes and procedures and drive consistency in their output. But you need to see the system and the principles behind it as more than a certificate that means you can tender.</p>
<p>So what happened to my gentleman? I explained how the system worked and suggested he start by aligning the Quality Policy and its objectives with his Business Plan. It’s then up to him whether he uses the tools he has or keeps the box firmly shut.</p>
<p>I hope he uses them, we need more British businesses which are strong, innovative and improvement based.</p>
<p>&nbsp;</p>
<p style="text-align: center;">Written by <a title="Colin Brown" href="https://plus.google.com/u/1/109135308302240162318?rel=author " target="_blank" rel="noopener">Colin Brown</a> of ISO Consultants</p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_7 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_15    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_7 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-8" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-8" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/iso-9001-how-to-make-it-work/">ISO 9001 &#8211; How to Make it Work</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/iso-9001-how-to-make-it-work/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>BYOD Policy, Security Threats, and Eight Ways That ISO 27001 Security Certification Can Help</title>
		<link>https://isoconsultants.co.uk/byod-policy-security-threats-eight-ways-iso-27001-security-certification-can-help/</link>
					<comments>https://isoconsultants.co.uk/byod-policy-security-threats-eight-ways-iso-27001-security-certification-can-help/#respond</comments>
		
		<dc:creator><![CDATA[PsyphaDeejay]]></dc:creator>
		<pubDate>Mon, 26 Nov 2012 12:03:02 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[Birmingham]]></category>
		<category><![CDATA[BYOD Dangers]]></category>
		<category><![CDATA[BYOD Policy]]></category>
		<category><![CDATA[BYOD Threats]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Derby]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[East Midlands]]></category>
		<category><![CDATA[ISO 27001 security]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[ISO9001 Quality]]></category>
		<category><![CDATA[Leicester]]></category>
		<category><![CDATA[Nottingham]]></category>
		<category><![CDATA[Quality Management System]]></category>
		<category><![CDATA[Requirements]]></category>
		<category><![CDATA[security audit]]></category>
		<category><![CDATA[What is ISO27001]]></category>
		<guid isPermaLink="false">http://iais.wpengine.com/?p=1889</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/byod-policy-security-threats-eight-ways-iso-27001-security-certification-can-help/">BYOD Policy, Security Threats, and Eight Ways That ISO 27001 Security Certification Can Help</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_8 et_pb_with_background et_section_specialty" >
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_16   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_8">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_8 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>The whole Bring Your Own Device <a href="http://www.zdnet.com/topic-byod-and-the-consumerization-of-it/" target="_blank" rel="noopener">(BYOD) </a>trend seems to be “the perfect storm”, but perfectly addressable through the security issues <a href="http://en.wikipedia.org/wiki/ISO/IEC_27001:2005" target="_blank" rel="noopener">ISO 27001</a> addresses.</p>
<p>However, a quick Google reveals some interesting and disturbing statistics.</p>
<p>75% of IT directors see BYOD as their major threat.</p>
<p>60% (or more) of all employees are using their own devices at work.</p>
<p>33% see absolutely no problem with doing this in respect of security risks.</p>
<p>Occasionally I wake up in the morning and thank God that I&#8217;m not a head of IT. The implications of a breach of security in terms of damage to corporate image, customer relations, and ultimately revenue don&#8217;t bear consideration. Or do they?<span id="more-1889"></span></p>
<p>Now, I&#8217;m in the quality standards business, so you may be slightly ahead of me here in thinking that I&#8217;m matching this threat with something I offer as a service, and this piece is simply a long advertisement. Well, actually, you&#8217;d be quite right. Implementation of the <a href="https://isoconsultants.co.uk/standards/iso-27001/">ISO 27001</a> security standard can be a significant weapon against the very real threat.</p>
<p>Some Suggestions:-</p>
<p><strong>1/</strong> Face The Problem. It&#8217;s going to happen anyway, driven by the device market. I&#8217;m regularly amazed that many corporates believe that BYOD is a social media-driven fad. The whole business of implementing standards, including ISO 27001 is based around application of agreed standards of honesty and (occasionally painful) reality.</p>
<p><strong>2/</strong> Face The Opportunity. A lot less PCs to buy, software upgrades to tackle, and productivity benefits of mobile working across the enterprise. And the chance to spring-clean your IT security policies at the same time.</p>
<p><strong>3/</strong> Have a Strategy. It&#8217;s not hard, but it is necessary. BYOD needs fair policing across the business, otherwise inequalities develop and cyber-anrchy may follow. Remarkably, many do not have a plan. See below.</p>
<p><strong>4/</strong>Have a Overall IT Strategy. If you&#8217;re sorting this particular challenge out, you might as well set policies, standards and procedures across the whole of your IT activity.</p>
<p><strong>5/</strong> Have a Holistic Vision of The IT Function. ISO 27001 security isn&#8217;t actually about IT, but systematic management, which embraces many functions and areas of responsibility. Specifically for BYOD, there are (or need to be) HR, security and legal implications, which will have organisation-wide implications.</p>
<p><strong>6/</strong> Make Policies and Procedures Simple. Less fuss and hassle means buy-in from employees is more likely. A well-written and researched overall ISO 27001 security policy should serve the business, not the other way around. Willing cooperation and adoption comes easily when the rules are easy and everyone knows them. Nothing breeds non-compliance faster than complexity.</p>
<p><strong>7/</strong> Review and Amend. The ISO 27001 security standard should include a process to monitor, evaluate and alter, otherwise it becomes static and irrelevant. It&#8217;s a start, not an end. The IT function is likely to be the most dynamic in the company, and hence a regular audit should be made part of the overall procedure. Reviews should seek to simplify rather than supplement and complicate.</p>
<p><strong>8/</strong> It&#8217;s Not Just a Security Issue. As the BYOD ”challenge” becomes more of a major issue, potential customers are likely to expect it before they release their commercially-sensitive data to you. There are key commercial benefits of holding ISO 27001.</p>
<p>So, it&#8217;s not difficult to be ready for the issues that are rapidly emerging, neither is it expensive. And it may just benefit many other areas of your business&#8230;.</p>
<p>&nbsp;</p>
<p>Written by <a title="Colin Brown" href="https://plus.google.com/u/1/109135308302240162318?rel=author" target="_blank" rel="noopener noreferrer">Colin Brown</a> of ISO Consultants</p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_8 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_17    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_8 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div id="block-2" class="et_pb_widget widget_block widget_search"><form role="search" method="get" action="https://isoconsultants.co.uk/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-9" >Search</label><div class="wp-block-search__inside-wrapper" ><input class="wp-block-search__input" id="wp-block-search__input-9" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></div><div id="block-3" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts is-layout-flow wp-block-latest-posts-is-layout-flow"><li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/common-pitfalls-in-iso-27001-implementation/">Common Pitfalls in ISO 27001 Implementation</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/iso14001-in-construction-and-architecture-industries/">ISO14001 in Construction and Architecture Industries</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/what-is-iso-17020-and-does-it-apply-to-your-sme/">What is ISO 17020 and does it apply to your SME?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/point-of-keeping-iso-certificate/">What&#8217;s the point of keeping an ISO Certificate?</a></li>
<li><a class="wp-block-latest-posts__post-title" href="https://isoconsultants.co.uk/risk-management-across-different-iso-standards/">Risk Management Across Different ISO Standards</a></li>
</ul></div></div><div id="block-4" class="et_pb_widget widget_block"><div class="wp-block-group is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><ol class="wp-block-latest-comments"><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a href="http://eccinternational.com/consulting/standards-and-compliance/" class="blc-broken-link" data-blc-broken="1">Raviarjun</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/insiders-view-iso-27001-certification/#comment-4">An Insider&#8217;s View of ISO 27001 Certification</a></footer></article></li><li class="wp-block-latest-comments__comment"><article><footer class="wp-block-latest-comments__comment-meta"><a class="wp-block-latest-comments__comment-author" href="http://www.iascertification.com/iso-27001-certification.html" target="_blank" rel="noopener">Iso 27001 Certification</a> on <a class="wp-block-latest-comments__comment-link" href="https://isoconsultants.co.uk/cost-effective-iso-27001-certification-and-why-most-companies-pay-too-much-2/#comment-2">Cost Effective ISO 27001 Certification and Why Most Companies Pay Too Much&#8230;</a></footer></article></li></ol></div></div>
			</div>
			</div>
				</div>
				
			</div></p>
<p>The post <a rel="nofollow" href="https://isoconsultants.co.uk/byod-policy-security-threats-eight-ways-iso-27001-security-certification-can-help/">BYOD Policy, Security Threats, and Eight Ways That ISO 27001 Security Certification Can Help</a> appeared first on <a rel="nofollow" href="https://isoconsultants.co.uk">UK ISO Consultants</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://isoconsultants.co.uk/byod-policy-security-threats-eight-ways-iso-27001-security-certification-can-help/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
