top of page

Status Assessment of New Business Management System (MS)

Overview

The status assessment of a Management System (MS) is very similar to MS audit. It is typically conducted:

  • After the decision has been made to implement an ISMS for improving internal information security processes and practicesf and for certification purposes

  • After a management system standard (MSS), e.g. ISO 27001 (Information Security Management Systems) has been selected

  • Before initiating the project for designing, documenting, implementing, and maintaining the ISMS to certification.

Our Services

Objectives of Status Assessment

To  establish any gaps between:

  • The current state of the organisation's MS, i.e. the documents, records, processes, and practices, against the requirements of the selected MSS, such as ISO 9001 (Quality Management Systems)

  • The future (desired) state, when the above MS has been planned, developed, effectively implemented, conforming with all requirements of the MSS, and is capable of achieving the MS's policy objectives.

 

Inputs

 

MS policy, history, document review findings, outcome of interviews with personnel performing the in-MS-scope processes, customer feedback, and planning.

Process

The Assessor (Auditor) reviews the existing components of a MS (e.g. Quality MS), and the way policies, processes, and procedures are implemented against the requirements of the selected MSS, such as ISO 9001, to establish if:

  • Required MS documents, mandated by the MSS, have been developed, and are maintained

  • Documented policies, processes, and procedures within the scope of the MS are correctly implemented, and maintained, and are effective in achieving set objectives

  • The MS is continuously improved.

Outputs

 

  • Status Assessment Report, including findings, Corrective Action Requests (CARs), recommendations, conclusions

  • Proposed Action Plan.

 

The above outputs of the status assesment, i.e. the report and action plan, are the main inputs for initiating the project that will:

 

  • Define, design, document, and implement the MS

  • Assess the MS for full compliance with the MSS and its ready for the certification audit.


N,B. Proceeding for MS certification is a strategic business decision, made by the senior management of the organisation concerned.

bottom of page