ISO27001 and the Resources and Competence Requirements
ISO27001 Information Security Management Systems

ISO2001:2013 clause 7 is all about Support, what do you need, what have you got, does everyone know what they should be doing, have you documented it and a few other things besides that. In this post we are going to cover the first two clauses, clause 7.1 Resources and Clause 7.2 Competence because we think they pretty much go hand in hand, hopeful...

  6824 Hits
Getting an Understanding of the Critical Elements in Your Lean Journey
Operational Excellence

Recently I had the chance to catch up with Craig from Mango QHSE to talk about lean. More specifically Understanding of the Critical Elements in Your Lean Journey, what things need to be in place if you are going to have a successful lean transformation for your organisation.  When it comes to lean people get hooked on the tools, forgetting th...

  2772 Hits
The 5 lean steps to stopping fire-fighting at work
Operational Excellence

The phone is ringing and you know it is going to be another unhappy customer, the only question is what are they going to complain about? Their product is late, there are defects in what they got, they got the wrong thing, there were too many or not enough. Every time the phone it is a complaint, another fire to be put out, another thing that you n...

  3992 Hits
ISO27001 - Information Security Objectives and Planning to Achieve Them
ISO27001 Information Security Management Systems

Having objectives is pretty important if you want to achieve something or get somewhere. Organisations (hopefully) have objectives for most things like profitability, sales per year, marketing and even their ISO9001 Quality Management System. It makes sense then that there should be some objectives linked to your ISO27001 Information Security Manag...

  10305 Hits
If you want better engagement and alignment, then its time to kill the Annual Review
Organisational Health

The working year has many milestones that are marked on the wall or outlook calendars. Some are looked on with excitement and some, well not so much. The annual break and long weekends would be the big positives, on the other side we have things like monthly budget reviews and of course the annual employee reviews. It does not matter if you are the...

  2980 Hits
ISO27001 and the Actions to Address Risk & Opportunities
ISO27001 Information Security Management Systems

Like many of the latest ISO standards ISO27001 for Information Security Management Systems takes a risk-based approach to things. That makes sense, since it is hard to make something secure, if you do not understand the risks. Clause 6.1 of the standard – Actions to address risk and opportunities is where this risk-based thinking really kicks into ...

  4665 Hits
Building the Lean Muscle
Operational Excellence

Last month I was having a chat with a friend about a problem they were having at their organisation. They had been trying to get their people involved in doing some continuous improvement, or any improvement work. They had sat everyone down and told them that they needed to find ways to get products out quicker. The issue was that their order book ...

  2293 Hits
Organisational Inductions - you are doing them wrong
Organisational Health

Recently I was talking to a group of people (all from different organisations) about Standard Work. That is when organisations have a method of doing things, just one method, everyone does it the same way so you can get repeatable results. However, the important thing about these standard work routines or practices is that they do have to change ov...

  2606 Hits
ISO27001 & The Roles, Responsibilities and Authorities Clause
ISO27001 Information Security Management Systems

If you have already obtained ISO9001 you will recognise the name of this clause because of course they are both aligned to the same high-level structure. The other bonus with already having obtained 9001 is that you are already mostly the way there with achieving the requirements of this clause for your Information security management System. The i...

  7495 Hits
How to Create a Lean Layout
Operational Excellence

The other day I watched the movie The Founder with Michael Keeton who plays Ray Kroc the "founder" of the McDonalds restaurant chain. It is a great movie and it is pretty factual as biopics go, and as it turns out technically, he is not the founder of McDonalds, the McDonald brothers were (hence the name) and certainly worth a watch. It brought bac...

  5801 Hits
ISO27001 & The Information Security Policy
ISO27001 Information Security Management Systems

Clause 5.2 of ISO27001:2013 is all about your Information Security Management Policy and it is pretty insistent that you have one, in fact its Mandatory. That is a pretty good thing since everything else in your entire Information Security Management System happens because of this policy which make sense if you think about it. Policies sit at the t...

  7120 Hits
Fractured – Waste in the Medical Clinic
Operational Excellence

Earlier this week I had to take my daughter to the fracture clinic to get her leg checked out. She had broken it 4 weeks ago and it was check up time. It was interesting when she 1st went to get it check out when it happened. On the original visit hey had asked all sorts of questions, decided on an outcome then thought, actually we should Xray it j...

  6031 Hits
How Does ISO Define Traceability?
ISO 9001 Quality Management

One of the questions I get asked a lot (and it really is a lot!) is "How does ISO define traceability?" that's always accompanied with: what do they want, what things do I need put in place, will it be expensive and but my customer doesn't care about it! The answer, initially at least is, "It depends!" Obviously, this is not overly helpful, so we n...

  12590 Hits
ISO27001 Leadership and Commitment
ISO27001 Information Security Management Systems

How many times have you heard people say that it is one rule for them and another for the management? It is certainly the fastest way to kill not only the morale at your company but also the systems that you are trying to use. That is why ISO27001 Clause 5.1 is all about the requirement for Leadership and Commitment, they are codifying the need for...

  10082 Hits
Other Peoples Monkeys – Stop Making Someone Else’s Problems Yours
Leadership

I have been working with a couple of people of late who are just struggling to get things done, they have so much on their plates that there is just more to do than there are hours in their working week. The result of that is that they are stealing time from their personal lives to try and get things done in their work lives and feeling guilty abou...

  9065 Hits
Determining the Scope of your ISO27001 ISMS
ISO27001 Information Security Management Systems

If you have taken our advice you have so far managed to work through clause for and create outputs for the other sections, 4.1 Understanding the organisation and it's context, 4.2 Understanding the needs and expectations of interested parties and 4.4 Information security management system. What that means is that you are left now with only clause 4...

  4519 Hits
8 Steps to using Bow Tie Analysis for Risk Management
ISO31000 Risk Management

When it comes to understanding risk analysis people are used to using a risk matrix and walking through a step by step risk analyses process, it's probably the default way of looking at the analysis of risk, but it's not the only way. The bow tie method is a really visual way of understanding the impacts of a hazard, the risk it presents, the conse...

  114792 Hits
ISO27001 and the Information Security Management Clause
ISO27001 Information Security Management Systems

ISO27001 Clause 4.4 Information Security Management System is a small 2-line clause which does not look like it should really matter, it says: The organisation shall establish, implement, maintain, and continually improve an information security management system, in accordance with the requirements of this international standard. Great, easy, that...

  3060 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.manycaps.com/

Subscribe to Our Newsletter

To Get Regular Updates on ISO | Lean | Free Resources
Sorry we need your name
Invalid Input - Sorry we need your last name here
Sorry Can you just check your email address as well

We Support

Trees That Count
Special Childrens Xmas Party

Proud To Be

Canterbury Trusted
EcoOnline - Platinum Partner