As we have mentioned before AS9100 REV D is very much focused on understanding the Risks in your Quality Management System and to your organisation plus how you will handle them. It makes sense, working in the aviation, space and defence industries is risky and the products that come out of those industries are perhaps the some of the highest risk ...
70 Hits
Free Template - Process Tracking Letters Template   We have put together a collection of daily Process tracking letters that you can use to track all of your key business processes daily and monthly. This allows you to have a great visual management tool to measure improvement across your organisation. They are really easy to use - print ...
87 Hits
What would you do if one day your accountant walked in and said Ok boss, we have no money and the bank is going to have to step in. They are going to keep us afloat and let us trade out of the problem, but we need to improve what we do. They want us to increase our productivity, reduce our money tied up in WIP & stock, oh, and they will not let...
86 Hits
The interesting thing about the leadership clause of any standard is that it is one many organisation do not pay enough attention to. It tends to be an area where people still believe it is the quality or the safety or the compliance manager's role and so the senior management team take a hands-off approach leaving things to the person they have ha...
112 Hits
Clause A6, Organisation of Information Security, of the ISO 27001 is about providing guidance on the management framework of your Information Security Management System (ISMS). Clause A6 is split into two sections, A6.1 covers the Internal Organisation while clause A6.1 covers Mobile Devices and Teleworking (remote working) which is particularly on...
132 Hits
The great thing about lean is that there is always more to learn, there is always improvement in the thinking, the methodologies, the approaches, and the tools that get used. However, the underlying idea never changes, people somehow manage to complicate it when trying to explain what lean is and that perhaps is one of the things that make people t...
503 Hits
How many times have you heard that a new process or a business change was being done to align to 'best practice'? Other phrases in the same mould are 'that this new process or methodology has worked in many organisation before it'll work here' or even better, 'we work to 'industry standard'? They are all the same thing when it boils down to it, a s...
237 Hits
ISO27001:2013 Annex A for Information Security Management Systems may seem like a bit of a long list of controls, there are 114 of them after all! However, it is fair to say that Annex A of the standard is quite possibly the most important section of the standard because it list's the controls that you need to consider and where appropriate have in...
208 Hits
When you read through AS9100 D you will notice that where ISO9001:2015 may hint at something or assume you understand what it means, AS9100D is far better at being explicit in what it's talking about. Right off the bat in the scope of the standard for example it states "If there is a conflict between the requirements of this standard and customer o...
205 Hits
Over the weekend I send some time down in Twizel which is in middle of New Zealand South Island. It is nestled not far from Mount Cook, NZ's highest peak and Queenstown, the adventure capital and is home to some of the most traumatic scenery and stunning views around, especially in autumn as the leaves turn golden and start to fall to the ground. I...
178 Hits
I remember sitting in Biology back in high school (admittedly a long time ago) and the teacher explaining that our bodies were just a big battery for our brain. Sure, we have arms for reaching out and grabbing things, typically food, legs make us mobile so we can run away from the sabre tooth tiger and of course eyes to see the same sabre tooth tig...
387 Hits
Clause 10 of ISO27001 Information Security Management Systems (ISMS) is where you get some serious value for your organisation. Along the way to implementing your ISMS you have planned things out, you have implemented your information security management policy, implemented various new processes and systems and in your internal auditing process you...
193 Hits
It does not matter if you are working to achieve or already have your International Standards Organisation (ISO) certification internal auditing is a key element you need to master. Internal auditing seems to be one of the areas of real trepidation and confusion around the requirements for internal auditing programs. When we talk with clients who a...
1199 Hits
ISO27001 for Information Security Management Systems clause 9 Performance Evaluation is full of that favourite ISO term "shall" which as we all know means you must do what they are asking. Clause 9 is split into 3 subclauses to help focus you onto the things that really drive the performance evaluation requirements in any management: 9.1 Monitoring...
339 Hits
The world of compliance is changing, it has had to change. The days of printing a forest worth of trees for your management systems and then keeping them, all safely tucked into a in a folder on the top shelf, is not something you can do today. COVID-19 has surely put paid to that myth once and for all? The idea of looking them it the week before a...
283 Hits
Going through university I studied manufacturing systems which is a fancy title for industrial engineering. We were the guys who learned lots about figuring out how to be productive. After university I landed a great job in an electronics company working as, you guessed it, a production engineer. Our focus, we were told was to create processes and ...
272 Hits
Pretty much everyone in industry at some level have heard of ISO 9001, it is the world's benchmark for Quality Management Systems, not as many however have heard of AS9100D or AS9100:2016 Rev D to give it it's full title. So, what exactly is it and why talk about it alongside ISO9001? AS9100D is the Quality Management Systems - Requirements for Avi...
256 Hits
ISO27001 for information Security Managements Systems Clause 8 Operation is where the rubber starts to meet the road, this is the part of the standard that requires to you to do what you have so far said you will do. If you think about the structure of the standard and apply the Plan Do Check Act (or Adjust) approach that the standard takes then th...
189 Hits
Even for the experienced ISO Systems manager, audits can be a nervous time. The second guessing of what you have created in your systems and what your ISO certification auditor is going to be looking for can lead to over thinking things and even on extremes the odd restless night. It does not matter if you are certifying to ISO9001 for quality mana...
238 Hits
Like all ISO Management Systems your ISO 27001:2013 Information Security management System is going to need some documentation. The requirements of exactly what to document however are spread throughout the standard in each clause as requirements for documented evidence or records, typically prefaces with the words shall. Clause 7.5 documented info...
287 Hits
There are a few things you need to know about Business Metrics or KPI's (Key Performance Indicators), firstly its that they are important, anyone who says any different clearly does not really understand how businesses work. KPI's help you understand how your organisation is performing, if you are winning or losing, getting better or getting worse....
539 Hits
With the year almost over a friend of mine got an email from his with a sheet of paper attached asking him to put together his 5 objectives for 2021 and remember they must be SMART! Smart being a SMART Goal which is about being Specific Measurable Achievable Realistic and Time bound. I hate this he said, what is the point, what the heck am I suppos...
330 Hits
The great thing about ISO27001:2013 is that it follows the high-level structure set out by ISO as their preferred way of working through a standard. What that means it that pretty much all the new ISO standards follow the same list of 10 clauses in the same order. It is designed to help you align your various management systems. That's really helpf...
600 Hits
It has been a fair while since ISO27001:2013 for Information Security Management Systems was published yet it's adoption is only really now starting to gain some traction, just in time for the work on the next revision to really get underway. Like all ISO standards there are set requirements about what you must do, ISO list these as "shall" , part ...
4577 Hits
Free Checklist - ISO27001:2013 Required Documents and Files  Like everything we do, getting the notes is simple, fill in the form below and we will send it to you for FREE, no catches, no strings attached just simple, tell us where to send it to and it's yours. We have broken all the ISO27001:2013 document & records requirements down ...
241 Hits
ISO2001:2013 clause 7 is all about Support, what do you need, what have you got, does everyone know what they should be doing, have you documented it and a few other things besides that. In this post we are going to cover the first two clauses, clause 7.1 Resources and Clause 7.2 Competence because we think they pretty much go hand in hand, hopeful...
720 Hits
Recently I had the chance to catch up with Craig from Mango QHSE to talk about lean. More specifically Understanding of the Critical Elements in Your Lean Journey, what things need to be in place if you are going to have a successful lean transformation for your organisation.  When it comes to lean people get hooked on the tools, forgetting th...
355 Hits
The phone is ringing and you know it is going to be another unhappy customer, the only question is what are they going to complain about? Their product is late, there are defects in what they got, they got the wrong thing, there were too many or not enough. Every time the phone it is a complaint, another fire to be put out, another thing that you n...
402 Hits
Having objectives is pretty important if you want to achieve something or get somewhere. Organisations (hopefully) have objectives for most things like profitability, sales per year, marketing and even their ISO9001 Quality Management System. It makes sense then that there should be some objectives linked to your ISO27001 Information Security Manag...
1713 Hits
The working year has many milestones that are marked on the wall or outlook calendars. Some are looked on with excitement and some, well not so much. The annual break and long weekends would be the big positives, on the other side we have things like monthly budget reviews and of course the annual employee reviews. It does not matter if you are the...
351 Hits
Like many of the latest ISO standards ISO27001 for Information Security Management Systems takes a risk-based approach to things. That makes sense, since it is hard to make something secure, if you do not understand the risks. Clause 6.1 of the standard – Actions to address risk and opportunities is where this risk-based thinking really kicks into ...
535 Hits
Last month I was having a chat with a friend about a problem they were having at their organisation. They had been trying to get their people involved in doing some continuous improvement, or any improvement work. They had sat everyone down and told them that they needed to find ways to get products out quicker. The issue was that their order book ...
312 Hits
Recently I was talking to a group of people (all from different organisations) about Standard Work. That is when organisations have a method of doing things, just one method, everyone does it the same way so you can get repeatable results. However, the important thing about these standard work routines or practices is that they do have to change ov...
279 Hits
If you have already obtained ISO9001 you will recognise the name of this clause because of course they are both aligned to the same high-level structure. The other bonus with already having obtained 9001 is that you are already mostly the way there with achieving the requirements of this clause for your Information security management System. The i...
1403 Hits
The other day I watched the movie The Founder with Michael Keeton who plays Ray Kroc the "founder" of the McDonalds restaurant chain. It is a great movie and it is pretty factual as biopics go, and as it turns out technically, he is not the founder of McDonalds, the McDonald brothers were (hence the name) and certainly worth a watch. It brought bac...
492 Hits
Clause 5.2 of ISO27001:2013 is all about your Information Security Management Policy and it is pretty insistent that you have one, in fact its Mandatory. That is a pretty good thing since everything else in your entire Information Security Management System happens because of this policy which make sense if you think about it. Policies sit at the t...
3602 Hits
Earlier this week I had to take my daughter to the fracture clinic to get her leg checked out. She had broken it 4 weeks ago and it was check up time. It was interesting when she 1st went to get it check out when it happened. On the original visit hey had asked all sorts of questions, decided on an outcome then thought, actually we should Xray it j...
3839 Hits
One of the questions I get asked a lot (and it really is a lot!) is "How does ISO define traceability?" that's always accompanied with: what do they want, what things do I need put in place, will it be expensive and but my customer doesn't care about it! The answer, initially at least is, "It depends!" Obviously, this is not overly helpful, so we n...
2080 Hits
How many times have you heard people say that it is one rule for them and another for the management? It is certainly the fastest way to kill not only the morale at your company but also the systems that you are trying to use. That is why ISO27001 Clause 5.1 is all about the requirement for Leadership and Commitment, they are codifying the need for...
5278 Hits
I have been working with a couple of people of late who are just struggling to get things done, they have so much on their plates that there is just more to do than there are hours in their working week. The result of that is that they are stealing time from their personal lives to try and get things done in their work lives and feeling guilty abou...
784 Hits
Free 8 Lean Wastes  for Healthcare Poster   Understanding the 8 lean wastes in healthcare is critical to any lean journey happening in a medical environment and a great place to start any journey.  We put together this simple poster that you can use to explain what each waste is with respect to the Health Care sector. Like every...
792 Hits
If you have taken our advice you have so far managed to work through clause for and create outputs for the other sections, 4.1 Understanding the organisation and it's context, 4.2 Understanding the needs and expectations of interested parties and 4.4 Information security management system. What that means is that you are left now with only clause 4...
609 Hits
When it comes to understanding risk analysis people are used to using a risk matrix and walking through a step by step risk analyses process, it's probably the default way of looking at the analysis of risk, but it's not the only way. The bow tie method is a really visual way of understanding the impacts of a hazard, the risk it presents, the conse...
9768 Hits
ISO27001 Clause 4.4 Information Security Management System is a small 2-line clause which does not look like it should really matter, it says: The organisation shall establish, implement, maintain, and continually improve an information security management system, in accordance with the requirements of this international standard. Great, easy, that...
666 Hits
Solving problems can be challenging, that is after all why they are called problems. It gets harder though if it is something completely out of left field, something that is completely new to you and just leaves you stumped. It can be stressful at times, especially if you have a bunch of people all depending on your decision. Thankfully, you are pa...
501 Hits
There are a few clauses in the ISO27001 Information Security management Systems Standard that can cause people a little trepidation or confusion, clause 4.1 – Context of the Organisation tends to be one of those. The thing is however, once you get what they are looking for here it is a really helpful thing for your organisation. Clause 4.1 Understa...
2728 Hits
The ability to deliver client orders quickly can be the difference between winning or losing an order but how can you ensure that you do that and how quickly do you really need to do it? Part of the challenge is of course the desire everyone seems to have of wanting stuff now, to have the safety net of knowing it's there just in case you or the cli...
2736 Hits
If you already have ISO9001:2015 then Clause 4 of ISO 27001 is going to sound very familiar, and it should, it's pretty much the same clause but with a few, very minor tweaks in wording and the odd reference. That means you can leverage the work that you have already done in your ISO9001:2015 system for use in your ISO27001:2013 Information Securit...
1479 Hits
There is a major problem in organisations, and we need to fix it. It is a problem so major that it is going to take years to fix it, and in some organisations it will be fatal, and they just will not make it I am afraid. The challenge is that the issue is not immediately obvious, first it pops up in one area of the business and then before you know...
607 Hits
Like most parents I have a morning routine that gets followed if I want to get my daughter to school on time, there is very little variation to the routine otherwise things go wrong and we miss the school bell. Of course, we could just get up earlier I suppose and have extra time to sit around but that just seems a little wasteful. When I get up th...
548 Hits
When talking to clients about implementing any ISO standard the question that they all have is "where do I start?" which seems like a really obvious question, and the answer, well that's equally obvious you start at the very beginning! Now that you have Mary Poppins in your head let's begin. The very first thing you should do is go out and actually...
677 Hits
Every organisation has problems, it doesn't matter how big or how small the organisation, there are always problems. They come in all shapes and sizes from little niggles like there's no A3 paper for the printer again to we have to do a full recall of the product all the way to the more serious we may have to shut the company down. There is a myria...
2095 Hits
Anyone who reads any of our blogs understands that continuous improvement runs through the DNA of the entire site, we live and breathe continuous improvement so it shouldn't be a surprise that we consider it a key principle of any ISO27001 Information Security management System. The expectation of continuous improvement doesn't just come from us ho...
1066 Hits
As a parent I find myself saying things to my 11 year old daughter that I certainly heard my parents say to me, things that made my eyes roll and managed to draw deep huffing breaths from me as these were stated for the umpteenth time, and I'm certain I'm not alone with this. Things like, tidy up your room, where is your other shoe (there is always...
572 Hits
It's easy to think that when something is called Information Security that it only relates to the 'Information Technology' Department of your organisation, it's a common mistake that many people make. They believe, wrongly, that the IT geeks will have this all taken care of and it's not something for their department or their people to worry about,...
400 Hits
We work with a lot of organisations helping with their ISO9001, 14001, 27001 or 45001 implementation and ongoing management of their new systems. We like to use Mango for this as it's a fantastic fully integrated platform to manage all the requirements of these standards. Over the last few years, we have noticed an ongoing trend within these implem...
789 Hits
When I talk to organisations about how to improve things something they all jump on is their quality, we must improve our quality. Great I'd say, so tell me what you mean by that, they would then typically run off a list of things that are found to be wrong with their products or service that either get to the customer or cause things to pile up at...
970 Hits
 A short while ago I got the chance to catch up with Craig Thornton from Mango QHSE, of course both being lock-down along with the rest of New Zealand and most of the world it was via a web call.  The subject was one close to my heart, improvements. Specifically how do you uncover that are already hiding within your QHSE system, that are ...
477 Hits
You may have noticed that we used the word Active twice in the title of this principle, that was deliberate. When it comes to your Information Security Management System relaying on passive, reactive security steps is going to be pretty disastrous for your organisation, waiting for something to happen ( or worse still if something happens and you d...
481 Hits
With everything that is going on in the world at the moment with the Covid-19 pandemic the move to working remotely has exploded. People have, to be fair, worked remotely for a long time and been successful with it, but it's not normally been the whole team, it's normally been a few people and even then they would pop in for face to face meetings o...
3691 Hits