The Elsmar Cove Wiki More Free Files The Elsmar Cove Forums Discussion Thread Index Post Attachments Listing Failure Modes Services and Solutions to Problems Elsmar cove Forums Main Page Elsmar Cove Home Page

Go Back   The Elsmar Cove Forum > Common Quality Assurance Processes and Tools > Management Review Meetings and related Processes
Forum Username

Elsmar Cove Forum Visitor Notice(s)


Elsmar Cove Forum Sidebar
Custom Search
Monitor the Elsmar Forum
Monitor New Forum Posts
Follow Marc & Elsmar
Elsmar Cove Forum RSS Feed  Marc Smith's Google+ Page  Marc Smith's Linked In Page   Marc Smith's Elsmar Cove YouTube Page  Marc Smith's Facebook Page
Elsmar Cove Groups
Elsmar Cove Google+ Group  Elsmar Cove LinkedIn Group  Elsmar Cove Facebook Group
Sponsor Links







Donate and $ Contributor Forum Access
Sponsored Links
Courtesy Quick Links

Links that Elsmar Cove visitors will find useful in your quest for knowledge:


Howard's
International Quality Services

Atul's
Symphony Technologies

Marcelo Antunes'
SQR Consulting

Bob Doering's
Correct SPC - Precision Machining


NIST's Engineering Statistics Handbook

IRCA - International Register of Certified Auditors

SAE - Society of Automotive Engineers

Quality Digest Portal

IEST - Institute of Environmental Sciences and Technology

ASQ - American Society for Quality


Related Topic Tags
iso 27001 - information security management system (isms), iso 9001 - quality management systems, management review
Reply
 
Thread Tools Search this Thread Rate Thread Content Display Modes
  #1  
Old 23rd May 2012, 06:44 AM
AnandR AnandR is offline
Involved in Discussions

 
Registration Date: Apr 2011
 
Posts: 29
Thanks Given to Others: 2
Thanked 2 Times in 2 Posts
Karma Power: 11
Karma: 20
AnandR has less than 100 Karma points so far.
Please Help! Management Review Meeting (MRM) Input & Output Interpretation

Good Afternoon!

I having difficult in interpreting the following MRM inputs and Outputs related to ISO 9001 and ISO 27001. Help from experts is appreciated.
Thanks
Anand

ISO 9001:
MRM Inputs:
1) Changes that could affect the QMS
2) Recommendations for improvement

Recommendation for improvement, is it based on the review of all the MRM inputs?

MRM Outputs:
1) Improvement of effectiveness of QMS & Its Processes
2) Improvement of product related to customer requirements

Is the above MRM output different from the Recommendations for improvement made in MRM input?



ISO 27001:
MRM Inputs:
1) Results of ISMS audits and reviews
2) Feedback from interested parties on ISMS
3) Techniques, products or procedures, which could be used in the organization to improve the ISMS performance and effectiveness
4) Results from effectiveness measurements


In QMS, it is only the results of audit. But, in ISMS it says results of audits and reviews

Techniques, products or procedures, which could be used in the organization to improve the ISMS performance and effectiveness
Here is it meaning recommendations for improvements? Is it for bringing in new items that never exists?


MRM Outputs:
  • Modification of procedures & controls that effect information security, as necessary, to respond to internal or external events that may impact on the ISMS, including changes to:
    a)Business Requirements b) Security Requirements c) Business Processes effecting the
    existing business requirements d) Regulatory or Legal Requirements
    e) Contractual Obligations & f) Levels of risks and/or criteria for accepting risks
  • Improvements to how the effectiveness of controls is being measured

Sponsored Links
  #2  
Old 23rd May 2012, 08:07 AM
Richard Regalado Richard Regalado is offline
Appreciated Member

 
Registration Date: Mar 2005
Location: Philippines
Age: 40
 
Posts: 180
Thanks Given to Others: 7
Thanked 105 Times in 69 Posts
Karma Power: 55
Karma: 1575
Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.
Send a message via Yahoo to Richard Regalado
Re: Management Review Meeting (MRM) Input & Output Interpretation

First of all AnandR, there is no requirement for an MRM or management review meeting. The requirement is for management to review the required inputs and come up with sensible outputs. You can do this is in various ways other than a meeting. I've seen organizations with management abroad doing management reviews via email exchanges.

I will answer the ISMS part first. You asked:
Quote:
ISO 27001:
MRM Inputs:
1) Results of ISMS audits and reviews
2) Feedback from interested parties on ISMS
3) Techniques, products or procedures, which could be used in the organization to improve the ISMS performance and effectiveness
4) Results from effectiveness measurements
1. Reviews are activities distinct from audits which can help ensure the preservation of CIA of your information assets. Reviews encompass technical vulnerability reviews such as penetration testing and vulnerability assessments.

2. Interested parties to your ISMS may include customers, stakeholders, the government, employees, contractors, 3rd-party vendors, consultants, etc.

3. Supposed one of your higher risk is employees tail-gating the main door and bypassing the current swipe card access. A product which can improve this situation such as installing a turnstile system could be part of the management review. The same goes for new products or techniques in the market which could lower your risk exposure and improve performance. A new co-lo site perhaps? A faster internet service provider?

4. There is a requirement to measure the effectiveness of the chosen and implemented controls. Make sure the results of the measurement process are part of the management review.

Will get back later after dinner. Wifey calling me.
Sponsored Links

  #3  
Old 23rd May 2012, 10:17 AM
Richard Regalado Richard Regalado is offline
Appreciated Member

 
Registration Date: Mar 2005
Location: Philippines
Age: 40
 
Posts: 180
Thanks Given to Others: 7
Thanked 105 Times in 69 Posts
Karma Power: 55
Karma: 1575
Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.
Send a message via Yahoo to Richard Regalado
Re: Management Review Meeting (MRM) Input & Output Interpretation

I'm back! Now for the outputs.

You said:
Quote:
MRM Outputs:
Modification of procedures & controls that effect information security, as necessary, to respond to internal or external events that may impact on the ISMS, including changes to:
a)Business Requirements b) Security Requirements c) Business Processes effecting the
existing business requirements d) Regulatory or Legal Requirements
e) Contractual Obligations & f) Levels of risks and/or criteria for accepting risks
Improvements to how the effectiveness of controls is being measured
One the required output of the management review for ISMS is how will management respond if there changes to the factors listed in a-e.

Business requirements pertain to your own organization changing requirements. For example, the next door office was recently robbed and ransacked. This will trigger or initiate your own review of physical security and if the risk is validated, certain control may be added. Regulatory and legal requirements are from the government and regulatory bodies while contractual obligations are normally from your customers. You need to determine the actions to be taken by the organization should there be changes to these.

The last MR output requirement is very straightforward. As a result of reviewing the results of the measurement of effectiveness of controls, what changes would management want to implement to improve the measurement process for controls' effectiveness. Would you want to measure with more regularity? Would you want to automate the measurement process?
  #4  
Old 24th May 2012, 04:15 AM
AnandR AnandR is offline
Involved in Discussions

 
Registration Date: Apr 2011
 
Posts: 29
Thanks Given to Others: 2
Thanked 2 Times in 2 Posts
Karma Power: 11
Karma: 20
AnandR has less than 100 Karma points so far.
Re: Management Review Meeting (MRM) Input & Output Interpretation

Richard, I thank you very much for taking time to explain me my queries. It really helps.
Request you to help me on MRM inputs for ISO 9001.
1) Changes that could affect the QMS
2) Recommendations for improvement

Recommendation for improvement, is it based on the review of all the MRM inputs?
  #5  
Old 24th May 2012, 08:49 AM
somashekar's Avatar
somashekar somashekar is offline
Cross Forum Moderator

 
Registration Date: Mar 2008
Location: Bangalore city, INDIA
 
Posts: 3,841
Thanks Given to Others: 1,209
Thanked 1,929 Times in 1,365 Posts
Blog Entries: 2
Karma Power: 431
Karma: 12851
somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.
somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.somashekar is appreciated, and has over 1700 Karma points.
Send a message via Yahoo to somashekar
Re: Management Review Meeting (MRM) Input & Output Interpretation

Quote:
In Reply to Parent Post by AnandR View Post

Richard, I thank you very much for taking time to explain me my queries. It really helps.
Request you to help me on MRM inputs for ISO 9001.
1) Changes that could affect the QMS
2) Recommendations for improvement

Recommendation for improvement, is it based on the review of all the MRM inputs?
A management review input is not only a status information of all business related processess, but also possible actions that can be taken up for the changes faced in a dynamic business world, for the results of analysis of various data concerning to internal activities., with a vision to improve.
You bring about all the prospects and consequences (pro's and con's) in the MR input and the MR outputs sets direction for future actions.
In very simple words, inputs help management to give outputs. Good inputs gets effective outputs.
__________________
Best Regards...
Somashekar BV, INDIA
  #6  
Old 25th May 2012, 01:16 AM
AnandR AnandR is offline
Involved in Discussions

 
Registration Date: Apr 2011
 
Posts: 29
Thanks Given to Others: 2
Thanked 2 Times in 2 Posts
Karma Power: 11
Karma: 20
AnandR has less than 100 Karma points so far.
Re: Management Review Meeting (MRM) Input & Output Interpretation

Thanks Somashekar
Reply

Lower Navigation Bar
Go Back   The Elsmar Cove Forum > Common Quality Assurance Processes and Tools > Management Review Meetings and related Processes

Do you find this discussion thread helpful and informational?


Bookmarks


Visitors Currently Viewing this Thread: 1 (0 Registered Visitors (Members) and 1 Unregistered Guest Visitors)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Forum Search
Display Modes Rate Thread Content
Rate Thread Content:

Forum Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Discussion Threads
Discussion Thread Title Thread Starter Forum Replies Last Post or Poll Vote
Is the Business Plan an Input, Resource or Output of Management Review? Manix Management Review Meetings and related Processes 32 29th February 2012 11:47 AM
What are the points to be discussed in a Management Review Meeting (MRM) PE-2011 ISO 9000, ISO 9001, and ISO 9004 - Questions and Discussions 18 20th June 2011 02:40 PM
Management Review Input and Output Content Requirements masimr ISO 10013 - Quality Management System (QMS) Manuals 2 5th January 2011 06:58 AM
Management Review NCR - No review output - Need Help uzaimi - 2008 Management Review Meetings and related Processes 1 28th March 2007 01:41 AM
Record of Inputs to Management Review Meeting (MRM) aynin_quality Management Review Meetings and related Processes 15 13th September 2006 08:34 AM



The time now is 12:02 PM. All times are GMT -4.
Your time zone can be changed in your UserCP --> Options.


   


Marc Timothy Smith - Elsmar.com
8466 LeSourdsville-West Chester Road, Olde West Chester, Ohio 45069-1929
513 341-6272