#27 – ISO 31000 SECURITY RISK MANAGEMENT – INGE VANDIJCK

INGE 2The biggest challenge for security managers is to demonstrate the value added of security.  It is not an easy task for risk management to argue the return on security investment (ROSI), but it is certainly not a mission impossible.

In many organizations with a lower maturity in security risk management the link between investment in security and the value added is not sufficiently explained and justified.  Costs for security are therefore regarded as a necessary evil, mainly to meet legal obligations. In more mature organizations the link between security and the value added are well understood, therefore investments in security are related to the protection of value already created within the organization. Continue reading

#27 – AUDIT MY PROCESS PLEASE! – T. DAN NELSON

T. Dan Nelson - Screen Shot 2013-09-06 at 8.16.28 PM

Sometime after the release of ISO 9001:2000, a shortcoming of ISO 9001 auditing became clear: certifying body (CB) auditors were often using a standard-based approach to auditing. Auditors would arrive at an audit client’s worksite armed with a copy of ISO 9001 as a stage 2 audit checklist.  This appeared to allow inconsistent application of the requirements.

Since the 2000 standard only reputedly required six procedures, stage 1 document review consisted of reviewing an organization’s 6 procedures against requirements contained in the 6 ISO 9001 clauses calling for documented procedures. This same mind-set is a carry-over from the 1987/1994 idea of auditing.  Then, document review consisted of reviewing an organization’s 20 procedures against the 20 elements calling for documented procedures; stage 2 auditing consisted of assessing working practice against procedures responding to ISO 9001 requirements. Continue reading

#27 – NEW NORMAL OF SUPPLY RISK MANAGEMENT – GREG HUTCHINS

Greg Hutchins pixWall Street Journal journalist wrote the following in a front-page article a few years ago:

“Purchasing managers play a role as highly effective cost cutters, though that part of their job has some surprising nuance.  To be sure, buyers save companies huge amounts by trolling the world for new, lower-cost sources, and this is certainly a big reason for their growing stature at many multinationals.  But in an era of scarce commodities and the risks of disruptions to supply lines posed by terrorist attacks or striking dockworkers, they also have to make sure they pick dependable sources – which might mean choosing the more expensive sources just to assure no disruptions.  Nothing is worse for a buyer’s reputation than to throw business to a lowball supplier who has trouble delivering.”[i] Continue reading

#26 – WHY HIRING MANAGERS DON’T HIRE YOU! – ELIZABETH LIONS

Elizabeth Lions PixThere is a definite behavioral pattern with managers in hiring.   Some are easy to work with, decisive and know their leadership style – well.   Asking them what they look for in talent is a concise and illuminating discussion.

However, not all hiring managers respond in this way.

Continue reading

#26 – POOR RELIABILITY: A RISK TO PRODUCTION – JOHN AYERS

John Ayers pixReliability is designed into a product.  Quality is built into a product.  Poor reliability is long term, difficult and expensive to rectify because it is woven into the fabric of the product.

Quality is a relative short term problem because once the badly written procedure, non-compliant material or poor workmanship is identified, it usually can be fixed relatively quickly with minimal impact to the program. Continue reading