Managing ISO Documentation – A Plain English Guide: A Step-by-Step Handbook for ISO Practitioners in Small Businesses
3.5/5
()
About this ebook
In this book, Dejan Kosutic, author and experienced ISO consultant, is giving away his practical know-how on managing policies, procedures, plans, forms, reports, and other documented information. No matter if you are new or experienced in the field, this book gives you everything you will ever need to learn on how to handle ISO 9001, ISO 14001, ISO 27001, ISO 22301, ISO 20000, ISO 22000, OHSAS 18001, ISO 13485, AS9100, and IATF 16949 documents.
Many ISO practitioners are often disappointed with the quantity and complexity of the documentation. You can frequently hear:
- “We don’t need these documents – we’re doing just fine without them; this would only be overkill.”
- “This standard is all about documentation – we simply need to fill out all the documents, and we’ll automatically get the certificate.”
- “We need to write policies and procedures for each and every process, activity, and control in our company – the more documents, the clearer the rules will be, and it will be easier for us to comply.”
This book is here to prove these statements wrong. As Kosutic says: “The main point of the implementation of any standard is that the employees perform their activities and processes in a better way, and the documentation is here to help you do that, because otherwise, their processes and activities would become unmanageable.”
Managing ISO Documentation: A Plain English Guide is a step-by-step guide that will explain the sequence of writing the documentation and its relationship with the PDCA cycle, how to decide on your documentation strategy, how to decide which policies and procedures to write, and what might be the most crucial part – how to write documentation that will be accepted by your employees.
Written in easy-to-understand language, whether you’re an experienced practitioner or new to the field, Managing ISO Documentation: A Plain English Guide is the only book you’ll ever need on the subject.
Other titles in Managing ISO Documentation – A Plain English Guide Series (6)
ISO 27001 Risk Management in Plain English: A Step-by-Step Handbook for Information Security Practitioners in Small Businesses Rating: 4 out of 5 stars4/5
Read more from Dejan Kosutic
Related to Managing ISO Documentation – A Plain English Guide
Related ebooks
Implementing an Integrated Management System (IMS): The strategic approach Rating: 5 out of 5 stars5/5ISO 14001 Step by Step - A practical guide: Second edition Rating: 5 out of 5 stars5/5ISO 27001 Complete Self-Assessment Guide Rating: 0 out of 5 stars0 ratingsThe ISO 14001:2015 Companion: A Straightforward Guide to Implementing an EMS in a Small Business Rating: 5 out of 5 stars5/5ISO 37001: An Introduction to Anti-Bribery Management Systems Rating: 0 out of 5 stars0 ratingsISO/IEC 20000: An Introduction to the global standard for service management Rating: 0 out of 5 stars0 ratingsISO/IEC 27701:2019: An introduction to privacy information management Rating: 4 out of 5 stars4/5Compliance Management: How Organizations Achieve the Highest Level of Business Integrity Rating: 0 out of 5 stars0 ratingsISO 22301: 2019 - An introduction to a business continuity management system (BCMS) Rating: 4 out of 5 stars4/5ISO 27001/ISO 27002: A guide to information security management systems Rating: 0 out of 5 stars0 ratingsThe Executive’S Guide to Internal Auditing Rating: 0 out of 5 stars0 ratingsThe Business Continuity Management Desk Reference Rating: 0 out of 5 stars0 ratingsBusiness Continuity Management A Complete Guide - 2020 Edition Rating: 0 out of 5 stars0 ratingsEnterprise Risk Management: A Practical Guide to Quick Start Rating: 0 out of 5 stars0 ratingsISO 55000: A Layman's Guide Rating: 0 out of 5 stars0 ratingsImplementing Service Quality based on ISO/IEC 20000: A Management Guide Rating: 4 out of 5 stars4/5ISO IEC 27006 The Ultimate Step-By-Step Guide Rating: 0 out of 5 stars0 ratingsNine Steps to Success: An ISO27001:2013 Implementation Overview Rating: 1 out of 5 stars1/5ISO 9001:2015: A Pocket Guide Rating: 4 out of 5 stars4/5Discover ISO 9001:2015 Through Practical Examples: A Straightforward Way to Adapt a QMS to Your Own Business Rating: 5 out of 5 stars5/5Quality Management Iso9001:2015 Changes: A Guide to Implementation Rating: 5 out of 5 stars5/5Iso 9001:2015 into the Future Rating: 0 out of 5 stars0 ratings
Business For You
Becoming Bulletproof: Protect Yourself, Read People, Influence Situations, and Live Fearlessly Rating: 4 out of 5 stars4/5Company Rules: Or Everything I Know About Business I Learned from the CIA Rating: 4 out of 5 stars4/5Collaborating with the Enemy: How to Work with People You Don't Agree with or Like or Trust Rating: 4 out of 5 stars4/5The Richest Man in Babylon: The most inspiring book on wealth ever written Rating: 4 out of 5 stars4/5Emotional Intelligence: Exploring the Most Powerful Intelligence Ever Discovered Rating: 4 out of 5 stars4/5The Art Of Critical Thinking: How To Build The Sharpest Reasoning Possible For Yourself Rating: 4 out of 5 stars4/5The Five Dysfunctions of a Team: A Leadership Fable, 20th Anniversary Edition Rating: 4 out of 5 stars4/5Your Next Five Moves: Master the Art of Business Strategy Rating: 5 out of 5 stars5/5Super Learning: Advanced Strategies for Quicker Comprehension, Greater Retention, and Systematic Expertise Rating: 4 out of 5 stars4/5The Book of Beautiful Questions: The Powerful Questions That Will Help You Decide, Create, Connect, and Lead Rating: 4 out of 5 stars4/5The ChatGPT Millionaire Handbook: Make Money Online With the Power of AI Technology Rating: 4 out of 5 stars4/5Capitalism and Freedom Rating: 4 out of 5 stars4/5How to Get Ideas Rating: 4 out of 5 stars4/5Strategy Skills: Techniques to Sharpen the Mind of the Strategist Rating: 4 out of 5 stars4/5Set for Life, Revised Edition: An All-Out Approach to Early Financial Freedom Rating: 4 out of 5 stars4/5Financial Words You Should Know: Over 1,000 Essential Investment, Accounting, Real Estate, and Tax Words Rating: 4 out of 5 stars4/5The Catalyst: How to Change Anyone's Mind Rating: 4 out of 5 stars4/5High Conflict: Why We Get Trapped and How We Get Out Rating: 4 out of 5 stars4/5
Reviews for Managing ISO Documentation – A Plain English Guide
3 ratings0 reviews
Book preview
Managing ISO Documentation – A Plain English Guide - Dejan Kosutic
Managing ISO Documentation:
A Plain English Guide
Also by Dejan Kosutic:
9 Steps to Cybersecurity: The Manager’s Information Security Strategy Manual
Becoming Resilient: The Definitive Guide to ISO 22301 Implementation
ISO 27001 Risk Management in Plain English
ISO 27001 Annex A Controls in Plain English
Preparing for ISO Certification Audit: A Plain English Guide
Dejan Kosutic
Managing ISO Documentation:
A Plain English Guide
A Step-by-Step Handbook for ISO Practitioners in Small Businesses
Advisera Expert Solutions Ltd
Zagreb, Croatia
Copyright ©2017 by Dejan Kosutic
All rights reserved. No part of this book may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording or otherwise, without written permission from the author, except for the inclusion of brief quotations in a review.
Limit of Liability / Disclaimer of Warranty: While the publisher and author have used their best efforts in preparing this book, they make no representation or warranties with respect to the accuracy or completeness of the contents of this book and specifically disclaim any implied warranties of merchantability or fitness for a particular purpose. This book does not contain all information available on the subject. This book has not been created to be specific to any individual’s or organization’s situation or needs. You should consult with a professional where appropriate. The author and publisher shall have no liability or responsibility to any person or entity regarding any loss or damage incurred, or alleged to have been incurred, directly or indirectly, by the information contained in this book.
First published by Advisera Expert Solutions Ltd
Zavizanska 12, 10000 Zagreb
Croatia
European Union
http://advisera.com/
ISBN: 978-953-8155-01-7
First Edition, 2017
ABOUT THE AUTHOR
img1.jpgDejan Kosutic is the author of numerous articles, video tutorials, documentation templates, webinars, and courses about ISO 27001, ISO 22301 and other ISO standards. He is the author of the leading ISO 27001 & ISO 22301 Blog, and has helped various organizations including financial institutions, government agencies, and IT companies implement information security management according to these standards. He holds numerous certificates, among them ISO 27001 Lead Auditor and ISO 9001 Lead Auditor.
Click here to see his LinkedIn profile
TABLE OF CONTENTS
ABOUT THE AUTHOR
PREFACE
1 INTRODUCTION
1.1 WHY IS DOCUMENTATION IMPORTANT FOR ISO MANAGEMENT SYSTEMS?
1.2 WHO SHOULD READ THIS BOOK?
1.3 HOW TO READ THIS BOOK?
1.4 WHAT THIS BOOK IS NOT
1.5 ADDITIONAL RESOURCES
2 PREPARING TO WRITE THE DOCUMENTS
2.1 THREE OPTIONS FOR IMPLEMENTING THE STANDARD AND WRITING THE DOCUMENTATION
2.2 SEQUENCE OF WRITING THE DOCUMENTATION & RELATIONSHIP WITH PDCA CYCLE
2.3 USING TOOLS AND TEMPLATES
2.4 DECIDE ON YOUR DOCUMENTATION STRATEGY
2.5 SUCCESS FACTORS
3 HANDLING YOUR DOCUMENTS IN A MANAGEMENT SYSTEM
3.1 CONTROL OF DOCUMENTS (CLAUSE 7.5)
3.2 CONTROL OF RECORDS (CLAUSE 7.5)
3.3 BEST PRACTICES FOR DOCUMENTING ROLES AND RESPONSIBILITIES (CLAUSE 5.3)
3.4 DECIDING WHICH POLICIES AND PROCEDURES TO WRITE
3.5 WHERE TO START WITH PARTICULAR DOCUMENTS
3.6 WRITING DOCUMENTATION THAT WILL BE ACCEPTED BY THE EMPLOYEES
3.7 MAINTENANCE OF THE DOCUMENTATION (CLAUSE 7.5)
3.8 SUCCESS FACTORS
4 MINI CASE STUDY: WRITING THE SECURITY POLICIES IN MANUFACTURING COMPANY
APPENDIX A – CHECKLIST OF MANDATORY DOCUMENTATION REQUIRED BY ISO 9001:2015
APPENDIX B – CHECKLIST OF MANDATORY DOCUMENTATION REQUIRED BY ISO 14001:2015
APPENDIX C – CHECKLIST OF MANDATORY DOCUMENTATION REQUIRED BY ISO 27001:2013
APPENDIX D – CHECKLIST OF MANDATORY DOCUMENTATION REQUIRED BY ISO 22301
APPENDIX E – CHECKLIST OF MANDATORY DOCUMENTATION REQUIRED BY OHSAS 18001
APPENDIX F – STRUCTURING THE DOCUMENTATION FOR ISO 27001 ANNEX A
BIBLIOGRAPHY
PREFACE
When my book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own was published last year, very soon I realized many people were reading it because they were interested to learn how to manage the documentation.
Therefore, I have created this shorter book, a part of the handbook series, which is focused solely on the issues of how to handle policies, procedures, plans, and other documents and records. This book is not focused solely on ISO 27001 – the rules for handling documents are the same for any standard, so I have adapted this book in such a way so that it is perfectly acceptable for ISO 9001, ISO 14001, ISO 27001, ISO 20000, ISO 22000, OHSAS 18001, ISO 13485 and IATF 16949.
This book, Managing ISO Documentation: A Plain English Guide, is actually an excerpt from the book Secure & Simple, and has been edited with only a few smaller details. So, if you compare the sections from Secure & Simple that speak about documentation, you’ll see the same sections here, with almost the same text – as I mentioned, the text was adapted in a way that it is readable from any ISO standard point of view.
So, why have two books with almost the same text? Because I wanted to provide a quick read for people who are focused solely on managing documentation, and don’t have the time (or need) to read a comprehensive book about ISO implementation, i.e., a book like Secure & Simple.
You might also be puzzled by the fact that this book is rather short, whereas there are other books on ISO documentation in the market that are much more lengthy and detailed. Is it really possible to explain such a complex subject in a short book like this? Well, there are two answers for this:
First, this book is focused on managing documents in smaller companies – therefore, I have intentionally simplified the description so that you can handle the document in an easy way, and left out all the elements that would be needed only for larger companies.
Second, and more importantly, I followed my company mission: We make complex frameworks easy to understand and simple to use.
In other words, it is easy to complicate things, but it is difficult to make things easy to understand. So, when you start reading this book you’ll notice I eliminated all the hard-to-understand talk, all the unnecessary details, and focused on what exactly needs to be done, in a language understandable for beginners with no prior experience in implementing ISO standard.
So, rest assured: if you are a smaller organization, by using this book you will be able to manage