SlideShare a Scribd company logo
1 of 19
PECB
Conference
Added value of an integrated
management system
By René St-Germain
PECB Europe
2
PECB Conference
1. Reality of the market
2. What is an integrated management system
3. New challenges
4. IMS and ISO standards
5. IMS and industry standards
6. IMS and regulations
7. Presentation of 5 business cases
3
Introduction
 Many organizations have adopted or are adopting formal
management system standards specifications such as ISO
9001, ISO 14001, ISO/IEC 27001, ISO 22000, ISO/IEC 20000
and OHSAS 18001 (ISO 45001) and also industry and/or legal
framework
 Frequently these are operated as independent systems
 In all management systems, however, there are certain
common elements which can be managed in an integrated way
 The essential unity of all these systems within the overall
management system of the organization can then be
recognized and used to best advantage
The reality of the market
4
If an organization decides to operate more than one
management system, it can can managed in one system as
an integrated management system
Integrated Management System
ISO 20000
ISO 27001ISO 9001
ISO 14001
Integrated
management system
5
New challedges for a Management
System
Quality
Contracts and
SLA
(Clients)
Standards
(Industry)
Laws and
regulations
(Authorities)
ResilienceSecurity
Compliance
6
Actual Management System Standards
Primary standards against which an organization can be
certified
ISO 9001
Quality
ISO 14001
Environment
ISO 45001
Health and Safety
at work
ISO 20000
IT Service
ISO 22000
Food Safety
ISO 22301
Business
continuity
ISO 27001
Information
security
ISO 28000
Supply Chain
Security
7
Integrated Management System
Old versions of ISO standards
Requirements
ISO
9001:2008
ISO
14001:2004
ISO
20000:2011
ISO
27001:2005
Objectives of the
management system
5.4.1 4.3.3 4.5.2 4.2.1
Policy of the
management system
5.3 4. 2 4.1.2 4.2.1
Management
commitment
5.1 4.4.1 4.1 5
Documentation
requirements
4.2 4.4 4.3 4.3
Internal audit 8.2.2 4.5.5 4.5.4.2 5
Continual improvement 8.5.1 4.5.3 4.5.5 8
Management review 5.6 4.6 4.5.4.3 7
8
Integrated Management System
Common structure of new ISO standards
Requirements
ISO
9001:2015
ISO
14001:2015
ISO
22301:2012
ISO
27001:2013
Objectives of the
management system
6.2 6.2 6.2 6.2
Policy of the
management system
5.2 5.2 5.2 5.2
Management
commitment
5.1 5.1 5.1 5.1
Documentation
requirements
7.5 7.5 7.5 7.5
Internal audit 9.2 9.2 9.2 9.2
Continual improvement 10 10 10 10
Management review 9.3 9.3 9.3 9.3
9
New Insdustry Standards
Increase of standards that companies need to follow
CTPAC
Cloud
Essential
SSAE-16
(Replacement of
SAS 70)
NERC
Tier IV
NIST
PCI-DSS
WLA-SCS
IT Baseline
OECD
Principles
10
Legal Aspects
Major topics to be monitored
1 Data protection
2 Privacy
3 Computer Crimes
4 Digital Signature
5 Intellectual Property
6 Electronic Payments
7 Records Management and electronic archiving
11
Compliance needs that we
need to ensure that
suppliers comply to
Compliance needs from
contracts and SLAs with
clients
Complexity of Contracts and SLA
Management
Second Party Audit
SSAE-16
(Replacement of
SAS 70)
Customer Supplier
Organization
12
Business sectors
Where integrated management system are important
Banks and
insurence
Aerospace and
Defense
Public sector
Healthcare UtilitiesGambling E-commerce
Telecom
13
An add-value?
1. Facilitating better decision making
2. Identifying risk areas
3. Helping to develop objectives and plans that are consistent with
business needs
4. Allowing better planning and allocation of available resources
5. Promoting harmonised methods and processes for the overall
'business management' system
6. Reducing the amount of documentation
7. Raising awareness of, and promoting the interaction and
interrelation of the IMS
8. Facilitating the development of coordinated solutions to problems
identified
9. Saving up to 30% of audit days
Integrated Management System
14
Business case 1
1. EN 9100 (Aerospace Quality Management System)
2. ISO 14001 (Environmental Management System)
3. ISO 27001 (Information Security Management System)
4. ISO 45001 (Occupational health and Safety
Management System)
5. CSPN (Certification de Sécurité de Premier Niveau)
6. DO-254 (Electronic embedded systems)
7. DO-178 series (Airborne Systems and Equipment
Certification)
8. Airbus contract and SLA
Aerospace Supplier for Electronic
Components
15
Medical research center
Business case 2
1. ISO 13485 (Medical Devices Management System)
2. ISO 20000 (Système de management des services)
3. ISO 27001 (Information Security Management System)
4. HADS (HealthCare data Management)
5. GDPR compliance
6. FDA rules and regulations
16
Datacenter
Business case 3
1. ISO 9001 (Quality Management System)
2. ISO 14001 (Environmental Management System)
3. ISO 20000 (Système de management des services)
4. ISO 22301 (Business Continuity Management System)
5. ISO 27001 (Information Security Management System)
6. ISO 45001 (Occupational health and Safety
Management System)
7. ISO 50001 (Energy Management System)
8. Cloud certification
9. GDPR compliance
10.Tier IV certification (infrastructure)
17
Electronic archiving
Business case 4
1. ISO 9001 (Quality Management System)
2. ISO 14001 (Environmental Management System)
3. ISO 27001 (Information Security Management System)
4. PSDC-D (Electronic Archiving – Demateralization)
5. PSDC-C (Electronic Archiving – Conservation)
6. GDPR compliance
18
National Lottery
Business case 5
1. ISO 9001 (Quality Management System)
2. ISO 27001 (Information Security Management System)
3. PCI-DSS (Credit card Payment)
4. WLA-SCS (Security Control Standard)
5. WLA-SG (Responsible Gaming)
19
QUESTIONS?
René St-Germain
PECB Europe
Email : rene.stgermain@pecb.eu
Tel: +352 (0) 20 30 10 44
Tel: +33 (0)1 86 86 00 53

More Related Content

What's hot

TUV Southwest Training Programs
TUV Southwest Training ProgramsTUV Southwest Training Programs
TUV Southwest Training ProgramsTUV Southwest
 
Lean Six Sigma Leadership 062507
Lean Six Sigma Leadership 062507Lean Six Sigma Leadership 062507
Lean Six Sigma Leadership 062507larrypenni
 
ISO 45001 Standard
ISO 45001 StandardISO 45001 Standard
ISO 45001 StandardIBEX SYSTEMS
 
How is ISO 45001 Related to 9001?
How is ISO 45001 Related to 9001?How is ISO 45001 Related to 9001?
How is ISO 45001 Related to 9001?PECB
 
ISO 45001 Key Implementation Steps
ISO 45001 Key Implementation StepsISO 45001 Key Implementation Steps
ISO 45001 Key Implementation StepsPECB
 
13 benefits of adopting ISO 14001
13 benefits of adopting ISO 1400113 benefits of adopting ISO 14001
13 benefits of adopting ISO 14001Genesys Training
 
Integrated Management Systems (IMS)
Integrated Management Systems (IMS)Integrated Management Systems (IMS)
Integrated Management Systems (IMS)Andre Marques Valio
 
NQA - ISO 45001 Implementation Guide
NQA - ISO 45001 Implementation GuideNQA - ISO 45001 Implementation Guide
NQA - ISO 45001 Implementation GuideNA Putra
 
Readymade ISO 45001:2018 Documentation Kit
Readymade ISO 45001:2018 Documentation KitReadymade ISO 45001:2018 Documentation Kit
Readymade ISO 45001:2018 Documentation KitGlobal Manager Group
 
Basic of Integrated Management System
Basic of Integrated Management SystemBasic of Integrated Management System
Basic of Integrated Management Systemjamaluddin ma'ruf
 
How to Implement ISO 45001
How to Implement ISO 45001 How to Implement ISO 45001
How to Implement ISO 45001 Craig Thornton
 
Changes to ISO9001/ISO14001
Changes to ISO9001/ISO14001Changes to ISO9001/ISO14001
Changes to ISO9001/ISO14001Sara Gulo
 
Concepts of ISO 9001 and ISO 14001
Concepts of ISO 9001 and ISO 14001Concepts of ISO 9001 and ISO 14001
Concepts of ISO 9001 and ISO 14001Akhil Garg
 
ISO 9001, 14001, 45001 (IMS) basics training material
ISO 9001, 14001, 45001 (IMS) basics training materialISO 9001, 14001, 45001 (IMS) basics training material
ISO 9001, 14001, 45001 (IMS) basics training materialRanganathanR9
 
AS9100D Awareness & Auditor Training - PPT Presentation
AS9100D Awareness & Auditor Training - PPT PresentationAS9100D Awareness & Auditor Training - PPT Presentation
AS9100D Awareness & Auditor Training - PPT PresentationDocumentation Consultancy
 
Best Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation ProjectBest Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation ProjectSAPinsider Events
 
IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001
IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001
IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001Global Manager Group
 

What's hot (20)

TUV Southwest Training Programs
TUV Southwest Training ProgramsTUV Southwest Training Programs
TUV Southwest Training Programs
 
Lean Six Sigma Leadership 062507
Lean Six Sigma Leadership 062507Lean Six Sigma Leadership 062507
Lean Six Sigma Leadership 062507
 
ISO 45001 Standard
ISO 45001 StandardISO 45001 Standard
ISO 45001 Standard
 
How is ISO 45001 Related to 9001?
How is ISO 45001 Related to 9001?How is ISO 45001 Related to 9001?
How is ISO 45001 Related to 9001?
 
[EN] Records Management: Definitions, Principles, Standards and Trends | DMS ...
[EN] Records Management: Definitions, Principles, Standards and Trends | DMS ...[EN] Records Management: Definitions, Principles, Standards and Trends | DMS ...
[EN] Records Management: Definitions, Principles, Standards and Trends | DMS ...
 
ISO 45001 Key Implementation Steps
ISO 45001 Key Implementation StepsISO 45001 Key Implementation Steps
ISO 45001 Key Implementation Steps
 
13 benefits of adopting ISO 14001
13 benefits of adopting ISO 1400113 benefits of adopting ISO 14001
13 benefits of adopting ISO 14001
 
Integrated Management Systems (IMS)
Integrated Management Systems (IMS)Integrated Management Systems (IMS)
Integrated Management Systems (IMS)
 
NQA - ISO 45001 Implementation Guide
NQA - ISO 45001 Implementation GuideNQA - ISO 45001 Implementation Guide
NQA - ISO 45001 Implementation Guide
 
Lean Management System
Lean Management SystemLean Management System
Lean Management System
 
Readymade ISO 45001:2018 Documentation Kit
Readymade ISO 45001:2018 Documentation KitReadymade ISO 45001:2018 Documentation Kit
Readymade ISO 45001:2018 Documentation Kit
 
Basic of Integrated Management System
Basic of Integrated Management SystemBasic of Integrated Management System
Basic of Integrated Management System
 
How to Implement ISO 45001
How to Implement ISO 45001 How to Implement ISO 45001
How to Implement ISO 45001
 
Changes to ISO9001/ISO14001
Changes to ISO9001/ISO14001Changes to ISO9001/ISO14001
Changes to ISO9001/ISO14001
 
Concepts of ISO 9001 and ISO 14001
Concepts of ISO 9001 and ISO 14001Concepts of ISO 9001 and ISO 14001
Concepts of ISO 9001 and ISO 14001
 
Iso 9001 2015
Iso 9001 2015 Iso 9001 2015
Iso 9001 2015
 
ISO 9001, 14001, 45001 (IMS) basics training material
ISO 9001, 14001, 45001 (IMS) basics training materialISO 9001, 14001, 45001 (IMS) basics training material
ISO 9001, 14001, 45001 (IMS) basics training material
 
AS9100D Awareness & Auditor Training - PPT Presentation
AS9100D Awareness & Auditor Training - PPT PresentationAS9100D Awareness & Auditor Training - PPT Presentation
AS9100D Awareness & Auditor Training - PPT Presentation
 
Best Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation ProjectBest Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation Project
 
IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001
IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001
IMS Documentation Requirements As per ISO 9001,ISO 14001 and ISO 45001
 

Similar to Added value of an integrated management system

Management systems integration - ims
Management systems integration - imsManagement systems integration - ims
Management systems integration - imsSikander Nawaz
 
Differences Between ISO 13485 and ISO 9001
Differences Between ISO 13485 and ISO 9001Differences Between ISO 13485 and ISO 9001
Differences Between ISO 13485 and ISO 9001riteshreddych
 
ISO 13485: Quality Management System for Medical Device
ISO 13485: Quality Management System for Medical DeviceISO 13485: Quality Management System for Medical Device
ISO 13485: Quality Management System for Medical DeviceMananShah147368
 
What are the Advantages of ISO 17025 certification in Oman? What are the Req...
What are the Advantages of ISO 17025 certification in Oman? What are  the Req...What are the Advantages of ISO 17025 certification in Oman? What are  the Req...
What are the Advantages of ISO 17025 certification in Oman? What are the Req...rakshithmv1
 
ISO 9001 implementation in IT Companies
ISO 9001 implementation in IT CompaniesISO 9001 implementation in IT Companies
ISO 9001 implementation in IT Companiesannoyket
 
Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...
Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...
Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...Innovation Agency
 
Integrated ISO 14001, ISO 45001 Certification Documents
Integrated ISO 14001, ISO 45001 Certification DocumentsIntegrated ISO 14001, ISO 45001 Certification Documents
Integrated ISO 14001, ISO 45001 Certification DocumentsGlobal Manager Group
 
NQA - ISO 13485 Transition Checklist
NQA - ISO 13485 Transition ChecklistNQA - ISO 13485 Transition Checklist
NQA - ISO 13485 Transition ChecklistNA Putra
 
tuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdftuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdfHalaGhaziAyoub
 
What is iso 9001 qms
What is iso 9001 qmsWhat is iso 9001 qms
What is iso 9001 qmsBusiness Beam
 
Compliance Framework
Compliance FrameworkCompliance Framework
Compliance Frameworkbarnetdh
 
How to Simplify Your Compliance to the New ISO 13485:2016
How to Simplify Your Compliance to the New ISO 13485:2016How to Simplify Your Compliance to the New ISO 13485:2016
How to Simplify Your Compliance to the New ISO 13485:2016Greenlight Guru
 

Similar to Added value of an integrated management system (20)

Management systems integration - ims
Management systems integration - imsManagement systems integration - ims
Management systems integration - ims
 
mm CGEIT Best Practices and Concepts
mm CGEIT Best Practices and Conceptsmm CGEIT Best Practices and Concepts
mm CGEIT Best Practices and Concepts
 
Differences Between ISO 13485 and ISO 9001
Differences Between ISO 13485 and ISO 9001Differences Between ISO 13485 and ISO 9001
Differences Between ISO 13485 and ISO 9001
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
ISO 13485: Quality Management System for Medical Device
ISO 13485: Quality Management System for Medical DeviceISO 13485: Quality Management System for Medical Device
ISO 13485: Quality Management System for Medical Device
 
What are the Advantages of ISO 17025 certification in Oman? What are the Req...
What are the Advantages of ISO 17025 certification in Oman? What are  the Req...What are the Advantages of ISO 17025 certification in Oman? What are  the Req...
What are the Advantages of ISO 17025 certification in Oman? What are the Req...
 
ISO 9001 implementation in IT Companies
ISO 9001 implementation in IT CompaniesISO 9001 implementation in IT Companies
ISO 9001 implementation in IT Companies
 
Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...
Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...
Richard Hall - Liverpool City Region SME workshop: Regulatory process and app...
 
Integrated ISO 14001, ISO 45001 Certification Documents
Integrated ISO 14001, ISO 45001 Certification DocumentsIntegrated ISO 14001, ISO 45001 Certification Documents
Integrated ISO 14001, ISO 45001 Certification Documents
 
NQA - ISO 13485 Transition Checklist
NQA - ISO 13485 Transition ChecklistNQA - ISO 13485 Transition Checklist
NQA - ISO 13485 Transition Checklist
 
Assignment
AssignmentAssignment
Assignment
 
ISO_SMB.pptx
ISO_SMB.pptxISO_SMB.pptx
ISO_SMB.pptx
 
tuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdftuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdf
 
What is iso 9001 qms
What is iso 9001 qmsWhat is iso 9001 qms
What is iso 9001 qms
 
Eurosec'2008 christophe feltus
Eurosec'2008 christophe feltusEurosec'2008 christophe feltus
Eurosec'2008 christophe feltus
 
ISO 9000
ISO 9000ISO 9000
ISO 9000
 
Preparing for ISO 45001 - The new WHS Systems Standard
Preparing for ISO 45001 - The new WHS Systems StandardPreparing for ISO 45001 - The new WHS Systems Standard
Preparing for ISO 45001 - The new WHS Systems Standard
 
Iso 9000 1 2015
Iso 9000 1 2015Iso 9000 1 2015
Iso 9000 1 2015
 
Compliance Framework
Compliance FrameworkCompliance Framework
Compliance Framework
 
How to Simplify Your Compliance to the New ISO 13485:2016
How to Simplify Your Compliance to the New ISO 13485:2016How to Simplify Your Compliance to the New ISO 13485:2016
How to Simplify Your Compliance to the New ISO 13485:2016
 

More from PECB

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemPECB
 

More from PECB (20)

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Recently uploaded

DATA STRUCTURE AND ALGORITHM for beginners
DATA STRUCTURE AND ALGORITHM for beginnersDATA STRUCTURE AND ALGORITHM for beginners
DATA STRUCTURE AND ALGORITHM for beginnersSabitha Banu
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxSayali Powar
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
AmericanHighSchoolsprezentacijaoskolama.
AmericanHighSchoolsprezentacijaoskolama.AmericanHighSchoolsprezentacijaoskolama.
AmericanHighSchoolsprezentacijaoskolama.arsicmarija21
 
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdfLike-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdfMr Bounab Samir
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTiammrhaywood
 
Full Stack Web Development Course for Beginners
Full Stack Web Development Course  for BeginnersFull Stack Web Development Course  for Beginners
Full Stack Web Development Course for BeginnersSabitha Banu
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatYousafMalik24
 
Hierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of managementHierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of managementmkooblal
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPCeline George
 
Final demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxFinal demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxAvyJaneVismanos
 
CELL CYCLE Division Science 8 quarter IV.pptx
CELL CYCLE Division Science 8 quarter IV.pptxCELL CYCLE Division Science 8 quarter IV.pptx
CELL CYCLE Division Science 8 quarter IV.pptxJiesonDelaCerna
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...JhezDiaz1
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaVirag Sontakke
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxthorishapillay1
 
Types of Journalistic Writing Grade 8.pptx
Types of Journalistic Writing Grade 8.pptxTypes of Journalistic Writing Grade 8.pptx
Types of Journalistic Writing Grade 8.pptxEyham Joco
 

Recently uploaded (20)

DATA STRUCTURE AND ALGORITHM for beginners
DATA STRUCTURE AND ALGORITHM for beginnersDATA STRUCTURE AND ALGORITHM for beginners
DATA STRUCTURE AND ALGORITHM for beginners
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
9953330565 Low Rate Call Girls In Rohini Delhi NCR
9953330565 Low Rate Call Girls In Rohini  Delhi NCR9953330565 Low Rate Call Girls In Rohini  Delhi NCR
9953330565 Low Rate Call Girls In Rohini Delhi NCR
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
AmericanHighSchoolsprezentacijaoskolama.
AmericanHighSchoolsprezentacijaoskolama.AmericanHighSchoolsprezentacijaoskolama.
AmericanHighSchoolsprezentacijaoskolama.
 
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdfLike-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
 
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
 
Full Stack Web Development Course for Beginners
Full Stack Web Development Course  for BeginnersFull Stack Web Development Course  for Beginners
Full Stack Web Development Course for Beginners
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice great
 
Hierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of managementHierarchy of management that covers different levels of management
Hierarchy of management that covers different levels of management
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERP
 
Final demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxFinal demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptx
 
CELL CYCLE Division Science 8 quarter IV.pptx
CELL CYCLE Division Science 8 quarter IV.pptxCELL CYCLE Division Science 8 quarter IV.pptx
CELL CYCLE Division Science 8 quarter IV.pptx
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of India
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptx
 
Types of Journalistic Writing Grade 8.pptx
Types of Journalistic Writing Grade 8.pptxTypes of Journalistic Writing Grade 8.pptx
Types of Journalistic Writing Grade 8.pptx
 

Added value of an integrated management system

  • 1. PECB Conference Added value of an integrated management system By René St-Germain PECB Europe
  • 2. 2 PECB Conference 1. Reality of the market 2. What is an integrated management system 3. New challenges 4. IMS and ISO standards 5. IMS and industry standards 6. IMS and regulations 7. Presentation of 5 business cases
  • 3. 3 Introduction  Many organizations have adopted or are adopting formal management system standards specifications such as ISO 9001, ISO 14001, ISO/IEC 27001, ISO 22000, ISO/IEC 20000 and OHSAS 18001 (ISO 45001) and also industry and/or legal framework  Frequently these are operated as independent systems  In all management systems, however, there are certain common elements which can be managed in an integrated way  The essential unity of all these systems within the overall management system of the organization can then be recognized and used to best advantage The reality of the market
  • 4. 4 If an organization decides to operate more than one management system, it can can managed in one system as an integrated management system Integrated Management System ISO 20000 ISO 27001ISO 9001 ISO 14001 Integrated management system
  • 5. 5 New challedges for a Management System Quality Contracts and SLA (Clients) Standards (Industry) Laws and regulations (Authorities) ResilienceSecurity Compliance
  • 6. 6 Actual Management System Standards Primary standards against which an organization can be certified ISO 9001 Quality ISO 14001 Environment ISO 45001 Health and Safety at work ISO 20000 IT Service ISO 22000 Food Safety ISO 22301 Business continuity ISO 27001 Information security ISO 28000 Supply Chain Security
  • 7. 7 Integrated Management System Old versions of ISO standards Requirements ISO 9001:2008 ISO 14001:2004 ISO 20000:2011 ISO 27001:2005 Objectives of the management system 5.4.1 4.3.3 4.5.2 4.2.1 Policy of the management system 5.3 4. 2 4.1.2 4.2.1 Management commitment 5.1 4.4.1 4.1 5 Documentation requirements 4.2 4.4 4.3 4.3 Internal audit 8.2.2 4.5.5 4.5.4.2 5 Continual improvement 8.5.1 4.5.3 4.5.5 8 Management review 5.6 4.6 4.5.4.3 7
  • 8. 8 Integrated Management System Common structure of new ISO standards Requirements ISO 9001:2015 ISO 14001:2015 ISO 22301:2012 ISO 27001:2013 Objectives of the management system 6.2 6.2 6.2 6.2 Policy of the management system 5.2 5.2 5.2 5.2 Management commitment 5.1 5.1 5.1 5.1 Documentation requirements 7.5 7.5 7.5 7.5 Internal audit 9.2 9.2 9.2 9.2 Continual improvement 10 10 10 10 Management review 9.3 9.3 9.3 9.3
  • 9. 9 New Insdustry Standards Increase of standards that companies need to follow CTPAC Cloud Essential SSAE-16 (Replacement of SAS 70) NERC Tier IV NIST PCI-DSS WLA-SCS IT Baseline OECD Principles
  • 10. 10 Legal Aspects Major topics to be monitored 1 Data protection 2 Privacy 3 Computer Crimes 4 Digital Signature 5 Intellectual Property 6 Electronic Payments 7 Records Management and electronic archiving
  • 11. 11 Compliance needs that we need to ensure that suppliers comply to Compliance needs from contracts and SLAs with clients Complexity of Contracts and SLA Management Second Party Audit SSAE-16 (Replacement of SAS 70) Customer Supplier Organization
  • 12. 12 Business sectors Where integrated management system are important Banks and insurence Aerospace and Defense Public sector Healthcare UtilitiesGambling E-commerce Telecom
  • 13. 13 An add-value? 1. Facilitating better decision making 2. Identifying risk areas 3. Helping to develop objectives and plans that are consistent with business needs 4. Allowing better planning and allocation of available resources 5. Promoting harmonised methods and processes for the overall 'business management' system 6. Reducing the amount of documentation 7. Raising awareness of, and promoting the interaction and interrelation of the IMS 8. Facilitating the development of coordinated solutions to problems identified 9. Saving up to 30% of audit days Integrated Management System
  • 14. 14 Business case 1 1. EN 9100 (Aerospace Quality Management System) 2. ISO 14001 (Environmental Management System) 3. ISO 27001 (Information Security Management System) 4. ISO 45001 (Occupational health and Safety Management System) 5. CSPN (Certification de Sécurité de Premier Niveau) 6. DO-254 (Electronic embedded systems) 7. DO-178 series (Airborne Systems and Equipment Certification) 8. Airbus contract and SLA Aerospace Supplier for Electronic Components
  • 15. 15 Medical research center Business case 2 1. ISO 13485 (Medical Devices Management System) 2. ISO 20000 (Système de management des services) 3. ISO 27001 (Information Security Management System) 4. HADS (HealthCare data Management) 5. GDPR compliance 6. FDA rules and regulations
  • 16. 16 Datacenter Business case 3 1. ISO 9001 (Quality Management System) 2. ISO 14001 (Environmental Management System) 3. ISO 20000 (Système de management des services) 4. ISO 22301 (Business Continuity Management System) 5. ISO 27001 (Information Security Management System) 6. ISO 45001 (Occupational health and Safety Management System) 7. ISO 50001 (Energy Management System) 8. Cloud certification 9. GDPR compliance 10.Tier IV certification (infrastructure)
  • 17. 17 Electronic archiving Business case 4 1. ISO 9001 (Quality Management System) 2. ISO 14001 (Environmental Management System) 3. ISO 27001 (Information Security Management System) 4. PSDC-D (Electronic Archiving – Demateralization) 5. PSDC-C (Electronic Archiving – Conservation) 6. GDPR compliance
  • 18. 18 National Lottery Business case 5 1. ISO 9001 (Quality Management System) 2. ISO 27001 (Information Security Management System) 3. PCI-DSS (Credit card Payment) 4. WLA-SCS (Security Control Standard) 5. WLA-SG (Responsible Gaming)
  • 19. 19 QUESTIONS? René St-Germain PECB Europe Email : rene.stgermain@pecb.eu Tel: +352 (0) 20 30 10 44 Tel: +33 (0)1 86 86 00 53