ISO/IEC 27001:2005 Information technology -- Security techniques -- Specification for an Information Security Management System
The standard covers all types of organizations (e.g. commercial enterprises, government agencies and non-profit organizations). It specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented ISMS within the context of the organization's overall risk management processes. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. It does not mandate specific information security controls.
The standard defines its 'process approach' as "The application of a system of processes within an organization, together with the identification and interactions of these processes, and their management". It employs the PDCA, Plan-Do-Check-Act model to structure the processes.
ISO/IEC 20000 is the first worldwide standard specifically aimed at IT Service Management. It describes an integrated set of management processes for the effective delivery of services to the business and its customers.
ISO/IEC 20000-1:2005 is the formal Specification and defines the requirements for an organisation to deliver managed services of an acceptable quality for its customers. The scope includes:
Requirements for a management system;
Planning and implementing service management;
Planning and implementing new or changed services;
Service delivery process;
Relationship processes;
Resolution processes;
Control processes; and
Release processes.
ISO/IEC 20000-1:2005 defines the requirements for a service provider to deliver managed services. It is based on BS 15000-2, which has been superseded.
It may be used
1. by businesses that are going out to tender for their services;
2. to provide a consistent approach by all service providers in a supply chain;
3. to benchmark IT service management;
4. as the basis for an independent assessment;
5. to demonstrate the ability to meet customer requirements;
6. to improve services
ISO/IEC 20000-1:2005 promotes the adoption of an integrated process approach to effectively deliver managed services to meet business and customer requirements
ISO 13485:2003 specifies requirements for a quality management system where an organization needs to demonstrate its ability to provide medical devices and related services that consistently meet customer requirements and regulatory requirements applicable to medical devices and related services.
The primary objective of ISO 13485:2003 is to facilitate harmonized medical device regulatory requirements for quality management systems. As a result, it includes some particular requirements for medical devices and excludes some of the requirements of ISO 9001 that are not appropriate as regulatory requirements. Because of these exclusions, organizations whose quality management systems conform to this International Standard cannot claim conformity to ISO 9001 unless their quality management systems conform to all the requirements of ISO 9001
All requirements of ISO 13485:2003 are specific to organizations providing medical devices, regardless of the type or size of the organization.
ISO/TS 16949:2002 is a common automotive quality system requirements catalog based on the ISO 9001:2008, AVSQ (Italian), EAQF (French), QS-9000 (American), and VDA 6.1 (German) standards. The aim of ISO/TS16949 is the development of a quality Managements system that provides for continual improvement, emphasizing defect prevention and the reduction of variation and waste in the supply chain. TS16949 applies to the design/development, production and, when relevant, installation and servicing of automotive-related products. It is based on ISO9000.
ISO/TS 16949:2002 was prepared by International Automotive Task Force (IATF) and Japan Automobile Manufacturers Assosiation Inc (JAMA),with support from ISO/TC 176, Quality Management and Quality Assurance.
ISO/TS16949 = ISO 9001:2008 requirement + Automotive Requirement + Customer Specific Requirement
The Organization that already implemented ISO9001:2008 can upgrade to ISO/TS16949:2002
Helpline 24/7days
9213283599