BCCManagement.com Highlights the BSI BS25999 CERTIFICATION PROCESS
TAKING THE NEXT STEP:
ACCORDING TO BSI-GLOBAL
Initial Assessment
Stage 1
The following aspects will be covered:
Review of the organization’s BCMS documentation
High level evaluation of the organization’s readiness
Stage 2 assessment Review the organization’s understanding of the
requirements of the standard Understanding of the proposed scope of the stage 2 assessment
Review and confirm the resources needed for the stage 2 assessment
Plan the stage 2 assessment
Ensure that Management Reviews and audit/self assessments are being planned and performed Any areas deemed not in compliance will be raised as nonconformities and must be cleared and approved by the
lead auditor prior to moving into the Stage 2 phase of the
certification audit.
Stage 2
The purpose of the stage 2 audit is to evaluate the
implementation, including effectiveness, of the
organization’s BCMS.
This phase is carried out using the process audit approach.
Unlike a checklist approach, the audit approach assesses
all processes included in the scope of operation and all linked
processes to ensure effectiveness and consistency. This will
include interviews with the stakeholders, gathering of
objective evidence (procedures, reports and test results)
and evaluating those findings against the standard.
Any areas deemed not in compliance and/or effective will
be raised as nonconformities and must be cleared and
approved by the lead auditor prior to being recommended
for certification.
Surveillance Audit
The first surveillance visit is typically planned to take place
yearly after the date of the stage 2 audit.
BSI will perform periodic monitoring audits of the certified
organization’s BCMS. Typically, an organization may be
visited for such an audit once a year. The purpose of these
monitoring audits is to verify the certified organization’s
continued compliance with certification requirements.
Surveillance audits typically cover critical activities that ensure
continuous improvement and effectiveness such as:
Management review and audits/self assessments
Review of actions taken on nonconformities from previous audits
Effectiveness of the BCMS
Progress of planned activities aimed at continual improvement
Verifying the effective interaction among all BCMS elements
Continuing operational control
Review of any changes
Use of marks and any other reference to certification
Verifying a demonstrated commitment by the organization
to maintaining the BCMS effectiveness
Reassessment
The purpose of the reassessment audit is to confirm the
continued conformity and effectiveness of the BCMS and
its continued relevance and applicability for the scope of
certification. The reassessment audit will typically include
the following aspects:
The effectiveness of the BCMS in its entirety in the light of
internal and external changes and applicability to the
scope of certification.
Demonstrated commitment to maintain the effectiveness
and improvement of the BCMS in order to enhance overall
performance.
Whether the operation of the certified BCMS contributes to
the achievement of the organizations policy and objectives.
All steps noted are typical accepted practice based on ISO 17021
and subject to revision at anytime.
Any areas deemed not in
compliance and/or effective will
be raised as nonconformities and
must be cleared and approved by
the lead auditor prior to being
recommended for certification.
BSI Management Systems How to deploy BS 25999
CONCLUSIONS
BS 25999 establishes the processes, principles and
terminology to address business continuity and availability
risk. It also provides a comprehensive set of controls based on
industry leading practices that help organizations develop,
implement, maintain and mature business continuity
processes. The standard can be used as a framework so that
those organizations without a BCMS can efficiently establish
a workable program, and those that already have a program
can ensure it meets best practices where applicable.
The growing consensus regarding BS 25999, combined with
the opportunity to become certified in its use, provides
unparalleled benefits to companies of all sizes whose
customers rely on their products and services
Reference:
BSI Global
0 responses so far ↓
There are no comments yet...Kick things off by filling out the form below.