By now most people are aware that ISO 9001 is in the process of being revised, with a planned release date of some time in 2015. Reactions from users range from mild curiosity to excitement to extreme trepidation. Continue reading
#21 – RISK BASED AUDITING – KEITH RIDGEWAY
Today’s business world is constantly changing—it’s unpredictable, volatile, and becoming more and more complex every day. By its very nature, it is fraught with risk.
Businesses have always looked at risk as a necessary evil that should be controlled, minimised or mitigated whenever possible. Continue reading
#21 – WHITE HOUSE INCENTIVES FOR CIP CYBER ADOPTION – CAROLYN TURBYFILL
It has been a busy year in the U.S. for Cybersecurity. The latest development (as of August 6, 2013) is an announcement from the White House outlining incentives under consideration to encourage Critical Infrastructure companies to implement the Cybersecurity Framework under development by NIST: Continue reading
#21 – RISK VERSUS PROCESS BASED AUDITS – UMBERTO TUNESI
James Lamprecht’s preliminary ISO 9001:2015 comments published on # 20 CERM Risk Insights Magazine catalyzes thinking, last but not least on requirement 9.2, internal audit.
Certainly this ISO 9001 supporting process is going to be more challenging; but it will become more subjectively-controlled, too, therefore open to endless – and useless – comparisons based on the very human principle “I’m better than you”. Continue reading
#21 – THE PROCESS OF RISK MANAGEMENT – LINDA WESTFALL
Risk management is an ongoing process that should be implemented as part of the initial planning activities for our projects, product, and processes. Risk management must also be an ongoing part of managing those projects, product, and processes. The purpose of risk management is to identify and analyze potential problems (risks) before they turn into actual problems so that we can: Continue reading
