ISO Management Systems Webinar Clause 8 Operations Slides
ISO Management Systems Webinar Clause 8 Operations Slides
Welcome to our webinar on clause 8 of ISO management systems written in the Annex
SL format..
As we go through the webinar, if you have any questions, please drop them in the
conversation window and I’ll pick up as many as possible at the end.
So before we dive into this webinar, a little information about CertiKit and myself.
1
Helped more
than 4000
customers
globally ISO Standards
Founded in and Data
2010 Protection
Compliance
Compliance Make
Toolkits and compliance
ISO Services easy
• CertiKit are a leading creator of compliance toolkits and provider of ISO services
based in Derbyshire, UK
• Since 2010 we have helped more than 4000 customers globally achieve
compliance
• We specialise in ISO standards and Data Protection compliance
• Our mission is to make compliance easy so that more organizations can achieve
certification to and benefit from their chosen standard or data protection
regulations
2
Ted Spiller
CertiKit’s Compliance Consultant:
• Consultant for ISO management systems,
including 9001, 14001, 45001, and 22301
assisting new and current CertiKit customers
• Technical author assisting the development of
the toolkits
• A certified ISO9001, 14001, 45001 and 22301
Lead Auditor with experience covering the past
20 years
• A certified lead IMS Implementer (ISOs 9001,
14001 & 45001)
• Blackbelt Lean Six Sigma practitioner
Responsible for providing Compliance Audit consultancy for ISO9001, 14001, 45001 and
22301 Management Systems to new and current CertiKit customers, and providing
guidance and advice, when needed, to customers who are implementing ISO9001,
14001, 45001 and 22301 using our management system toolkits.
I am qualified Lead Auditor in 9001, 14001, 45001 and Auditor for 22301 and have
gained a lot of experience over the last 22 years, holding senior management positions
within Defence, Aerospace, Airport Management and Training sectors.
I’m also a Lead Implementer for ISO’s 9001, 14001 and 45001
3
What will we cover today?
What is clause 8?
Clause 8 in ISO9001
Clause 8 in ISO14001
Clause 8 in ISO45001
Clause 8 in ISO27001
Summary
4
What is Clause 8 about?
In the context of ISO management systems, Clause 8 refers to the "Operation" clause. This clause is a
fundamental part of ISO management system standards, such as ISO 9001, ISO 14001, ISO 45001, and
others.
The purpose of Clause 8 - Operation is to provide guidelines and requirements for effectively
implementing the processes and activities necessary to achieve the organization's objectives and deliver
the products or services in line with its policies and plans.
1. Operational Planning
2. Resource Management
3. Product or Service Provision
4. Control of Processes, Products, and Services
5. Emergency Preparedness and Response
6. Performance Evaluation
7. Improvement
5
or other relevant aspects.
5
ISO 9001
Clause 8 in ISO 9001 requires you to plan, control,
and implement quality processes.
Clause 8 in ISO9001 requires you to plan, control and implement process necessary for
your products and service to conform with the your requirements and the requirements
of the standard.
It also has the only mandatory procedure, which is clause 8.4 - Control of externally
provided processes, products and services.
6
Clause 8 – ISO9001 changes
The following sub-sections make up clause 8 in the ISO9001 Quality Management system.
ISO 9001 is an international standard that outlines the requirements for a quality
management system (QMS) within an organization. Clauses 8.1 to 8.7 of ISO 9001
pertain to the planning and realization of products and services, which are crucial
aspects of maintaining consistent quality throughout an organization's processes. Here's
a brief explanation of each of these clauses:
7
ensure they meet the specified requirements before moving into production.
7
Links to other areas of the 9001 standard
Clause 8: Operation. This clause focuses on the operational processes within an
organization and ensures that products and services meet customer
requirements and are delivered effectively. Alignment with other clauses:
Clause 4: Context of the Organization: The context analysis identifies the external and
internal factors that can affect the organization's operations, helping to determine risks and
opportunities.
Clause 5: Leadership: Leadership's commitment to quality and their involvement in the
operational processes are critical for successful implementation.
Clause 6: Planning: Quality objectives are established, and operational planning takes place
to achieve these objectives.
8
external and internal factors that can affect the organization's operations,
helping to determine risks and opportunities.
Clause 5: Leadership: Leadership's commitment to quality and their
involvement in the operational processes are critical for successful
implementation.
Clause 6: Planning: Quality objectives are established, and operational
planning takes place to achieve these objectives.
8
Links to other areas of the 9001 standard
Clause 7: Support: Resources, including competent personnel and infrastructure, are
provided to support the operational processes.
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and evaluating
operational performance help to identify areas for improvement.
Clause 10: Improvement: Actions to improve operational processes are taken based on the
results of performance evaluations.
9
infrastructure, are provided to support the operational processes.
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and
evaluating operational performance help to identify areas for improvement.
Clause 10: Improvement: Actions to improve operational processes are taken
based on the results of performance evaluations.
9
ISO 14001
With Clause 8 in ISO 14001, you are required to
develop operational planning, emergency
response, and environmental monitoring.
10
Clause 8 – ISO14001 changes
The following subsections make up clause 8 in the ISO14001
Environmental Management system.
11
laws, regulations, and other requirements is a crucial part of operational planning.
11
Links to other areas of the 14001 standard
Clause 8: Operation. This clause focuses on the implementation of
environmental controls and measures to address the identified significant
environmental aspects and ensure compliance with legal and regulatory
requirements. Alignment with other clauses:
12
context helps identify the environmental aspects and impacts to be
addressed in the operational processes.
Clause 5: Leadership: Leadership commitment is crucial for the effective
implementation of environmental controls and resource allocation.
Clause 6: Planning: Environmental objectives and targets are set, and
operational planning takes place to achieve these objectives.
12
Links to other areas of the 14001 standard
Clause 7: Support: Resources, awareness, and competence are provided to support the
operational processes.
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and evaluating
environmental performance helps identify areas for improvement.
Clause 10: Improvement: Actions to improve environmental performance are taken based on
the results of performance evaluations.
13
support the operational processes.
Clause 9: Performance Evaluation: Monitoring, measuring, analyzing, and
evaluating environmental performance helps identify areas for
improvement.
Clause 10: Improvement: Actions to improve environmental performance are
taken based on the results of performance evaluations.
13
ISO 45001
With Clause 8, ISO 45001 requires you to plan,
control hazards and mitigation, manage change and
procurement, and prepare emergency responses.
14
Clause 8 – ISO45001 changes
The following subsections make up clause 8 in the ISO45001
Occupational Health and Safety Management system.
ISO 45001 is an international standard that sets the requirements for occupational
health and safety management systems (OHSMS). It provides a framework for
organizations to manage and improve their occupational health and safety performance.
Clauses 8.1 and 8.2 of ISO 45001 are part of the "Operation" section of the standard,
focusing on the implementation and control of the OHSMS. Here's a brief explanation of
each of these clauses:
15
hazards and reduce the associated risks.
• Monitoring and Review: The effects of changes on health and safety should be
monitored and reviewed to ensure that the intended outcomes are achieved and that
new risks are promptly addressed.
15
Links to other areas of the 45001 standard
Clause 8: Operation. This clause focuses on the operational controls necessary
to manage occupational health and safety risks and ensure a safe working
environment for employees and other stakeholders. Alignment with other
clauses:
Clause 4: Context of the Organization: Understanding the context helps identify the
occupational health and safety risks and opportunities in the operational processes.
Clause 5: Leadership: Leadership commitment is crucial for implementing and maintaining
effective operational controls.
Clause 6: Planning: Objectives and action plans are established to control occupational health
and safety risks in the operational processes.
16
identify the occupational health and safety risks and opportunities in the
operational processes.
Clause 5: Leadership: Leadership commitment is crucial for implementing
and maintaining effective operational controls.
Clause 6: Planning: Objectives and action plans are established to control
occupational health and safety risks in the operational processes.
16
Links to other areas of the 45001 standard
Clause 7: Support: Resources, training, and awareness are provided to support the
operational controls.
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and evaluating
occupational health and safety performance helps identify areas for improvement.
Clause 10: Improvement: Actions to improve occupational health and safety performance are
taken based on the results of performance evaluations.
17
support the operational controls.
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and
evaluating occupational health and safety performance helps identify areas
for improvement.
Clause 10: Improvement: Actions to improve occupational health and safety
performance are taken based on the results of performance evaluations.
17
ISO 27001
With Clause 8 in ISO 27001, you are required to
develop operational planning and control,
information security risk assessments and
treatments.
18
Clause 8 – ISO27001 changes
The following subsections make up clause 8 in the ISO27001 Quality
Management system.
ISO 27001, which is the international standard for information security management
systems (ISMS). This clause provides the framework to establish operational planning
and control, risk assessment and treatment, business continuity planning and disaster
recovery and monitoring, measurement, analysis and evaluation. Here's a brief
explanation of these clauses:
• Risk Assessment and Treatment: Organizations must continue to assess risks to their
information assets and implement appropriate measures to manage and mitigate
these risks.
• Selection of Controls: Based on the risk assessment, organizations need to select and
implement appropriate security controls from the ISO 27001 Annex A, which provides
a comprehensive set of controls addressing various aspects of information security.
19
• Documentation of Controls: The controls selected for implementation must be
documented, along with the procedures and guidelines for their effective use.
• Risk Treatment: Based on the risk assessment results, organizations must decide on
appropriate risk treatment strategies, which may involve avoiding, mitigating,
transferring, or accepting risks.
• Review and Iteration: The risk assessment process should be reviewed and updated
regularly to account for changes in the organization's context and the evolving threat
landscape.
• During the operation of the ISMS, whenever the risk assessment is updated, the
organization then applies the risk treatment consistent with clause 6.1.3 (information
security risk treatment) and updates the risk treatment plan. Then the risk treatment
plan is again implemented.
• The information security risk treatment process should be performed after each
iteration of the security assessment process in clause 8.2 or when the implementation
f the risk treatment plan or parts of it fails.
19
Links to other areas of the 27001 standard
Clause 8: Operation. This clause focuses on the implementation of controls and
measures to protect information assets and ensure the confidentiality, integrity,
and availability of information. Alignment with other clauses:
Clause 4: Context of the Organization: Understanding the information security context helps
identify the risks and opportunities related to information security in operational processes.
Clause 5: Leadership: Leadership commitment is essential for implementing and maintaining
effective information security controls.
Clause 6: Plans are established to protect information assets in operational processes
through information security risk assessments and risk treatments. Planning: Information
security objectives and how to achieve them.
20
information security in operational processes.
Clause 5: Leadership: Leadership commitment is essential for implementing
and maintaining effective information security controls.
Clause 6: Plans are established to protect information assets in operational
processes through information security risk assessments and risk
treatments. Planning: Information security objectives and how to achieve
them.
20
Links to other areas of the 27001 standard
Clause 7: Support: Resources, training, and awareness are provided to support the
implementation of information security controls.
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and evaluating
information security performance helps identify areas for improvement.
Clause 10: Improvement: Actions to improve information security performance are taken
based on the results of performance evaluations.
21
Clause 9: Performance Evaluation: Monitoring, measuring, analysing, and
evaluating information security performance helps identify areas for
improvement.
Clause 10: Improvement: Actions to improve information security
performance are taken based on the results of performance evaluations.
21
In summary
In summary, Clause 8 in each of these ISO management systems deals with
operational aspects related to quality, environmental management, occupational
health and safety, or information security, depending on the standard.
The alignment with other clauses ensures that the operational processes are well-
integrated into the overall management system, thereby contributing to the
achievement of organizational objectives and continuous improvement.
The alignment with other clauses ensures that the operational processes are
well-integrated into the overall management system, thereby contributing to the
achievement of organizational objectives and continuous improvement.
22
How can CertiKit help you?
CertiKit Toolkits Logo Replacer Service ISO Consultancy ISO Internal Auditing
Website: certikit.com
LinkedIn: @certikit
Email: [email protected]
Besides providing toolkits to customers around the world, we also provide a number of
other services to assist businesses in gaining their certification or compliance needs.
These include:
ISO Consultancy
Although our ISO toolkits are designed to be used without needing additional
consultancy, sometimes our customers find that a bit of extra help is useful, either
because of time constraints, lack of resource or because there are a few specialist areas
they need expertise in. Benefit from the knowledge of our experts who have years of
experience. Please note, CertiKit’s consultancy is performed remotely via MS Teams by
23
our consultants in the UK.
23
Do you have any questions?
24