<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Implementing ISO 27001</title>
	<atom:link href="http://www.secure-data-destruction.co.uk/iso27001blog/index.php/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.secure-data-destruction.co.uk/iso27001blog</link>
	<description>A Coal-Face Account From The Secure Data Destruction Industry</description>
	<pubDate>Thu, 22 Apr 2010 07:37:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Understanding Information Security Risk Assessment</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/22/information-security-risk-assessment/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/22/information-security-risk-assessment/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 07:31:15 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[A. Overall IMS Strategy]]></category>

		<category><![CDATA[B. ISO 27001]]></category>

		<category><![CDATA[General Research]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=729</guid>
		<description><![CDATA[This morning I am firmly back on the shores of http://www.iso27001security.com/ and looking around again.  Apparently, there&#8217;s a discussion forum and a members area which you have to join to access.  The membership criteria are written to deter the unworthy from joining or so to speak.  I write an application which explains I am a [...]]]></description>
			<content:encoded><![CDATA[<p>This morning I am firmly back on the shores of <a href="http://www.iso27001security.com/">http://www.iso27001security.com/</a> and looking around again.  Apparently, there&#8217;s a discussion forum and a members area which you have to join to access.  The membership criteria are written to deter the unworthy from joining or so to speak.  I write an application which explains I am a management consultant who may be doing this kind of work for clients.  I also say that I could add a review of Alan Calder&#8217;s book which I have just read.  I am hoping for an immediate reply but I don&#8217;t get one - I&#8217;ll have to wait.</p>
<p>Having partially cracked the Statement of Applicability puzzle I am now looking for stuff to help me understand Risk Assessment - or  at least risk assessment as it specifically applies to ISO27001.  Continuing with my swimming in the sea analogy, <a href="http://www.iso27001security.com/">http://www.iso27001security.com/</a> does seem to be like a desert island with a few trees of fruit in the middle of an vast ocean.  In my anaology, the ocean represents internet or life (depending on how profound you want to be) and it is devoid of any  information about iso27001.)</p>
<p>My mind temporarily skips to BBC Radio 4&#8217;s desert island disks which I have always listened to and also wanted to play.  I think that if I was marooned on this desert island, I certainly wouldn&#8217;t choose the ISO 27001 standard or even a Statement of Applicability to go alongside the bible and the complete works of Shakespeare.  Would my one luxury on the desert island might be a fully certified, UKAS approved integrated management system for a secure data destruction company?  I think not but I&#8217;d love to have one of those on this temperate island (Britain), right now and be at the end of all this!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/22/information-security-risk-assessment/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ISO 27001 The Statement of Applicability</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/18/iso-27001-the-statement-of-applicability/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/18/iso-27001-the-statement-of-applicability/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 07:26:02 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[Statement of Applicability]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=613</guid>
		<description><![CDATA[I have been examining the ISO 27001 Standard Document itself and feeling rather overwhelmed and that I am bashing my head against a brick wall.
I begin to rethink my strategy and flick backwards quickly to page 5.  This is where the &#8216;Statement of Applicability&#8217; is mentioned.  This ties together the list of Controls and Objectives [...]]]></description>
			<content:encoded><![CDATA[<p>I have been examining the ISO 27001 Standard Document itself and feeling rather overwhelmed and that I am bashing my head against a brick wall.</p>
<p>I begin to rethink my strategy and flick backwards quickly to page 5.  This is where the &#8216;Statement of Applicability&#8217; is mentioned.  This ties together the list of Controls and Objectives - the list of practical things one need to do to implement the standard - with the content of the standard itself so its probably a good place to start.  There is a lot about Risk Assessment before the Statement of Applicability which I don&#8217;t understand but I can come back to them later.  I&#8217;ve got the Statement of Applicability as a short term objective - a buoy to swim towards that perhaps I can cling onto for a while.  So I type &#8220;Statement of Applicability ISO27001&#8243; into Google and start trawling through the results.</p>
<p>Almost immediately I come across <a href="http://www.iso27001security.com/">http://www.iso27001security.com/</a>.  By its basic but functional design this site just looks like the kind of site that could cut to the chase and &#8216;deal the deal&#8217;.  There are a few scary bits like mentions of other ISO27002, ISO 27003 but what catches my eye immediately after this is a FREE ISSO27k toolkit.  Amazingly, I don&#8217;t even have to register on the site to get access to it.</p>
<div class="wp-caption alignright" style="width: 256px"><a href="http://www.secure-data-destruction.co.uk/data_destruction.html"><img title="Hard Drive Destruction" src="http://www.secure-data-destruction.co.uk/images/crushed-dard-discs.jpg" alt="Hard Drives after Destruction." width="246" height="188" /></a><p class="wp-caption-text">Hard Drives after Destruction.</p></div>
<p>I spend quite a while opening documents up on the site and reading them.  The documents here have been developed by ISO 27001 implementers and then put up on the site.   This site clearly doesn&#8217;t offer a complete toolkit or total solution to my problems but it does give applied examples of certain documents and there is comparatively little in the way of guff.  Most of the contributions are made by two individuals but there are other contributors too.</p>
<p>The fourth document I open off the site is a Statement of Applicability.  This is a blank template - which is not populated with data - but I still get the jist - more than having see an actual example of one, I quickly see its primary purpose.  The list is a spreadsheet for all the Controls and Objectives listed in Appendix A of the standard.  There are several columns and notes I don&#8217;t understand yet  but clearly what one has to do is go through each of these 120 or so items and record what one has done to cover them off in one&#8217;s own organisation.</p>
<p>Against each row is a &#8220;Controls&#8221; column and a &#8220;Selected Controls&#8221; and a &#8220;Reasons for Selection&#8221; group of columns.  Reasons for Selection are broken down into four types &#8216;LR: legal requirements, CO: contractual obligations, BR/BP: business requirements/adopted best practices, RRA: results of risk assessment, TSE: to some extent.</p>
<p>On the right there&#8217;s a &#8216;Remarks (Overview of implementation)&#8217; column where one should record the  to the specific action taken to meet the control.  This could be introducing a swipe card system on doors, creating a written policy or implementing a procedure to verify the <a title="http://www.secure-data-destruction.co.uk/data_destruction.html" href="http://">destruction of hard drives</a>.</p>
<p>I don&#8217;t get the whole picture yet, but what I do get is that the ISO 27001 Standards sets a defined series of things called &#8220;controls&#8221; with which my <a title="Data Destruction" href="http://www.secure-data-destruction.co.uk/default.html">data destruction</a> company needs to comply.  I will need to go through this list one by one and check that I can practically meet them.</p>
<p>The buoy I spotted in the distance has turned out to be a rubber ring.  Thanks to this I am now riding higher in the water and time to float home for the night.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/18/iso-27001-the-statement-of-applicability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>On to ISO 27001 and an Information Security Management System</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/14/on-to-iso-27001-and-an-information-security-management-system/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/14/on-to-iso-27001-and-an-information-security-management-system/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 08:49:50 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[A. Overall IMS Strategy]]></category>

		<category><![CDATA[B. ISO 27001]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=568</guid>
		<description><![CDATA[

So begins the start of a refreshed effort to find the practical or working examples of how to implement 27001 which have so far evaded me. What does it mean for the way my shredding business should handle personal data and comply with legislation such as the Data Protection Act and the WEE Directive?
I start [...]]]></description>
			<content:encoded><![CDATA[<p><!-- /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin-top:0cm; 	mso-para-margin-right:0cm; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0cm; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;}--></p>
<p><!--endif--></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">So begins the start of a refreshed effort to find the practical or working examples of how to implement 27001 which have so far evaded me. What does it mean for the way my shredding business should handle personal data and comply with legislation such as the Data Protection Act and the WEE Directive?</span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">I start to give <a href="http://www.google.co.uk">Google</a> a pummelling. There really aren’t many links that look like they are going to give me what I want. So I end up going very deep – to search results 80 and above and opening tens of documents including ones on information assurance, the Cabinet Office and risk management - in pursuit of my goal.</span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">What I really want to find is an Information Security Manual for a small or mid-size organisation which somebody has published on their website – one which is a bit more friendly that the one from the IT Governance Toolkit trial. I am aware that organisations shouldn’t publish such things on their website –particularly those involved security - as letting the public know about their security systems obviously isn’t a good idea. But I am expecting to find something out there in cyberspace – you can find almost anything else! </span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">The first useful looking document is an </span><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"><a title="ISMS Manual" href="http://www.secure-data-destruction.co.uk/images/penninenhstrust27001manual.pdf">Information Security Manual </a>produced <span style="color: #000000;">by the Pennine Care NHS Trust. Thi</span>s is clearly the kind of thing that I am looking for but it doesn’t strike me as particularly friendly. The first two sides are about “Policy Document Control” and then the index comprises pages 3-5. I have seen this kind of thing before from the <span style="color: #000000;"><a title="CSIA" href="http://www.cabinetoffice.gov.uk/csia.aspx">Cabinet Office</a> and <a title="CESG" href="http://www.cesg.gov.uk/">CESG</a>. Th</span>e first actual prose appears on page 6: </span></p>
<p style="margin-bottom: 0.0001pt; line-height: normal;"><em>“1. INTRODUCTION</em></p>
<p style="margin-bottom: 0.0001pt; line-height: normal;"><em>1.1 The Trust has a duty to protect its information assets and thus to ensure business continuity and minimise the adverse effects of securityincidents. Information assets and the IT systems that support them arebecoming increasingly more vulnerable as the potential for wideraccessibility is facilitated via more powerful computers and communications networks.</em></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><em>1.2 Any loss of the ability to access information could have a significanteffect on the efficient operation of the Trust and may result an inabilityto provide services to patients and financial loss to the Trust.”</em></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">These are to me statements of the very obvious, the like of which feature widely in many ISO 27001 documents I have seen. I know they have to be there but doesn’t their continued use and repetition run the risk of making the user, who should be interested in their content, just switch off?</span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">The document continues for 47 pages. There are guidelines here for information assurance practices including the setting of passwords and controlling access to buildings. However, its difficult to determine the structure of the document and how it fits into an overall framework. It is on the right lines of what I am looking for but it is for a very sizeable organisation. I move on.</span></p>
<p class="MsoNormal"><span style="color: #000000;"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">The next document which catches my eye is an <a title="Information Security Manual" href="http://www.secure-data-destruction.co.uk/images/A.3.1.1_Information_Security_Business_Manual.doc">Information Security Business Manual</a> from NHS Wales. This is in Word and is clearly a template with blanks or red text which can be filled in by different NHS branch offices to suit their needs. It’s a lot shorter than the Pennine document at only 24 pages.</span></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">Some terms used are ery familiar such as “</span><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Senior Management Team”. W</span><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;" lang="EN-GB">e then get onto “ISMS </span><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Operational Forum Membership” which sounds very corporate and, stone me, Plan/Do/Check/Act (PDCA) model with a little chart makes an appearance on Page 10!</span></p>
<p class="MsoNormal"><span style="color: #000000;"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">The good thing about this document though is its length. It has some slightly scary headings such as those mentioned above but it strikes me (although I can’t be sure) that somebody has spent a lot of time simplifying things and reducing them down to produce a very well put together template that will save an NHS departmental manager a lot of time in producing an Information Security Manual. Whether the person producing the manual would understand what they were doing beyond filling in the blanks I am not sure. In other words, this document is a bit like doing dot to dot. You join the dots (or fill in the blanks) but can you see the whole picture when you’re finished? Ok, not exactly what I want, but I keep it because it could be useful.</span></span></p>
<p class="MsoNormal"><span style="color: #000000;"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">I am aware that the NHS has a lot of data handling procedures and it computers hold a lot of personal data. No central, London based government department seems to have produced similar guidance. The NHS are good potential customer for our CCT Mark Certified service which we have just  formally submitted to CESG and the Cabinet Office office as our “<a title="Secure Destruction of Data on Hard Drives" href="http://www.cesg.gov.uk/">Secure Destruction of Data on Hard Drives and Magnetic Media v1.0</a>”!</span></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"><em>Based on diary entries from June 2008.</em><br />
</span>&lt;&#8211;&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/14/on-to-iso-27001-and-an-information-security-management-system/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Interpreting ISO 27001 Controls and Objectives for a Hard Disk Destruction Business</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/08/interpreting-iso-27001-controls-and-objectives-for-a-hard-disk-destruction-business/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/08/interpreting-iso-27001-controls-and-objectives-for-a-hard-disk-destruction-business/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 19:04:25 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[B. ISO 27001]]></category>

		<category><![CDATA[D. ISO 14001]]></category>

		<category><![CDATA[ISO9001 Quality Manual]]></category>

		<category><![CDATA[Info Sec Research]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=597</guid>
		<description><![CDATA[I continue working my way through the ISO 27001 Standard Document.  When I look at Appendix A, it appears I may be about to make a breakthrough in terms of understanding.  The title is Controls and Objectives.  For this first time this looks like a list of practical things one has to do to comply [...]]]></description>
			<content:encoded><![CDATA[<p>I continue working my way through the ISO 27001 Standard Document.  When I look at Appendix A, it appears I may be about to make a breakthrough in terms of understanding.  The title is Controls and Objectives.  For this first time this looks like a list of practical things one has to do to comply with the ISO 27001 Information Security standard.</p>
<p>For example, at A.5.1.1 is declares &#8220;An information security  policy document shall be approved by management, and published and communicated to all employees and relevant external parties.&#8221;  What this practically means is that at minimum I need find a model Information Security policy, insert my company&#8217;s name, sign it and stick it  up on the company website and wahey - route one compliance with A5.1.1!  To do things properly, I will have to tailor the policy to the specific requirements of a <a title="Secure Data Erasure" href="http://www.secure-data-destruction.co.uk/data_destruction.html">secure data erasure</a> company.    I am starting to understand what is practically being asked for by ISO 27001 the information security standard.</p>
<p>The next four controls up to A6.1.3 aren&#8217;t as easy  A5.1.1. but they could be met with a bit of thought and paperwork.  I turn the page and there are more controls.</p>
<p>A6.1.4 I says I need an authorization process for new information processing facilities.  I get this but how do it in a small organisation?  Does this mean mandatory testing process for any new bit of kit or software?  Would my company  have the resources for that?  Maybe it would just apply to <a title="Data Erasure Secure" href="http://www.secure-data-destruction.co.uk/data_destruction.html">secure data erasure software</a> or<a title="Hard Drive Destruction" href="http://www.secure-data-destruction.co.uk/"> hard drive destruction</a> equipment.</p>
<p>A6.1.5 talks about the need to have Confidentiality Agreements or NDAs in place which is fair enough and clearly understood.</p>
<p>A6.1.6   and A6.1.7 require the maintenance of contacts with authorities and special interest groups in security forums or specialist associations.  I don&#8217;t know what this means in practice though.  What kind of authorities are they talking about?  Does this means government, police or what?  Is one meant to have meetings with them?  I am also not part of any security related professional associations- and, if I was going to be, which ones should I try and be an member of?  And again what does &#8220;maintain contact&#8221; mean exactly?<a rel="attachment wp-att-599" href="http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/08/interpreting-iso-27001-controls-and-objectives-for-a-hard-disk-destruction-business/data_protection_act1/"><img class="alignright size-thumbnail wp-image-599" title="secure service for erasure of confidential data" src="http://www.secure-data-destruction.co.uk/images/Hard-Drive-Sanitisation .jpg" alt="secure service for erasure of confidential data" width="150" height="150" /></a></p>
<p>Having recently been spurred on by the appearance of my &#8220;Control of Documents and Records&#8221; friends I am now getting bogged down again.  I wonder what lies in the pages ahead.  So turn over and see more controls. I turn again and there are more.  And again - more.  I gulp - it feels like I am desperately reaching for air in the face of a massive wave of controls which is about to overwhelm me.</p>
<p>I turn the page 5 more times before I get to the end of the list of ISO 27001 Controls and Objectives - I am just looking at the page numbers now - closer focus is detrimental to my well-being.  The wave is right on top of me - what do I do to escape?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/08/interpreting-iso-27001-controls-and-objectives-for-a-hard-disk-destruction-business/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Understanding the ISO 27001 Standard Document Itself - Blurred Brain and an Old Friend</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/04/understanding-the-iso-27001-standard-document-itself-blurred-brain-and-an-old-friend/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/04/understanding-the-iso-27001-standard-document-itself-blurred-brain-and-an-old-friend/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 13:40:01 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[B. ISO 27001]]></category>

		<category><![CDATA[Standard Document 27001]]></category>

		<category><![CDATA[Standard Document 9001]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=593</guid>
		<description><![CDATA[I am now used to looking at the ISO 9001 Standard document itself.  The ISO 27001 Standard document I have  is 36 pages long as opposed to 20 pages for the ISO 9001 Standard.  We&#8217;ve got even more Plan, Do, Check, Act in the ISO 27001 document.  However, I soon suss out that the key [...]]]></description>
			<content:encoded><![CDATA[<p>I am now used to looking at the ISO 9001 Standard document itself.  The ISO 27001 Standard document I have  is 36 pages long as opposed to 20 pages for the ISO 9001 Standard.  We&#8217;ve got even more Plan, Do, Check, Act in the ISO 27001 document.  However, I soon suss out that the key bit we are looking at is Clause 4 onwards.</p>
<p>To start with Clause 4 is pretty similar to the corresponding clause in ISO 9001.  4.2.1a talks about the establishment of an Information Security policy suitable for the business and a scope.  Guess I can get my head around this.</p>
<p>4.2.1c is more problematic.  I am told to &#8220;define a risk assessment methodology for my organisation&#8221; and &#8220;develop criteria for accepting risks and identify the acceptable levels of risks&#8221;.  I just have limited concept of what is involved here.  This sounds like a job for McKinsey or Accenture but not me.  The ISO 27001 Standards says more information about Risk Assessment Methodologies  can be found in &#8220;ISO/IEC TR 13335- Guidelines for the management of IT Security = Techniques for the Management of IT Security&#8221;.   There is no way I am going to be a sucker for that document!  I&#8217;d rather disk by head in the<a title="Hard Disk Crusher" href="http://www.secure-data-destruction.co.uk/default.html"> hard disk</a> crusher!</p>
<p><a rel="attachment wp-att-594" href="http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/04/understanding-the-iso-27001-standard-document-itself-blurred-brain-and-an-old-friend/smallcruchedharddrive1/"><img class="alignright size-medium wp-image-594" title="smallcruchedharddrive1" src="http://www.secure-data-destruction.co.uk/iso27001blog/wp-content/uploads/2009/06/smallcruchedharddrive1-300x176.jpg" alt="smallcruchedharddrive1" width="300" height="176" /></a>I can feel myself sinking lower in the water and looking up at this massive wave towering above me made of long words, jargon and confusion.  Around this mix, there is an information security industry built which comprises lots of people who make money regurgitating long words which few outsiders understand.  Right now the wave is looking really big - and its about to swamp my enthusiasm - for today at least.</p>
<p>Back to the ISO 27001 Standard - when I have done a risk assessment, I then to treat the risks.  This involves &#8220;selecting control objectives and controls&#8221;.  What are those?   No idea.</p>
<p>Next I&#8217;ve got to prepare a Statement of Applicability in which must apparently  list my controls and my control objectives and give my reasons for selecting them.  My problem here is that I need an example of a Statement of Applicability - yes to see the PRACTICAL implementation of all this.   Information on which still can seemingly cannot be found anywhere.</p>
<p>My brain and vision are blurred by the time I turn over to page 6.  I am not reading every sentence just kind of prodding the content with the eyes to see how painful it might be.  But these bits, namely  4.2.2 through 4.3.1, are broadly familiar.  They are talking about implementing the ISMS , monitoring and reviewing it and maintaining it.</p>
<p>And blow me, over the page is my old friend &#8220;Control of Documents&#8221;.   And I am not being sarcastic - when you read him he might be one of the most boring friends I know but, right now ,I am really please to see him.  He&#8217;s hanging out with another buddy, &#8220;Control of Records&#8221;.  This is okay, I now understand now what these guys are about.</p>
<p>The next couple of pages aren&#8217;t so bad either - though I am skimming quite fast now - improvements to the system, preventative and corrective action etc.  I want to keep by <a title="Hard Disk Erasure" href="http://www.secure-data-destruction.co.uk/data_destruction.html">hard disk shredding</a> company as straightforward as possible. These could be called problems (Non Conformities), temporary fixes (Corrective Action) and Solutions (Preventative Action) could they not?  Life could be simpler if these people wanted it to be!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/04/04/understanding-the-iso-27001-standard-document-itself-blurred-brain-and-an-old-friend/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Creating a CONCISE Integrated Management System Manual for ISO 9001 and ISO 14001</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/28/creating-a-concise-integrated-management-system-manual-for-iso-9001-and-iso-14001/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/28/creating-a-concise-integrated-management-system-manual-for-iso-9001-and-iso-14001/#comments</comments>
		<pubDate>Sun, 28 Mar 2010 16:13:29 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[C. ISO 9001]]></category>

		<category><![CDATA[D. ISO 14001]]></category>

		<category><![CDATA[ISO9001 Quality Manual]]></category>

		<category><![CDATA[Manual 14001]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=561</guid>
		<description><![CDATA[My information sources for developing an ISO 14001 manual include:
•	A copy of the Standard itself (which arrived by email a couple of days ago)
•	My Arthur-shredded or approved Compact 9001 Manual
•	The Acorn Course Book which cost me £50
•	A Handout provided written by NQA, the UKAS approved system auditors,  but actually given to me by Adrian.
I [...]]]></description>
			<content:encoded><![CDATA[<p>My information sources for developing an ISO 14001 manual include:</p>
<p>•	A copy of the Standard itself (which arrived by email a couple of days ago)<br />
•	My Arthur-shredded or approved Compact 9001 Manual<br />
•	The <a title="Acorn BS855 Book" href="http://www.iema.net/shop/product_info.php?products_id=8810">Acorn Course Book </a>which cost me £50<br />
•	A Handout provided written by NQA, the UKAS approved system auditors,  but actually given to me by Adrian.</p>
<p>I begin by creating a complete stand alone ISO 14001 manual – even though I know there is going to be duplication between ISO 9001 and ISO 14001. This way might seem more long-winded but  I need to learn each standard one at time before I merge them.  Otherwise it gets too confusing and complicated.</p>
<p>Sovereign Certification provides a useful but wordy version of an <a title="ISO 14001 Manual" href="http://www.sovereigncertification.com/tier2/iso14001_guidance.htm">ISO 14001 manual</a>.  For<a title="Hard Drive Destruction" href="http://www.secure-data-destruction.co.uk/default.html"> Data Eliminate</a>&#8217;s version, I exclude from the first section of my ISO 14001 manual all Sovereign’s wording which is similar or equivalent to what Arthur deleted from my ISO 9001 manual.</p>
<p>I still find it hard to make sense of the “Interaction of Processes” – but I think its probably because is so simple I can’t understand it - if you know what I mean.   The examples of  Interaction of Processes charts I have are more concerned with the process of implementing the environmental standard (Plan, Do, Check, Act I suppose) rather than featuring specific Data Eliminate customer service processes.</p>
<p>I work out a number of things in order to  keep the ISO 14001 documentation to a minimum.  The first is that the six standard procedures required by ISO 14001 (Corrective Action, Preventative Action etc) are almost identical to those required for ISO 9001.  In addition, you need a  Training Needs Assessment Form to track training you believe your employees need to fill skill gaps.  To complement this, you need a  Training Record Form to record the details of the actual training.</p>
<p>When compared to the<a title="Data Eliminate Quality Policy" href="http://www.secure-data-destruction.co.uk/images/qp.PDF"> Quality Policy</a>, the <a title="Environmental Policy" href="http://www.secure-data-destruction.co.uk/images/ep.PDF">Environmental Policy</a> is different in focus but much the same in style.  As was the case with ISO 9001, thanks to Supply London I had a morning’s lesson in how to write a policy.  However, one could have used someone else’s and created one in a few minutes by making some very minor changes.</p>
<p>The we get onto the bits which are not part of ISO 9001 but which ISO 14001 requires.  These include:</p>
<p>•	An Environmental Aspects Register<br />
•	An Environmental Aspects Analysis<br />
•	A Register of Applicable Laws and Regulations<br />
•	A Risk Assessment Methodology</p>
<p>I also add some questions to the Supplier Questionnaire which is already part of my ISO 9001 manual and some items to the Management review Agenda.  The Environmental policy has to be on our web site with contact details for the manager responsible. We also need documented environmental objectives.</p>
<p>The first version of my Environmental Management System manual is 25 pages long – a lot more compact than my 53 page long ISO 9001 Quality Manual first starter  effort.</p>
<p>I then spend an hour or so removing the items from my ISO 14001 manual that are duplicated in my Arthur approved ISO 9001 manual.  After that the Environmental Manual is down to about 14 pages.</p>
<p>Things are coming together nicely.  ISO 9001 and ISO 1400 are integrated.  I will now need to merge ISO 27001 with them.</p>
<p>I contact Arthur to arrange another session.  This time I am going to get him to review my combined manual for ISO 9001 and ISO 14001.   I hope that I have pre-weeded it this time so that he doesn&#8217;t need to tear it apart or tell me I like detail.  If he does that again after all this effort it will take more than one flapjack in my mouth to keep me quiet!</p>
<p><em>Based on notes from my diary from June 2008.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/28/creating-a-concise-integrated-management-system-manual-for-iso-9001-and-iso-14001/feed/</wfw:commentRss>
		</item>
		<item>
		<title>My ISO 9001 Manual for Data Destruction is Partially Shredded</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/26/my-iso-9001-manual-for-data-destruction-is-partially-shredded-already/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/26/my-iso-9001-manual-for-data-destruction-is-partially-shredded-already/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 08:19:42 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[C. ISO 9001]]></category>

		<category><![CDATA[D. ISO 14001]]></category>

		<category><![CDATA[ISO9001 Quality Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=521</guid>
		<description><![CDATA[Today, Arthur the Supply London advisor comes to assess my draft ISO 9001 Manual. For mutual convenience, we arranged for him to come to my home.
 
I go up the road before Arthur’s meant to arrive to buy him a flapjack – all part of the PR offensive. I get back 15 minutes before he’s [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Today, Arthur the Supply London advisor comes to assess my draft ISO 9001 Manual.<span> </span>For mutual convenience, we arranged for him to come to my home.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">I go up the road before Arthur’s meant to arrive to buy him a flapjack – all part of the PR offensive.<span> </span>I get back 15 minutes before he’s meant to be there but he’s already standing outside the front door looking slightly irritated. He’s come from some way away. <span> </span>I say, “You’re early aren’t you? I just went up the road to buy you a flapjack.”<span> </span>He didn’t break into a grateful smile.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">He asks for a coffee.<span> </span>I only have instant coffee but he doesn’t seem to be phased.<span> </span>He enquires about Data Eliminate’s <a href="http://www.cctmark.gov.uk/CCTMAwards/CCTMDataEliminateLimited/tabid/111/Default.aspx">CCT Mark</a>.<span> </span>I explain that it was given to us by <a href="http://www.cesg.gov.uk/">CESG</a> and the <a href="http://www.cabinetoffice.gov.uk/csia.aspx">Cabinet Office</a>.<span> </span>He asks what CESG is.<span> </span>I explain that it’s the Information Assurance arm of the Cabinet Office.<span> </span>He nods but I am not sure he is any the wiser.<span> </span>Perhaps I haven’t explained it properly.<span> </span>Perhaps I am turning into an information security head and losing my ability to communicate with normal mortals.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">I put my 53 page pile in front of him and ask him to review the information. <span> </span>He flicks through the document and confirms that we are destroying data on <a title="hard disks and data tapes" href="http://www.secure-data-destruction.co.uk/CCTM.html">hard disks and data tapes</a> and then recycling them in line with the WEEE Directive? <span> </span>I nod.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">My manual is divided into four sections. Below is the outcome of Arthur’s assessment of the first of its four sections point by point:</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<table class="MsoNormalTable" style="border: medium none; border-collapse: collapse;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="border: 1pt solid black; padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Section   Title</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Arthur’s   Assessment</span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">1.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Introduction</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">1.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Organisation Description</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">ok</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">1.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Scope of Certification</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">ok</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">1.3</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Third Party Certification</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">ok</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">2.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Responsibilities</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">2.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Office Based Personnel</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">2.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Site Based Personnel</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">3.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Business   Processes</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">3.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Description</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">3.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Implementation &amp; Maintenance</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">4.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Quality   Management System</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">4.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">General Requirement</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">4.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Documentation Requirements</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Management   Responsibility</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Management Commitment</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Customer Focus</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.3</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Quality Policy</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.4</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Planning</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.5</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Responsibility, Authority and   Communication</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">5.6</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Management Review</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">“Is this good or is this bad?”<span> </span>I am wondering.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Arthur interrupts, ”Julian you really like details don’t you!”<span> </span></span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">I don’t. I really, really hate detail.<span> </span>If he read my blog he wouldn’t say this.<span> </span>But I maintain my composure because I know that although Arthur is effectively shredding almost half my work, he is helping me a lot.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">So that I don’t speak, I reach forward for a flap jack and take an enormous bite out of it which completely fills my mouth.<span> </span>I begin to chew.<span> </span>Arthur continues through the next section.<span> </span>He starts to talk about the Data Protection Act or something but doesn’t finish his point.<span> </span>He continues his review:</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<table class="MsoNormalTable" style="border: medium none; border-collapse: collapse;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="border: 1pt solid black; padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Section   Title</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Arthur’s   Assessment</span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">6.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Resources</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">6.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Provision of Resources</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">6.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Human Resources</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">6.3</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Infrastructure</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">6.4</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Work Environment</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Product   Realisation</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Planning of Product Realisation</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Customer Related Processes</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.3</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Design and Development</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.4 </span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Purchasing</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Ok – some amendment needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.5</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Production and Service Provision</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">7.6 </span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Control of monitoring and measuring   devices</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">8.0</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Measurement,   Analysis and Improvement</span></strong></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><strong><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></strong></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">8.1</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">General</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">8.2</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Monitoring and Measurement</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">8.3</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Control of nonconforming product</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">8.4</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Analysis of data</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; width: 32.9pt;" width="44" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">8.5</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 226.15pt;" width="302" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Improvement</span></p>
</td>
<td style="padding: 0cm 5.4pt; width: 219.75pt;" width="293" valign="top">
<p class="MsoNoSpacing"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Not needed</span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">He hasn’t touched his flapjack.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">“So many people think their manual has to repeat what the Standard says,” he exclaims “you don’t need to do it!”</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Arthur is more impressed by the rest of the content. A lot of it he says though is just repeating the standard again.<span> </span>He also says that when the manual is applied in practice that it will make things more straightforward.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">He excuses himself.<span> </span>He leaves the room with me smarting from the “Julian=detail” accusation.<span> </span>I exact revenge by demolishing his flapjack too.<span> </span></span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">The contrast between the ultra-wordy material I have waded through on ISO standards and information security and Arthur’s approach is marked.<span> </span>Perhaps this is one of those few cases where its better to have less information!</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"><span> </span>I am still chewing intensively when he returns.<span> </span>He is not phased.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">Ironically, Arther has shredded last part of my ISO Manaual for a <a title="Data Destruction" href="http://www.secure-data-destruction.co.uk/default.html">secure data destruction</a> or <a title="Hard Drive Destruction" href="http://www.secure-data-destruction.co.uk/data_destruction.html">hard drive shredding</a> business!  However, in sum Arthur approves of the stuff I have originated myself.<span> </span>Where I have text dumps, he says they are too wordy.<span> </span></span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">I will take on board most of what he says but I am aware that different experts/auditors on these Standards are likely to have different views of these things.<span> </span>For example, if they come from an information security background they might have a different view to Arthur’s.</span></p>
<p class="MsoNoSpacing"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"> </span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;">So far so good then with ISO 9001.<span> </span>I&#8217;ll need to do the same with  ISO 14001 down to a similar minimum.</span></p>
<p class="MsoNormal"><span style="font-size: 10pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; color: #1f497d;"><em>Based on notes from my diary from June 2008.</em><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/26/my-iso-9001-manual-for-data-destruction-is-partially-shredded-already/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Finding A Copy of ISO 27001- The Standard Itself</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/18/finding-a-copy-of-iso-27001-information-technology-%e2%80%93-security-techniques-%e2%80%93-information-security-management-systems-%e2%80%93-the-standard-itself/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/18/finding-a-copy-of-iso-27001-information-technology-%e2%80%93-security-techniques-%e2%80%93-information-security-management-systems-%e2%80%93-the-standard-itself/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 10:20:53 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[A. Overall IMS Strategy]]></category>

		<category><![CDATA[B. ISO 27001]]></category>

		<category><![CDATA[General Research]]></category>

		<category><![CDATA[HR Security]]></category>

		<category><![CDATA[ISO9001 Quality Manual]]></category>

		<category><![CDATA[Public Sector Issues]]></category>

		<category><![CDATA[Standard Document 27001]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=513</guid>
		<description><![CDATA[I spend a while  looking for a copy of ISO 27001 on the internet and just when I think I have wasted a my time,  I strike gold.  On result 26 of the fourth Google search, a copy of ISO 27001 – all 34 pages of it! 
 

The security rubric on [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">I spend a while <span> </span>looking for a copy of ISO 27001 on the internet and just when I think I have wasted a my time, <span> </span>I strike gold.<span> </span><span> </span>On result 26 of the fourth Google search,<span> </span>a copy of ISO 27001 – all 34 pages of it!<span> </span></span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNormal">
<div id="attachment_585" class="wp-caption alignright" style="width: 160px"><a href="http://www.secure-data-destruction.co.uk/data_destruction.html"><img class="size-thumbnail wp-image-585" title="bg_header_p21" src="http://www.secure-data-destruction.co.uk/iso27001blog/wp-content/uploads/2009/05/bg_header_p21-150x150.jpg" alt="Items containing computer hard drives" width="150" height="150" /></a><p class="wp-caption-text">Items containing computer hard drives</p></div>
<p>The security rubric on the document has the words “Uncontrolled Copy” on it.<span> </span>“You can say that again,” I think.<span> </span>It was available as a download off some German student’s website in a directory which was full of photos and videos and other stuff.<span> </span>That’s pretty uncontrolled!</p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">I know when I sit down to read it that understanding it is going to be a challenge <span> </span>(judging from my ISO 9001 experience), but at least I have got <span> </span>a copy.<span> </span>Nice one!</span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">I then email a contact that I have met at the Supply London<span> </span>seminars I have been to recently and ask her for a copy of ISO 14001 which she said she had.<span> </span>She says she will be able to oblige but I might have to wait a while.<span> </span>The point is that I’ve got so much work to do on ISO 27001,<span> </span>I am very happy to wait a while  for for a copy of the ISO 14001 Standard!</span></p>
<p class="MsoNoSpacing">
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"><em>Based on notes from my diary in June 2008.</em><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/18/finding-a-copy-of-iso-27001-information-technology-%e2%80%93-security-techniques-%e2%80%93-information-security-management-systems-%e2%80%93-the-standard-itself/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Market Comment - Making ISO 27001 More Accessible and Understandable</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/17/market-comment-making-iso-27001-more-accessible-and-understandable/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/17/market-comment-making-iso-27001-more-accessible-and-understandable/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 13:01:08 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[E. Market Comment]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=555</guid>
		<description><![CDATA[Stuart King makes a good point about ISO 27001 providing the basis of public sector information security.  The public sector oil tanker knows where it is heading but it is still very much in the process of making its turn.  Being the public sector there may be deviations and hazards on route.There is, in my opinion, very much a disconnect at present between talk at the policy maker level in government and actions at the local authority or county court house level. ]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span lang="EN-GB">Stuart King makes a good point about <a href="http://www.computerweekly.com/blogs/stuart_king/2009/02/public-sector-vs-private-secto-1.html">ISO 27001 providing the basis of public sector information security</a>.<span> </span>The public sector oil tanker knows where it is heading but it is still very much in the process of making its turn.<span> </span>Being the public sector there may be deviations and hazards on route.</span></p>
<p class="MsoNormal"><span lang="EN-GB"> </span></p>
<p class="MsoNormal"><span lang="EN-GB">There is, in my opinion, very much a disconnect at present between talk at the policy maker level in government and actions at the local authority or county court house level. <span> </span>Platform speakers at the CIPCOG conference in York in February essentially confirmed a new age of information security focus had arrived.<span> </span>However, our <a title="Data destruction sales team" href="http://www.secure-data-destruction.co.uk/default.html">data destruction</a> sales team regularly finds that knowledge and demand at the purchasing coalface within the public sector is poor and way behind where the policy makers would have you believe it is.</span></p>
<p class="MsoNormal"><span lang="EN-GB"> </span></p>
<p class="MsoNormal"><span lang="EN-GB">This is partly caused by the fact that information security is not seen as an enabler by civil servants.<span> </span>New rules mean they can no longer put files onto their memory stick so they can work from home for example.<span> </span>Take-up of information security measures will be enforced rather than spontaneous or voluntary.</span></p>
<p class="MsoNormal"><span lang="EN-GB"> </span></p>
<p class="MsoNormal"><span lang="EN-GB">Likewise, take up in the private sector will be driven by government requirements placed on larger Tier 1 providers and there will be a trickle down effect in the private sector.<span> </span>Suppliers further down the food chain will eventually have to comply and implement information security themselves.<span> </span>If they do that presently, they will find it a real challenge due to the lack of straightforward and concise guidance available on ISO 27001.</span></p>
<p class="MsoNormal"><span lang="EN-GB"> </span></p>
<p class="MsoNormal"><span lang="EN-GB">I hope that <a href="http://www.secure-data-destruction.co.uk/iso27001blog/">this blog</a> will play a part in filling that gap by making ISO 27001 more accessible and understandable.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/17/market-comment-making-iso-27001-more-accessible-and-understandable/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Supply London Workshops on Environmental Policy and Winning Public Sector Contracts Contract</title>
		<link>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/15/supply-london-workshops-on-environmental-policy-and-winning-public-sector-contracts-contract/</link>
		<comments>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/15/supply-london-workshops-on-environmental-policy-and-winning-public-sector-contracts-contract/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 08:43:42 +0000</pubDate>
		<dc:creator>Julian Fraser</dc:creator>
		
		<category><![CDATA[A. Overall IMS Strategy]]></category>

		<category><![CDATA[General Research]]></category>

		<category><![CDATA[Public Sector Issues]]></category>

		<category><![CDATA[The 27001 Manual]]></category>

		<guid isPermaLink="false">http://www.secure-data-destruction.co.uk/iso27001blog/?p=506</guid>
		<description><![CDATA[In the last three days I have been to two Supply London  workshops. 
 
The first was the Environmental Workshop. This was a real basic level course aimed at getting you to think about the environmental aspects of your business. I feel good when I understand where it fits into the overall ISO 14001 [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #1f497d;" lang="EN-GB">In the last three days I have been to two Supply London <span> </span>workshops.<span> </span></span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">The first was the Environmental Workshop. This was a real basic level course aimed at getting you to think about the environmental aspects of your business.<span> </span>I feel good when I understand where it fits into the overall ISO 14001 accreditation process.<span> </span>It only covers the very early part of the Acorn book. <span> </span>Including the book, I am now in <span> </span>possession of a significant amount of information on ISO 14001 which I have accrued by my own research and feel I understand what is required.</p>
<div id="attachment_590" class="wp-caption alignright" style="width: 108px"><a href="http://www.secure-data-destruction.co.uk/CCTM.html"><img class="size-full wp-image-590" title="weee_recycling" src="http://www.secure-data-destruction.co.uk/iso27001blog/wp-content/uploads/2009/05/weee_recycling.jpg" alt="Computer media including data tapes must be properly recycled." width="98" height="83" /></a><p class="wp-caption-text">Computer media including data tapes must be properly recycled.</p></div>
<p></span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">The second Supply London event I attended is about Wining Public Sector Business. <span> </span>Its the third out of the four free courses I get from Supply London and I have been told by other delegates who have already done this one that this is the best course.  (None of these provide <a title="Hard Disk Erasure Services" href="http://www.secure-data-destruction.co.uk/default.html">hard disk destruction services</a>.)<span> </span></span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">Things get underway at about 930 and go through until about 3.<span> </span>This is the first course that we don’t spend the day thinking about policies and being introduced to real common denominator level concepts.<span> </span>Most of the slides/talk was about material I didn’t know.</span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">We are given lots of really useful information including a great 58 page printed A4 booklet.<span> </span>At the back was a list of London councils and the way they took quotes and tenders for different values of contracts from the small under £5k, to the biggies over £144k which apparently have to be offered to all EU companies under some directive.<span> </span></span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">The course explained what councils typically look for in supplier.<span> </span>The basic is that they have the right balance of skills and experience.<span> </span>Companies are unlikely to win a contract which is worth more than a quarter of their existing turnover.<span> </span><a title="Supply London" href="http://www.supplylondon.com/">Supply London</a> gave a check list to measure one’s fitness to supply.</span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB"> </span></p>
<p class="MsoNoSpacing"><span style="color: #1f497d;" lang="EN-GB">This course just confirms the importance of the ISOs and why they have to be tackled.<span> </span>I made sure I took a second copy of the course material from the empty seat next to me.<span> </span>In 17 years of running and being involved in businesses this is the most useful free handout or course I have had from the government.<span> </span>I can’t believe I am saying this considering the grief government generally causes business!</span></p>
<p class="MsoNoSpacing"><em>Based on notes from my diary from June 2008.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secure-data-destruction.co.uk/iso27001blog/index.php/2010/03/15/supply-london-workshops-on-environmental-policy-and-winning-public-sector-contracts-contract/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
