Quality Matters is an independent Management Consultancy based in Maldon, Essex. Here we discuss the latest in Quality and Information Security News.
There are many potential disasters that can affect our organisations, some serious and some just inconvenient.
A sensible precaution is to put into place a Disaster Recovery Plan. The main parts of which are kept off site:
To be successful the plan should show what should happen immediately an incident is discovered, what should happen after two hours then four hours and so on.
Here are some simple ways to reduce your carbon footprint; the added bonus is that it will save you a considerable amount of cash:
This will help save the planet and help your bank balance.
Social engineering is the term used to obtain information from people without them realising what is going on.
A recent exercise carried out by one of our clients was to invite by email, specially selected employees (although all employees received the invitation) to take part in an exciting new venture. All, they had top do was to go to a secure web-site and enter their company log on and password to verify their interest. The recipients were warned not to talk about this venture to any of their colleagues as the matter was highly secret.
This company (that I will not identify) is accredited to ISO27001 and takes security very seriously but many of the employees did enter this confidential information into the web-site believing that it was quite innocent.
A delivery of flowers or chocolates is made, usually by a pretty girl, and the idea is to surprise the recipient so the usual security at reception is waived.
Labels: information security, ISO27001, social engineering
Many Large Organisations and Government Departments have set minimum entry criteria for quotations and tenders for products and services; these are usually in the form of recognised quality and/or environmental standards.
If the tender request states that ISO9001 and ISO14001 are entry requirements and you don't have these, your quotation or tender, however well prepared, will not get beyond the starting gate.
These organisations simply do not have the time to vet each potential supplier for quality or environmental status. It is easier to rely on one of the Certification Bodies to do the work for them. If the supplier can show that it has passed, and continues to pass, the International Requirements for quality and environmental performance it will be considered for inclusion of that organisation’s preferred suppliers list.
ISO9001 & ISO14001 open doors
0 Comments:
Post a Comment