SlideShare a Scribd company logo
1 of 33
Introduction to ISO27k Standards
www.cmu.edu/rwanda
1
ISMS implementation andISMS implementation and
certification process overviewcertification process overview
TopicsTopics
• Brief intro to ISO
• General understanding for ISO certification
• Elements of an ISO Management System
• What’s the new Annex SL?
• Benefits of an ISO Management System
Source: Radian Management
Brief IntroductionBrief Introduction
The BeginningThe Beginning
Twenty-five years ago, Nobel laureate
Robert Solow remarked, “You can see the
computer age everywhere but in the
productivity statistics.” That skepticism is
gone, as ICT increasingly fuels innovation,
efficiency and economic growth. This
applies in the ICT-producing and ICT-using
sectors – in other words, the whole
interconnected world.
• 
Who is IOS and What Is ISO?Who is IOS and What Is ISO?
• The International Organization for
Standardization (IOS) is a worldwide
federation of national standards bodies.
• Working through Technical Committees, it
has developed and published over 18,000
different ISO standards that are used
internationally for subjects ranging from
film speeds to wine glasses to quality
management systems.
• The official purpose for the issuance of ISO
Standards is to facilitate world trade
through standardization.
Management
Systems
ISO 20000-1:2011
Service Management
ISO 22301
Business Continuity
Management
ISO 27001-2005
Information
Security
Management
System
ISO 9001:
2008
Quality
Management
System
ISO 31000 Risk
Management
ISO/IEC-JTCISO/IEC-JTC
• ISO and the International Electrotechnical
Commission (IEC)’s joint technical
committee ISO/IEC JTC 1, Information
Technology has kept pace with the
industry’s staggering dynamism and
development, introduced numerous
standards, and identified many focus areas
for future work.
• Information Security and Cyber Security
have been in the forefront of the work
conducted resulting in the development of
many important frameworks, practices, and
standards.
ISO/IEC-JTCISO/IEC-JTC
Understanding theUnderstanding the
Standards - DocumentsStandards - Documents
Most standards have at least two supporting
documents;
•Requirements – these are the “Shalls” and
are required to be implemented unless
exclusions can be taken. The auditor can only
audit against the “Shalls”.
•Code of Practice – these are the “Shoulds”
and are guidance to assist you in
implementation.
•Guidance – a fully implementable standard
that does not have a “certification scheme”.
You can be compliant, but not certified.
Understanding the StandardsUnderstanding the Standards
- PDCA- PDCA
Do
Plan
Check
Act
Understanding the StandardsUnderstanding the Standards
- Scope- Scope
• Determine your Scope of Registration
• How many people within your organization
support this Management System?
• How many processes are included?
• How many locations?
Requirements for CertificationRequirements for Certification
Stages for RegistrationStages for Registration
• Submit application to registrar
• Stage 1: Assessment of readiness
• Stage 2: Assessment for registration
audit
• Registration/certification awarded for 3
years
• Surveillance audits (at least annually)
• Recertification audit at the end of 3rd
year
RegistrationRegistration
• Usually takes 1 or possibly 2 auditors 1 to
3 days
o depending on scope, size, locations and
personnel
• You will be told whether or not you will be
recommended for registration at the
completion of the Stage 2 audit
• Certificate usually arrives a 2 – 6 weeks
later
• Maintaining your ISO Certification(s) is the
first step in continuous improvement
Registrar/Auditor SelectionRegistrar/Auditor Selection
CriteriaCriteria
• Accreditation and scope of accreditation
• Reputation and customer acceptance
• Availability, cost, and location
• Knowledge of your business
• Culture fit with your organization
• Ability to audit all of your future standards
Note: The external auditor is hired by the Registrar
and presented with qualifications to you upon
agreement of audits. You cannot go out and hire
your own external auditor.
Getting Ready for the AuditGetting Ready for the Audit
• Determine team, set budget
• Internal auditor(s) training if using in-house
resources
• Hire consulting firm if applicable
• Gap Assessment
• Implement requirements of standard to meet your
business needs against the gap assessment
• Go-Live
• Hold Management Review Meeting
• Conduct Internal Audit
• Refine documentation
• Employee involvement training
• System adjustment
• Registration audit – Stage 1
• System adjustment
• Registration audit – Stage 2
Ongoing CommitmentOngoing Commitment
• Getting certification is only the beginning
• Management Representative must keep up
weekly/monthly/quarterly with tasks
• Internal audits are required at least
annually
• Management review is required at least
annually
• Timely completion and updates to internal
documents
• Annual Surveillance audit by external
registrar
An ISOAn ISO
Management SystemManagement System
Elements of a Management SystemElements of a Management System
• Management Commitment
Top management shall……………….
Participation in Management Reviews
Provide input for continuous improvement
Accountable for resource management
• Resource Management
Identification of resources including
human, technical, information and
financial
Identification of roles, accountability and
responsibility (RACI)
Competence, awareness & training
Elements of a Management SystemElements of a Management System
• Management Reviews
Required inputs including reviews of audits,
customer feedback, performance
measurements, improvements, changes
Required outputs including actions recorded for
improvements, documented improvements and
the effectiveness of those improvements,
additional follow-through of actions identified
such as resource needs or completion of
changes identified
• Document & Records Control
Documented procedure for creating,
approving, maintaining, protecting archiving
and destroying documents & records
Identifying documents of external origin
Elements of a Management SystemElements of a Management System
• Internal Audit
 Document an audit plan
 Identify internal auditors, hire or train
 Document outputs and act upon findings
 Timely reporting
• Continual Improvement
 Organization shall continually improve the effectiveness of the
management system through the use of the policy, objectives,
audit results, analysis of data, corrective and preventive
actions and management review
 Corrective/Preventive Actions recorded, planned and updated
timely
 Good Root Cause methodology
 Review of effectiveness of actions taken
ISO 20000, 27001, 9001ISO 20000, 27001, 9001
ISO 20000 ISO 27001 ISO 9001
4.0 SMS General
Requirements
4.0 ISMS
5.0 Management Responsibility 4.1 General requirements
4.1.1 Management
Commitment
5.1 Management Commitment
5.0 Management Commitment
4.3.2 Control of
Documents
4.3.2 Control of Documents 4.2.3 Control of Documents
4.3.3 Control of Records 4.3.3. Control of Records 4.2.4 Control of Records
4.4.1 Provision of
Resources
4.4.2 Human Resources
5.2.1 Provision of Resources
5.2.2 Training, Awareness &
Competence
6.0 Resource Management
4.5.4.2 Internal Audit 6 Internal ISMS audits 8.1.2 Internal audit
4.5.4.3 Management
Review
7 Management Review 5.6 Management Review
4.5.5 Maintain and
improve the SMS
8 ISMS improvement 8.4 Continual improvement
A New StructureA New Structure
• Starting with ISO 22301, the Annex SL (see
reference below) concept was introduced
to standardize the management system
requirements for ALL management system
standards. The next series of standards that
were published with the Annex SL is ISO
27001 in 2014 and the next major re-write is
the much anticipated 2015 release of ISO
9001.
http://www.iso.org/iso/home/news_index/news_archive/news.htm
 
Examples from the new AnnexExamples from the new Annex
SLSL
Introduction
1. Scope
2. Normative references
3. Terms and definitions
4. Context of the organization
5. Leadership
6. Planning
7. Support
8. Operation
9. Performance evaluation
10. Improvement
Examples from the new Annex SLExamples from the new Annex SL
Example of identical definitions : 
•Organization, interested party, policy, objective,
competence, conformity.
Example of identical text : 
•Top management shall ensure that the
responsibilities and authorities for relevant roles
are assigned and communicated within the
organization.
•The 27001 standard has been harmonized under
the new Annex SL
Benefits of ISOBenefits of ISO
Benefits of the Management SystemBenefits of the Management System
• There are obvious internal benefits
 Competitive Advantage
 Commitment to detail for the scope; i.e.: quality, security,
services, etc.
 Better employee engagement through training,
communication and accountability
 Formalized & repeatable processes
 Accountability at all levels
 Ongoing internal and external audits ensure weaknesses are
identified and improvements are completed
 Better governance and management of suppliers and
outsourced processes
 More efficient ability to change
 Reduction in duplicate effort
Reducing RiskReducing Risk
• 85% of information security (ISO 27001) clients
built stakeholder confidence
• 79% experienced faster recovery speeds from
incidents
• 83% of business continuity (ISO 25999) clients
reported enhanced reputation as the key benefit
• 64% of health & safety clients reduced incidents
while 49% made cost savings
• 99% of organizations meets their Information
Security objectives once they have implemented
ISO 27001
Source: BSI Excellerator Research 2011 and Erasmus University Study
Client InsightsClient Insights
Large Printing Company
•The biggest benefit we have seen over the course of
our ISO certification is a reduction in spoilage. Before
we were ISO certified, we averaged about 6.5%
spoilage per year. Last year our spoilage was 1.2%.
•Earnings for 2012 were 57 million so 1.2% was
approx. $684,000 versus 6.5% would be 3.7 million.
Pretty significant benefit.
•We have also benefitted from standardization of
processes and improved communication.
The East African SceneThe East African Scene
• The East African Information Security
Managers Forum (ISMF), aiming to involve
security practitioners across the region to share
experiences on information management,
• The ISMF has been set up to discuss these issues
at length and develop the necessary solutions and
systems that will help East Africa in attaining
maximum security in information delivery.
• Almerindo Graziano, chief executive officer (CEO)
at Silensec Kenya, said: “We have come up with a
new information security standard, the ISO 27001
that emphasizes on leadership and senior
management responsibilities in organisations.
• Salome Kanyugo, representing the Kenya
Revenue Authority (KRA), said: “The increased
automation in services has become a major
challenge for us and this has brought about the
need to secure our information so it is not easily
accessible to the wrong people.
• “To cover this challenge and others such as
internal threats and web cloning, we have
implemented various information security
standards and currently we are in the process of
implementing the new ISO 27001.”
• She said implementing the new standards will
ensure customers are able to trust their
information is secure with the organisation.
The East African SceneThe East African Scene
QuestionsQuestions

More Related Content

What's hot

Qms awareness training
Qms awareness trainingQms awareness training
Qms awareness trainingshree
 
ISO 9001:2015 Introduction & Awareness Training
ISO  9001:2015 Introduction & Awareness Training ISO  9001:2015 Introduction & Awareness Training
ISO 9001:2015 Introduction & Awareness Training Sadanand Borade
 
ISO in general
ISO in generalISO in general
ISO in generalKumuda J
 
Introduction To Iso22000
Introduction To Iso22000Introduction To Iso22000
Introduction To Iso22000Cynthia Weber
 
ISO Presentation
ISO PresentationISO Presentation
ISO Presentationkhalid shah
 
ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...
ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...
ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...Team Web Africa
 
Internal audit
Internal auditInternal audit
Internal auditHpm India
 
Iso9001 Orientation
Iso9001 OrientationIso9001 Orientation
Iso9001 OrientationImam Karim
 
What is iso 9001 qms
What is iso 9001 qmsWhat is iso 9001 qms
What is iso 9001 qmsBusiness Beam
 
ISO 9000 Quality Management System - A Presentation by Akshay Anand
ISO 9000 Quality Management System - A Presentation by Akshay AnandISO 9000 Quality Management System - A Presentation by Akshay Anand
ISO 9000 Quality Management System - A Presentation by Akshay AnandAkshay Anand
 
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMSISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMSSubhendu Datta
 
Quality management systems (QMS)
Quality management systems (QMS)Quality management systems (QMS)
Quality management systems (QMS)salman-fuu
 
Iso 9001 2015 documented information guidlines
Iso 9001 2015 documented information guidlinesIso 9001 2015 documented information guidlines
Iso 9001 2015 documented information guidlinesRajeesh Thumpayil
 

What's hot (20)

Qms awareness training
Qms awareness trainingQms awareness training
Qms awareness training
 
ISO 9001:2015 Introduction & Awareness Training
ISO  9001:2015 Introduction & Awareness Training ISO  9001:2015 Introduction & Awareness Training
ISO 9001:2015 Introduction & Awareness Training
 
ISO in general
ISO in generalISO in general
ISO in general
 
Introduction To Iso22000
Introduction To Iso22000Introduction To Iso22000
Introduction To Iso22000
 
Iso 9001 2015
Iso 9001 2015 Iso 9001 2015
Iso 9001 2015
 
ISO Presentation
ISO PresentationISO Presentation
ISO Presentation
 
ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...
ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...
ISO 22000 Clauses Requirements and Documentation training ISO 22000 RS 184 HA...
 
Internal audit
Internal auditInternal audit
Internal audit
 
Iso presentation
Iso presentationIso presentation
Iso presentation
 
Iso 22000
Iso 22000Iso 22000
Iso 22000
 
Iso9001 Orientation
Iso9001 OrientationIso9001 Orientation
Iso9001 Orientation
 
Iso 9001 2015 Understanding
Iso 9001 2015 Understanding Iso 9001 2015 Understanding
Iso 9001 2015 Understanding
 
What is iso 9001 qms
What is iso 9001 qmsWhat is iso 9001 qms
What is iso 9001 qms
 
ISO 9000 Quality Management System - A Presentation by Akshay Anand
ISO 9000 Quality Management System - A Presentation by Akshay AnandISO 9000 Quality Management System - A Presentation by Akshay Anand
ISO 9000 Quality Management System - A Presentation by Akshay Anand
 
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMSISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
ISO 9001: 2015 QUALITY MANAGEMENT SYSTEMS
 
Quality management systems (QMS)
Quality management systems (QMS)Quality management systems (QMS)
Quality management systems (QMS)
 
ISO 9001:2015
ISO 9001:2015ISO 9001:2015
ISO 9001:2015
 
Iso
IsoIso
Iso
 
Iso 9001 2015 documented information guidlines
Iso 9001 2015 documented information guidlinesIso 9001 2015 documented information guidlines
Iso 9001 2015 documented information guidlines
 
ISO9001:2015
ISO9001:2015ISO9001:2015
ISO9001:2015
 

Viewers also liked

Khachab-Top Management role to implement ISO 27001
Khachab-Top Management role to implement ISO 27001Khachab-Top Management role to implement ISO 27001
Khachab-Top Management role to implement ISO 27001Mohamad Khachab
 
Iso27001 The Road To Certification
Iso27001   The Road To CertificationIso27001   The Road To Certification
Iso27001 The Road To Certificationtschraider
 
Implementing ISO27001 2013
Implementing ISO27001 2013Implementing ISO27001 2013
Implementing ISO27001 2013scttmcvy
 
Information security management system (isms) overview
Information security management system (isms) overviewInformation security management system (isms) overview
Information security management system (isms) overviewJulia Urbina-Pineda
 
ISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_ListISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_ListSriramITISConsultant
 
ISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process OverviewISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process OverviewShankar Subramaniyan
 

Viewers also liked (7)

Isms v kumar
Isms v kumarIsms v kumar
Isms v kumar
 
Khachab-Top Management role to implement ISO 27001
Khachab-Top Management role to implement ISO 27001Khachab-Top Management role to implement ISO 27001
Khachab-Top Management role to implement ISO 27001
 
Iso27001 The Road To Certification
Iso27001   The Road To CertificationIso27001   The Road To Certification
Iso27001 The Road To Certification
 
Implementing ISO27001 2013
Implementing ISO27001 2013Implementing ISO27001 2013
Implementing ISO27001 2013
 
Information security management system (isms) overview
Information security management system (isms) overviewInformation security management system (isms) overview
Information security management system (isms) overview
 
ISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_ListISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_List
 
ISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process OverviewISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process Overview
 

Similar to Intro to ISO

ISO Auditing: What Is It and Why Should You Consider It?
ISO Auditing: What Is It and Why Should You Consider It?ISO Auditing: What Is It and Why Should You Consider It?
ISO Auditing: What Is It and Why Should You Consider It?Triumvirate Environmental
 
ISO 27001-Manage IT Risks and Build Customer Confidence
ISO 27001-Manage IT Risks and Build Customer ConfidenceISO 27001-Manage IT Risks and Build Customer Confidence
ISO 27001-Manage IT Risks and Build Customer ConfidenceAl Abbas, PMP, CISSP, MBA, MSc
 
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...Egyptian Engineers Association
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsNimonik
 
Get iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsGet iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsBen Pournader
 
Internal Process Audit
Internal Process AuditInternal Process Audit
Internal Process Auditintellisenseit
 
Auditing Information Security Management System Using ISO 27001 2013
Auditing Information Security Management System Using ISO 27001 2013Auditing Information Security Management System Using ISO 27001 2013
Auditing Information Security Management System Using ISO 27001 2013Andrea Porter
 
Iso 9001 internal audit tips
Iso 9001 internal audit tipsIso 9001 internal audit tips
Iso 9001 internal audit tipsBaptist Molai
 
ISO Implementation Roadmap- By Motaharul Islam
ISO Implementation Roadmap- By Motaharul IslamISO Implementation Roadmap- By Motaharul Islam
ISO Implementation Roadmap- By Motaharul IslamMotaharul Islam
 
ISO 9001 Quality Management Systems: Implementation and Integration
ISO 9001 Quality Management Systems: Implementation and IntegrationISO 9001 Quality Management Systems: Implementation and Integration
ISO 9001 Quality Management Systems: Implementation and IntegrationSpecialty Technical Publishers
 
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008Engr. Syed Noor Mustafa Shah
 
How to Perform a Successful Internal Quality Audit
How to Perform a Successful Internal Quality AuditHow to Perform a Successful Internal Quality Audit
How to Perform a Successful Internal Quality AuditGreenlight Guru
 
Seven essential steps to achieve an iso 45001 certification in zambia
Seven essential steps to achieve an iso 45001 certification in zambiaSeven essential steps to achieve an iso 45001 certification in zambia
Seven essential steps to achieve an iso 45001 certification in zambiaAnoosha Factocert
 
Internal-Audit-Methodology-VV.pdf
Internal-Audit-Methodology-VV.pdfInternal-Audit-Methodology-VV.pdf
Internal-Audit-Methodology-VV.pdfrobinverma31
 
Chapter 2-Lecture 4.pptx
Chapter 2-Lecture  4.pptxChapter 2-Lecture  4.pptx
Chapter 2-Lecture 4.pptxOsmanHassan35
 
Integrated Management System training,awareness,safety
Integrated Management System training,awareness,safetyIntegrated Management System training,awareness,safety
Integrated Management System training,awareness,safetyG Rajan Kumar
 

Similar to Intro to ISO (20)

ISO awarness
ISO awarnessISO awarness
ISO awarness
 
ISO Auditing: What Is It and Why Should You Consider It?
ISO Auditing: What Is It and Why Should You Consider It?ISO Auditing: What Is It and Why Should You Consider It?
ISO Auditing: What Is It and Why Should You Consider It?
 
CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016
 
ISO 27001-Manage IT Risks and Build Customer Confidence
ISO 27001-Manage IT Risks and Build Customer ConfidenceISO 27001-Manage IT Risks and Build Customer Confidence
ISO 27001-Manage IT Risks and Build Customer Confidence
 
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
 
Get iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsGet iso 27000 certification in 7 steps
Get iso 27000 certification in 7 steps
 
Internal Process Audit
Internal Process AuditInternal Process Audit
Internal Process Audit
 
Damco iso 27001
Damco iso   27001Damco iso   27001
Damco iso 27001
 
Auditing Information Security Management System Using ISO 27001 2013
Auditing Information Security Management System Using ISO 27001 2013Auditing Information Security Management System Using ISO 27001 2013
Auditing Information Security Management System Using ISO 27001 2013
 
Iso 9001 internal audit tips
Iso 9001 internal audit tipsIso 9001 internal audit tips
Iso 9001 internal audit tips
 
ISO Implementation Roadmap- By Motaharul Islam
ISO Implementation Roadmap- By Motaharul IslamISO Implementation Roadmap- By Motaharul Islam
ISO Implementation Roadmap- By Motaharul Islam
 
ISO 9001 Quality Management Systems: Implementation and Integration
ISO 9001 Quality Management Systems: Implementation and IntegrationISO 9001 Quality Management Systems: Implementation and Integration
ISO 9001 Quality Management Systems: Implementation and Integration
 
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
 
How to Perform a Successful Internal Quality Audit
How to Perform a Successful Internal Quality AuditHow to Perform a Successful Internal Quality Audit
How to Perform a Successful Internal Quality Audit
 
Internal audit day 1
Internal audit day 1Internal audit day 1
Internal audit day 1
 
Seven essential steps to achieve an iso 45001 certification in zambia
Seven essential steps to achieve an iso 45001 certification in zambiaSeven essential steps to achieve an iso 45001 certification in zambia
Seven essential steps to achieve an iso 45001 certification in zambia
 
Internal-Audit-Methodology-VV.pdf
Internal-Audit-Methodology-VV.pdfInternal-Audit-Methodology-VV.pdf
Internal-Audit-Methodology-VV.pdf
 
Chapter 2-Lecture 4.pptx
Chapter 2-Lecture  4.pptxChapter 2-Lecture  4.pptx
Chapter 2-Lecture 4.pptx
 
Integrated Management System training,awareness,safety
Integrated Management System training,awareness,safetyIntegrated Management System training,awareness,safety
Integrated Management System training,awareness,safety
 

More from Adrian Hall

Afripay Presentation IAD DCS 2022
Afripay Presentation IAD DCS 2022Afripay Presentation IAD DCS 2022
Afripay Presentation IAD DCS 2022Adrian Hall
 
ITU Presentation at IAD DCS Summit 2022
ITU Presentation at IAD DCS Summit 2022ITU Presentation at IAD DCS Summit 2022
ITU Presentation at IAD DCS Summit 2022Adrian Hall
 
Modular Data Center - Innovation Africa Digital Summit 20220512.pptx
Modular Data Center - Innovation Africa Digital Summit  20220512.pptxModular Data Center - Innovation Africa Digital Summit  20220512.pptx
Modular Data Center - Innovation Africa Digital Summit 20220512.pptxAdrian Hall
 
DCA - Africa Market Analysis 2021_South Africa.pdf
DCA - Africa Market Analysis 2021_South Africa.pdfDCA - Africa Market Analysis 2021_South Africa.pdf
DCA - Africa Market Analysis 2021_South Africa.pdfAdrian Hall
 
Napoleon - C Squared.pdf
Napoleon - C Squared.pdfNapoleon - C Squared.pdf
Napoleon - C Squared.pdfAdrian Hall
 
Chris Lazarues Safaricom Ethiopia
Chris Lazarues Safaricom EthiopiaChris Lazarues Safaricom Ethiopia
Chris Lazarues Safaricom EthiopiaAdrian Hall
 
Anthony Voscarides - Wingu.pdf
Anthony Voscarides - Wingu.pdfAnthony Voscarides - Wingu.pdf
Anthony Voscarides - Wingu.pdfAdrian Hall
 
Bethelhem Dejene.pptx
Bethelhem Dejene.pptxBethelhem Dejene.pptx
Bethelhem Dejene.pptxAdrian Hall
 
JICA - Project Ninja in Africa
JICA - Project Ninja in AfricaJICA - Project Ninja in Africa
JICA - Project Ninja in AfricaAdrian Hall
 
Orbit Health - Transforming Healthcare Access and Delivery in Africa
Orbit Health - Transforming Healthcare Access and Delivery in AfricaOrbit Health - Transforming Healthcare Access and Delivery in Africa
Orbit Health - Transforming Healthcare Access and Delivery in AfricaAdrian Hall
 
Sewasew presentation IAD DCS 2022
Sewasew presentation IAD DCS 2022Sewasew presentation IAD DCS 2022
Sewasew presentation IAD DCS 2022Adrian Hall
 
Blue Health presentation IAD DCS 2022 summit.pptx
Blue Health presentation IAD DCS 2022 summit.pptxBlue Health presentation IAD DCS 2022 summit.pptx
Blue Health presentation IAD DCS 2022 summit.pptxAdrian Hall
 
Roen Menezes Regional Director Thuraya IAD Summit 2019
Roen Menezes Regional Director Thuraya IAD Summit 2019Roen Menezes Regional Director Thuraya IAD Summit 2019
Roen Menezes Regional Director Thuraya IAD Summit 2019Adrian Hall
 
Jonathon Adams VP Ericsson IAD 2019
Jonathon Adams VP Ericsson  IAD 2019Jonathon Adams VP Ericsson  IAD 2019
Jonathon Adams VP Ericsson IAD 2019Adrian Hall
 
Nuran solution showcase
Nuran solution showcaseNuran solution showcase
Nuran solution showcaseAdrian Hall
 
Abdessattar Sassi CTO ZTE
Abdessattar Sassi  CTO ZTEAbdessattar Sassi  CTO ZTE
Abdessattar Sassi CTO ZTEAdrian Hall
 
Daniel Jaeger VP Nokia IAD 2019
Daniel Jaeger VP Nokia IAD 2019Daniel Jaeger VP Nokia IAD 2019
Daniel Jaeger VP Nokia IAD 2019Adrian Hall
 
Dr. Solomon Assefa VP IBM Research IAD 2019
Dr. Solomon Assefa VP IBM Research IAD 2019 Dr. Solomon Assefa VP IBM Research IAD 2019
Dr. Solomon Assefa VP IBM Research IAD 2019 Adrian Hall
 
MTN IAD 2019 presentation - group COO
MTN IAD 2019 presentation - group COOMTN IAD 2019 presentation - group COO
MTN IAD 2019 presentation - group COOAdrian Hall
 

More from Adrian Hall (20)

Afripay Presentation IAD DCS 2022
Afripay Presentation IAD DCS 2022Afripay Presentation IAD DCS 2022
Afripay Presentation IAD DCS 2022
 
ITU Presentation at IAD DCS Summit 2022
ITU Presentation at IAD DCS Summit 2022ITU Presentation at IAD DCS Summit 2022
ITU Presentation at IAD DCS Summit 2022
 
Modular Data Center - Innovation Africa Digital Summit 20220512.pptx
Modular Data Center - Innovation Africa Digital Summit  20220512.pptxModular Data Center - Innovation Africa Digital Summit  20220512.pptx
Modular Data Center - Innovation Africa Digital Summit 20220512.pptx
 
DCA - Africa Market Analysis 2021_South Africa.pdf
DCA - Africa Market Analysis 2021_South Africa.pdfDCA - Africa Market Analysis 2021_South Africa.pdf
DCA - Africa Market Analysis 2021_South Africa.pdf
 
Napoleon - C Squared.pdf
Napoleon - C Squared.pdfNapoleon - C Squared.pdf
Napoleon - C Squared.pdf
 
Chris Lazarues Safaricom Ethiopia
Chris Lazarues Safaricom EthiopiaChris Lazarues Safaricom Ethiopia
Chris Lazarues Safaricom Ethiopia
 
Anthony Voscarides - Wingu.pdf
Anthony Voscarides - Wingu.pdfAnthony Voscarides - Wingu.pdf
Anthony Voscarides - Wingu.pdf
 
Bethelhem Dejene.pptx
Bethelhem Dejene.pptxBethelhem Dejene.pptx
Bethelhem Dejene.pptx
 
JICA - Project Ninja in Africa
JICA - Project Ninja in AfricaJICA - Project Ninja in Africa
JICA - Project Ninja in Africa
 
Orbit Health - Transforming Healthcare Access and Delivery in Africa
Orbit Health - Transforming Healthcare Access and Delivery in AfricaOrbit Health - Transforming Healthcare Access and Delivery in Africa
Orbit Health - Transforming Healthcare Access and Delivery in Africa
 
Sewasew presentation IAD DCS 2022
Sewasew presentation IAD DCS 2022Sewasew presentation IAD DCS 2022
Sewasew presentation IAD DCS 2022
 
Blue Health presentation IAD DCS 2022 summit.pptx
Blue Health presentation IAD DCS 2022 summit.pptxBlue Health presentation IAD DCS 2022 summit.pptx
Blue Health presentation IAD DCS 2022 summit.pptx
 
Roen Menezes Regional Director Thuraya IAD Summit 2019
Roen Menezes Regional Director Thuraya IAD Summit 2019Roen Menezes Regional Director Thuraya IAD Summit 2019
Roen Menezes Regional Director Thuraya IAD Summit 2019
 
Jonathon Adams VP Ericsson IAD 2019
Jonathon Adams VP Ericsson  IAD 2019Jonathon Adams VP Ericsson  IAD 2019
Jonathon Adams VP Ericsson IAD 2019
 
Nuran solution showcase
Nuran solution showcaseNuran solution showcase
Nuran solution showcase
 
Aviat slides
Aviat slidesAviat slides
Aviat slides
 
Abdessattar Sassi CTO ZTE
Abdessattar Sassi  CTO ZTEAbdessattar Sassi  CTO ZTE
Abdessattar Sassi CTO ZTE
 
Daniel Jaeger VP Nokia IAD 2019
Daniel Jaeger VP Nokia IAD 2019Daniel Jaeger VP Nokia IAD 2019
Daniel Jaeger VP Nokia IAD 2019
 
Dr. Solomon Assefa VP IBM Research IAD 2019
Dr. Solomon Assefa VP IBM Research IAD 2019 Dr. Solomon Assefa VP IBM Research IAD 2019
Dr. Solomon Assefa VP IBM Research IAD 2019
 
MTN IAD 2019 presentation - group COO
MTN IAD 2019 presentation - group COOMTN IAD 2019 presentation - group COO
MTN IAD 2019 presentation - group COO
 

Recently uploaded

Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 

Recently uploaded (20)

Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
The transition to renewables in India.pdf
The transition to renewables in India.pdfThe transition to renewables in India.pdf
The transition to renewables in India.pdf
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 

Intro to ISO

  • 1. Introduction to ISO27k Standards www.cmu.edu/rwanda 1 ISMS implementation andISMS implementation and certification process overviewcertification process overview
  • 2.
  • 3. TopicsTopics • Brief intro to ISO • General understanding for ISO certification • Elements of an ISO Management System • What’s the new Annex SL? • Benefits of an ISO Management System Source: Radian Management
  • 5. The BeginningThe Beginning Twenty-five years ago, Nobel laureate Robert Solow remarked, “You can see the computer age everywhere but in the productivity statistics.” That skepticism is gone, as ICT increasingly fuels innovation, efficiency and economic growth. This applies in the ICT-producing and ICT-using sectors – in other words, the whole interconnected world. • 
  • 6. Who is IOS and What Is ISO?Who is IOS and What Is ISO? • The International Organization for Standardization (IOS) is a worldwide federation of national standards bodies. • Working through Technical Committees, it has developed and published over 18,000 different ISO standards that are used internationally for subjects ranging from film speeds to wine glasses to quality management systems. • The official purpose for the issuance of ISO Standards is to facilitate world trade through standardization.
  • 7. Management Systems ISO 20000-1:2011 Service Management ISO 22301 Business Continuity Management ISO 27001-2005 Information Security Management System ISO 9001: 2008 Quality Management System ISO 31000 Risk Management
  • 9. • ISO and the International Electrotechnical Commission (IEC)’s joint technical committee ISO/IEC JTC 1, Information Technology has kept pace with the industry’s staggering dynamism and development, introduced numerous standards, and identified many focus areas for future work. • Information Security and Cyber Security have been in the forefront of the work conducted resulting in the development of many important frameworks, practices, and standards. ISO/IEC-JTCISO/IEC-JTC
  • 10. Understanding theUnderstanding the Standards - DocumentsStandards - Documents Most standards have at least two supporting documents; •Requirements – these are the “Shalls” and are required to be implemented unless exclusions can be taken. The auditor can only audit against the “Shalls”. •Code of Practice – these are the “Shoulds” and are guidance to assist you in implementation. •Guidance – a fully implementable standard that does not have a “certification scheme”. You can be compliant, but not certified.
  • 11. Understanding the StandardsUnderstanding the Standards - PDCA- PDCA Do Plan Check Act
  • 12. Understanding the StandardsUnderstanding the Standards - Scope- Scope • Determine your Scope of Registration • How many people within your organization support this Management System? • How many processes are included? • How many locations?
  • 14. Stages for RegistrationStages for Registration • Submit application to registrar • Stage 1: Assessment of readiness • Stage 2: Assessment for registration audit • Registration/certification awarded for 3 years • Surveillance audits (at least annually) • Recertification audit at the end of 3rd year
  • 15. RegistrationRegistration • Usually takes 1 or possibly 2 auditors 1 to 3 days o depending on scope, size, locations and personnel • You will be told whether or not you will be recommended for registration at the completion of the Stage 2 audit • Certificate usually arrives a 2 – 6 weeks later • Maintaining your ISO Certification(s) is the first step in continuous improvement
  • 16. Registrar/Auditor SelectionRegistrar/Auditor Selection CriteriaCriteria • Accreditation and scope of accreditation • Reputation and customer acceptance • Availability, cost, and location • Knowledge of your business • Culture fit with your organization • Ability to audit all of your future standards Note: The external auditor is hired by the Registrar and presented with qualifications to you upon agreement of audits. You cannot go out and hire your own external auditor.
  • 17. Getting Ready for the AuditGetting Ready for the Audit • Determine team, set budget • Internal auditor(s) training if using in-house resources • Hire consulting firm if applicable • Gap Assessment • Implement requirements of standard to meet your business needs against the gap assessment • Go-Live • Hold Management Review Meeting • Conduct Internal Audit • Refine documentation • Employee involvement training • System adjustment • Registration audit – Stage 1 • System adjustment • Registration audit – Stage 2
  • 18. Ongoing CommitmentOngoing Commitment • Getting certification is only the beginning • Management Representative must keep up weekly/monthly/quarterly with tasks • Internal audits are required at least annually • Management review is required at least annually • Timely completion and updates to internal documents • Annual Surveillance audit by external registrar
  • 19. An ISOAn ISO Management SystemManagement System
  • 20. Elements of a Management SystemElements of a Management System • Management Commitment Top management shall………………. Participation in Management Reviews Provide input for continuous improvement Accountable for resource management • Resource Management Identification of resources including human, technical, information and financial Identification of roles, accountability and responsibility (RACI) Competence, awareness & training
  • 21. Elements of a Management SystemElements of a Management System • Management Reviews Required inputs including reviews of audits, customer feedback, performance measurements, improvements, changes Required outputs including actions recorded for improvements, documented improvements and the effectiveness of those improvements, additional follow-through of actions identified such as resource needs or completion of changes identified • Document & Records Control Documented procedure for creating, approving, maintaining, protecting archiving and destroying documents & records Identifying documents of external origin
  • 22. Elements of a Management SystemElements of a Management System • Internal Audit  Document an audit plan  Identify internal auditors, hire or train  Document outputs and act upon findings  Timely reporting • Continual Improvement  Organization shall continually improve the effectiveness of the management system through the use of the policy, objectives, audit results, analysis of data, corrective and preventive actions and management review  Corrective/Preventive Actions recorded, planned and updated timely  Good Root Cause methodology  Review of effectiveness of actions taken
  • 23. ISO 20000, 27001, 9001ISO 20000, 27001, 9001 ISO 20000 ISO 27001 ISO 9001 4.0 SMS General Requirements 4.0 ISMS 5.0 Management Responsibility 4.1 General requirements 4.1.1 Management Commitment 5.1 Management Commitment 5.0 Management Commitment 4.3.2 Control of Documents 4.3.2 Control of Documents 4.2.3 Control of Documents 4.3.3 Control of Records 4.3.3. Control of Records 4.2.4 Control of Records 4.4.1 Provision of Resources 4.4.2 Human Resources 5.2.1 Provision of Resources 5.2.2 Training, Awareness & Competence 6.0 Resource Management 4.5.4.2 Internal Audit 6 Internal ISMS audits 8.1.2 Internal audit 4.5.4.3 Management Review 7 Management Review 5.6 Management Review 4.5.5 Maintain and improve the SMS 8 ISMS improvement 8.4 Continual improvement
  • 24. A New StructureA New Structure • Starting with ISO 22301, the Annex SL (see reference below) concept was introduced to standardize the management system requirements for ALL management system standards. The next series of standards that were published with the Annex SL is ISO 27001 in 2014 and the next major re-write is the much anticipated 2015 release of ISO 9001. http://www.iso.org/iso/home/news_index/news_archive/news.htm  
  • 25. Examples from the new AnnexExamples from the new Annex SLSL Introduction 1. Scope 2. Normative references 3. Terms and definitions 4. Context of the organization 5. Leadership 6. Planning 7. Support 8. Operation 9. Performance evaluation 10. Improvement
  • 26. Examples from the new Annex SLExamples from the new Annex SL Example of identical definitions :  •Organization, interested party, policy, objective, competence, conformity. Example of identical text :  •Top management shall ensure that the responsibilities and authorities for relevant roles are assigned and communicated within the organization. •The 27001 standard has been harmonized under the new Annex SL
  • 28. Benefits of the Management SystemBenefits of the Management System • There are obvious internal benefits  Competitive Advantage  Commitment to detail for the scope; i.e.: quality, security, services, etc.  Better employee engagement through training, communication and accountability  Formalized & repeatable processes  Accountability at all levels  Ongoing internal and external audits ensure weaknesses are identified and improvements are completed  Better governance and management of suppliers and outsourced processes  More efficient ability to change  Reduction in duplicate effort
  • 29. Reducing RiskReducing Risk • 85% of information security (ISO 27001) clients built stakeholder confidence • 79% experienced faster recovery speeds from incidents • 83% of business continuity (ISO 25999) clients reported enhanced reputation as the key benefit • 64% of health & safety clients reduced incidents while 49% made cost savings • 99% of organizations meets their Information Security objectives once they have implemented ISO 27001 Source: BSI Excellerator Research 2011 and Erasmus University Study
  • 30. Client InsightsClient Insights Large Printing Company •The biggest benefit we have seen over the course of our ISO certification is a reduction in spoilage. Before we were ISO certified, we averaged about 6.5% spoilage per year. Last year our spoilage was 1.2%. •Earnings for 2012 were 57 million so 1.2% was approx. $684,000 versus 6.5% would be 3.7 million. Pretty significant benefit. •We have also benefitted from standardization of processes and improved communication.
  • 31. The East African SceneThe East African Scene • The East African Information Security Managers Forum (ISMF), aiming to involve security practitioners across the region to share experiences on information management, • The ISMF has been set up to discuss these issues at length and develop the necessary solutions and systems that will help East Africa in attaining maximum security in information delivery. • Almerindo Graziano, chief executive officer (CEO) at Silensec Kenya, said: “We have come up with a new information security standard, the ISO 27001 that emphasizes on leadership and senior management responsibilities in organisations.
  • 32. • Salome Kanyugo, representing the Kenya Revenue Authority (KRA), said: “The increased automation in services has become a major challenge for us and this has brought about the need to secure our information so it is not easily accessible to the wrong people. • “To cover this challenge and others such as internal threats and web cloning, we have implemented various information security standards and currently we are in the process of implementing the new ISO 27001.” • She said implementing the new standards will ensure customers are able to trust their information is secure with the organisation. The East African SceneThe East African Scene