Quality Risk

       
 

This part of the IMS deals with quality risk.

The approach taken is based on the methodology presented by Brewer and List in their paper on "Measuring the effectiveness of an internal control system" (the "time" theory) . In this methodology an event describes how a threat agent might exploit some vulnerability to compromise the security of some asset and cause some impact. The events, threat agents, vulnerabilities, assets and impacts are considered generically in order to maximise the efficiency of the risk analysis process, as the objective of the exercise is to identify what quality controls, in particular those listed in the SOA, are required to reduce quality risk to an acceptable level.

Risk is determined in the context of our particular quality objectives, which are defined as part of our IMS Policy, the infrastructure necessary to achieve product conformity and our work environment.

 

Threat Agents

In the "threat agent ID" column, use some simple descriptive identifier. Use it also it as an anchor. You will refer to it from elsewhere. In the "description" column, describe briefly what the threat agent is. If the threat agent is common to other risk assessments use the same identifier. There will be just one definition in the Glossary page. Note that there is a special threat (supplier) that is identified by ISO 9001. It is labelled TA-out. Use the label T- (i.e. drop the A) for the threat agents that you define so that the list may still be put into alphabetic order (should you so wish).

Threat Agent ID Description
TA-Sup Suppliers
<<>> <<>>

 

Sequence and Interaction of Quality Processes

Summarise here, with the aid of a diagram, the sequence and interaction of the quality processes. In practice, these should be a composite of the various quality RTPs.

Ensure that these processes meet the following two ISO 9001 requirements (8.2.4):

  • The organisation shall monitor and measure the characteristics of the product to verify that product requirements have been met. This shall be carried out at appropriate stages of the product realisation process in accordance with the planned arrangements.
  • Product release and service delivery shall not proceed until the planned arrangements have been satisfactorily completed, unless otherwise approved by a relevant authority and, where applicable, by the customer.
<<>>

 

IMS-Smart produced by Gamma Secure Systems Limited. Gamma is an ISO/IEC 27001:2005 and BS EN ISO 9001: 2000 registered company, certified for the provision of information security consultancy.  BSI certificate numbers IS 85916 and FS  30710.  Gamma Secure Systems, Diamond House, Frimley Road, Camberley, Surrey, GU15 2PS, UK Tel: +44 1276 702500 - Fax: +44 1276 692903.  Use of IMS-Smart is governed by a EULA. Template reference 033-080124, copyright © Gamma Secure Systems Limited, 2007-8
 
TemplateIMSDemo
Page last updated: 17 March, 2008