<?xml version="1.0" encoding="ISO-8859-1"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xml:lang="en-US">
	<title>The Risk Briefing</title>
	<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php" />
	<modified>2012-02-07T09:42:02Z</modified>
	<author>
		<name>Assent Risk Management</name>
	</author>
	<copyright>Copyright 2012, Assent Risk Management</copyright>
	<generator url="http://www.sourceforge.net/projects/sphpblog" version="0.5.1">SPHPBLOG</generator>
	<entry>
		<title>Win Public Sector Contracts with Accreditations</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120206-104003" />
		<content type="text/html" mode="escaped"><![CDATA[<b>The Benefits</b><br />The rewards of public sector tendering are plentiful with over £236 Billion spent in the year 2009/2010.<br /><br />2500 Contract Notices are published each week and 25% are awarded to Small and Medium Sized Enterprises (SMEs).<br /><br />Unfortunately many businesses do not take full advantage of these opportunities because they are unclear about the process and how to answer the many intimidating questions.<br /><br />Achieving accreditations and ISO certification is a great way to demonstrate your commitment and capabilities but it only forms part of the tendering process.<br /><br /><b>Register for Tender Alerts</b><br />It is mandatory that public sector contracts above £173,934 are publicly released. However, many contracts far below this value are put through the same channels.<br /><br />There are many services that distribute tender notices at varying costs.<br /><br /><b>Pre - Qualification Questionnaire [PQQ]</b><br />If you then decide to apply for a contract the next step will be the PQQ.  This can be a daunting document and you may wish to seek advice on how to answer the questions to ensure you represent your company well.<br /><br />The PQQ gives the awarding authority an opportunity to filter applicants into a short list and, at this stage, accreditations play a vital role!<br /><br /><b>Invitation To Tender [ITT]</b><br />If you successfully reach a short list you may be invited to tender.  At this stage the authority is more concerned with the &quot;what, where, when and how&quot; of your service delivery.<br /><br />This is a good time to seek advice and guidance if you are unsure how to respond.<br /><br /><b>Tender Award</b><br />After successfully completing the process you will be awarded the contract and it&#039;s time to deliver. Don&#039;t miss the opportunity!<br /><br />Thank you to <b>Tender Assist</b> for their input into this article.  Tender assist can help your business tender for public sector contracts. <br />Contact 01438 861931 or visit <a href="http://www.tenderassist.co.uk" target="_blank" >www.tenderassist.co.uk</a> for details.<br />]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120206-104003</id>
		<issued>2012-02-06T00:00:00Z</issued>
		<modified>2012-02-06T00:00:00Z</modified>
	</entry>
	<entry>
		<title>Proposals for Tougher European Data Protection Laws Expected</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120125-114611" />
		<content type="text/html" mode="escaped"><![CDATA[New legislation is expected to replace the EU Data Protection Directive 95/46 and reduce the bureaucratic burden on organisations, while increasing responsibility to protect data, acknowledge and report data breaches.  <br /><br />There will also be stiffer penalties for companies that do not meet the legal requirements.<br /><br />Three main requirements included in a leaked draft are:<br /><br />1. Mandatory notification of data breaches.  Recommending relevant Data Protect Authorities are noticed and any affected individuals, within 24 hours of a data protection incident.<br /><br />2. Requirement of named data protection officers in public sector organisations and all companies exceed 250 employees.<br /><br />3. Increased fines for non-compliance, up to one million Euros, or up to 5% of an enterprise&#039;s annual world wide revenue.<br /><br /><b>Social Networks</b><br />Another interesting comment is regarding social networking website, which may be required to hand back data to a user, when they close their account, for them to post else where.  <br /><br /><b>Right to be Forgotten</b><br />The phrase right to be forgotten means Internet companies would be required to erase all data their held and, in some cases, all traces of that data on search engines, if members withdrew their consent for it to be used.<br /><br /><b><a href="http://www.assentriskmanagement.co.uk/iso27001" target="_blank" >ISO 27001 Information Security</a></b><br />One way to mitigate the risk on non-compliance under the new data protection legislation is to implement an Information Security Management system to the requirements of ISO 27001. <br /><br />This risk based standard provides a management framework that will insure correct policies and procedures are in place for all applicable legislation.<br /><a href="http://www.assentriskmanagement.co.uk/iso27001" target="_blank" >More Information</a><br /><br /><b>Conclusion</b><br />In the mean time, we look forward to European Commissioner Viviane Reding&#039;s presentation later today.<br /><br /><b>Sources</b><br /><br /><a href="http://www.marketwatch.com/story/iron-mountain-marks-european-privacy-and-data-protection-day-with-call-to-action-prepare-today-or-be-penalised-tomorrow-2012-01-25" target="_blank" >http://www.marketwatch.com/story/iron-m ... 2012-01-25</a><br /><br /><a href="http://www.abs-cbnnews.com/business/01/25/12/new-eu-data-laws-command-tide-not-cost" target="_blank" >http://www.abs-cbnnews.com/business/01/ ... e-not-cost</a><br /><br />*UPDATE*<br />Proposal Released: <a href="http://ec.europa.eu/justice/newsroom/data-protection/news/120125_en.htm" target="_blank" >http://ec.europa.eu/justice/newsroom/da ... 125_en.htm</a><br /><br /> ]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120125-114611</id>
		<issued>2012-01-25T00:00:00Z</issued>
		<modified>2012-01-25T00:00:00Z</modified>
	</entry>
	<entry>
		<title>FSC Paper Stock - 3 Sustainable Options</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120124-132750" />
		<content type="text/html" mode="escaped"><![CDATA[The FSC Chain of Custody scheme is appearing more and more in everyday life.  As discussed here last March (<a href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry110330-132211" target="_blank" >http://www.assentriskmanagement.co.uk/b ... 330-132211</a>) it is easy for companies to gain certification to this standard and thus significantly reduce their impact on the world&#039;s forestry.<br /><br />Here we focus in on the 3 types of paper stock certified under FSC CoC:<br /><br /><b>1. FSC Certified Stock</b><br />Completely sourced from sustainable, well managed forestry.  However this stock takes around 70% more energy than recycled stock (Below).  However, FSC Certified Stock is still a good choice as it can be traced back to source.<br /><br /><b>2. FSC Mixed Sources</b><br />Blends virgin fibres with recycled fibres.  At least half of the virgin fibres must be FSC certified.  <br /><br /><b>3. Recycled Fibre.</b><br />100% recycled from post-consumer waste from accredited paper-mills.<br /><br /><b>Conclusion</b><br />As you can see, although often considered to be sold at a premium, there are several options for buying sustainable paper product.  <br /><br />For more information on the scheme please contact us on 020 3432 2854.]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120124-132750</id>
		<issued>2012-01-24T00:00:00Z</issued>
		<modified>2012-01-24T00:00:00Z</modified>
	</entry>
	<entry>
		<title>The Green Deal</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120105-103702" />
		<content type="text/html" mode="escaped"><![CDATA[The Energy Act 2011 includes provision for the Department for Energy and Climate Change&#039;s (DECC) &#039;Green Deal&#039;, a scheme intended to reduce carbon emissions by revolutionising the energy efficiency of British Properties.<br /><br />Under the Green Deal, there will be no need to pay &#039;up front&#039; for energy efficiency improvements to properties, instead the cost is recovered through savings on energy bills.<br /><br />Installers and Assessors are required to complete accredited certification to provide services under the Green Deal and use the Green Deal Mark.  The Department for Energy and Climate Change has appointed UKAS to accredit certification bodies for the certification of Green Deal installers and advisors.  <br /><br />It is intended that the Green Deal Scheme will be operational by October 2012.  <br /><br />Contact us for more information contact Assent on 020 3432 2854.<br /><br />Green Deal Website: <a href="http://www.decc.gov.uk/en/content/cms/tackling/green_deal/green_deal.aspx" target="_blank" >http://www.decc.gov.uk/en/content/cms/t ... _deal.aspx</a>]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120105-103702</id>
		<issued>2012-01-05T00:00:00Z</issued>
		<modified>2012-01-05T00:00:00Z</modified>
	</entry>
	<entry>
		<title>Start Ups in Shoreditch and London&#039;s Tech City could benefit from ISO Certification.</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111212-134540" />
		<content type="text/html" mode="escaped"><![CDATA[The area of East London dubbed as Tech City is rich in technology start ups who could benefit from the efficiencies and credibility an ISO management system would bring.<br /><br />All around Shoreditch and the Silicon Roundabout on Old Street, there are companies that depend on the security and continuity of I.T systems in order to trade.  <br /><br />This is where we have been able to help companies achieve certification to <a href="http://www.assentriskmanagement.co.uk/iso27001" target="_blank" >ISO 27001</a>, an Internationally recognised Information Security Standard. The implementation process involves a series of risk assessments across a wide range of business areas.  <br /><br />There is also a basic element of business continuity planning involved, however we usually assist clients in preparing a comprehensive business continuity plan, which could later be certified to <a href="http://www.assentriskmanagement.co.uk/bs25999" target="_blank" >BS 25999</a> standard.<br /><br />The London Riots, which occurred in several areas of London, demonstrated how unpredictable and fast such events can be and our clients who operated an ISO 27001 management system were able to quickly react.<br /><br />There is also competitive advantage to be gained from ISO certification, with many public sector bodies requesting it during the tendering process.<br /><br />Call our office on 020 3432 2854 to arrange a free consultation with one of our ISO consultants.]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111212-134540</id>
		<issued>2011-12-12T00:00:00Z</issued>
		<modified>2011-12-12T00:00:00Z</modified>
	</entry>
	<entry>
		<title>Revision C Update to Aerospace AS/EN9100 Standard</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111123-130903" />
		<content type="text/html" mode="escaped"><![CDATA[The International Aerospace Quality Group (IAQG) has made some revisions to the Aerospace  AS 9100, 9110 and 9120 series of standards.<br /><br />Key changes to the standards include:<br />• broadening the scope to cover Aviation, Space &amp; Defence.<br />• greater emphasis on the process approach and project management.<br />• a Risk Management Process is now required.<br />• processes must be measured for effectiveness.<br /><br />The auditing process now focuses more strongly on objectives, with the scoring system being replaced by &#039;Process Effectiveness Assessment Reports&#039;.<br /><br />Organisations currently registered will need to make the transition to Revision C by 1st July 2012.<br /><br />For help and guidance on the change please call our aerospace consultants on 020 3432 2854. <br /><br />For more info on this standard: <a href="http://www.peterjclements.co.uk/aerospace/" target="_blank" >http://www.peterjclements.co.uk/aerospace/</a><br /><br /><a href="javascript:openpopup('http://www.peterjclements.co.uk/images/airport.jpg',800,600,false);"><img src="http://www.peterjclements.co.uk/images/airport.jpg" border="0" alt="" /></a>]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111123-130903</id>
		<issued>2011-11-23T00:00:00Z</issued>
		<modified>2011-11-23T00:00:00Z</modified>
	</entry>
	<entry>
		<title>ISO/IEC 27035:2011 Information Security Incident Management</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111101-115116" />
		<content type="text/html" mode="escaped"><![CDATA[ISO/IEC 27035:2011 provides best practice guidance for information security incident detection, reporting and management.<br /><br />The ISO standard aims to help organisations reduce the impact of I.T security threats by implementing the defined incident management approach.<br /><br />Although Incident management is addressed within <a href="http://www.assentriskmanagement.co.uk/iso27001" target="_blank" >ISO/IEC 27001</a> the Information Security Management System Standard, ISO/IEC 27035:2011 supports and expands guidance.<br /><br />ISO describe the standard as a solution to &quot;help businesses respond to information security incidents, including the activation of appropriate controls for the prevention and reduction of, and recovery from, impacts, and, in so doing, learn and improve their overall approach.&quot;<br /><br />Many organisation are vulnerable to security incidents and the increased resources needed to recover the business.  Incidents could also result in a criminal investigation and/or ICO fine, which could be prevented using the methods contained within this standard.<br /><br />For advice on Incident Management contact Assent on 020 3432 2854<br /><br /><br />]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111101-115116</id>
		<issued>2011-11-01T00:00:00Z</issued>
		<modified>2011-11-01T00:00:00Z</modified>
	</entry>
	<entry>
		<title>Managed Audit Programmes</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111024-112012" />
		<content type="text/html" mode="escaped"><![CDATA[<a href="http://www.assentriskmanagement.co.uk/auditing/" target="_blank" >Auditing</a> is an important part of maintaining a management system, so be sure that your auditors&#039; programme is effective for your business. <br /><br />Here we take a look at our own audit programmes and the best practises we apply.<br /><br /><b>Guidelines for Auditing Management Systems</b><br /><br />As you would expect, there are ISO standards specifying guidelines for auditors.  The recently updated ISO 19011:2011 &#039;Guidelines for Auditing Management Systems&#039; is a good place to start.<br /><br /><b>Principles of Auditing</b><br />The standard defines the following six principles of auditing which all our auditors adhere to:<br /><br /><b>Integrity</b> - <i>Ethical Conduct.</i><br /><b>Fair Presentation</b> - <i>report truthfully and accurately.</i><br /><b>Due Professional Care</b> - <i>application of diligence and judgement.</i><br /><b>Confidentiality</b> - <i>security of knowledge acquired.</i><br /><b>Independence</b> - <i>objectivity of audit results.</i><br /><b>Evidence-Based Approach</b> - <i>rational method fro reaching reliable and reproducible conclusions.</i><br /><br /><b>Choosing the Audit Team</b><br />When establishing an audit programme we consider which of our auditors has the relevant experience to evaluate the evidence presented.  It&#039;s important that the auditor understands the business they are auditing.  <br /><br />We ensure competence by using IRCA training lead auditors, who have experience of implementing and auditing management systems.  Continued Professional Development is also an important part of our auditor training.<br /><br /><b>Schedule and Programme Improvement</b><br />Where ever possible, we will fit the audit schedule around you.  Our auditors will be looking for evidence to support your management system, but will not want to disrupt the running of your business.  Therefore we may prepare some aspects pre-audit.<br /><br />The audit team will also be improving their audit programme with each visit, and may identify areas that they would like to revisit more often.  <br /><br /><b>Conclusion</b><br />Our audit team will apply the 6 auditing principles to establish and maintain an appropriate audit programme for your management systems.  Their feedback is intended to identify weaknesses that you can improve and strengthen.  <br /><br />To discuss the audit of your management systems or suppliers contact 020 3432 2854.<br /><br /><a href="http://www.assentriskmanagement.co.uk/auditing/" target="_blank" >More on Auditing</a>.]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111024-112012</id>
		<issued>2011-10-24T00:00:00Z</issued>
		<modified>2011-10-24T00:00:00Z</modified>
	</entry>
	<entry>
		<title>Smartphone Outage Exposes Business Risk</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111014-130631" />
		<content type="text/html" mode="escaped"><![CDATA[The recent blackberry outage saw several days pass before services to affected smartphones return to normal and it serves as a good reminder of the inter-dependent world we live and work in.<br /><br />Many businesses are left asking &#039;where&#039; in the world their services are held and what are the points of failure.<br /><br />Internet technology is deployed in the production of goods and provision of services globally.  Therefore it&#039;s important to evaluate the risks your business is exposed.<br /><br />One way to identify and manage this risk is to implement a management system to <a href="http://www.assentriskmanagement.co.uk/iso27001" target="_blank" >ISO 27001</a>.  The standard provides a plan, do, check, act approach to identify, treat and reduce business risks.  It&#039;s also possible to quantify the risk and apply a monetary value to non-compliance.<br /><br />The standard also requires risks with 3rd parties and suppliers be evaluated, which can lead to some interesting discoveries.<br /><br />If you are interested in implementing <a href="http://www.assentriskmanagement.co.uk/iso27001" target="_blank" >ISO 27001 Information Security Management</a>, please <a href="http://www.assentriskmanagement.co.uk/contact" target="_blank" >contact our consultants</a> on 020 3432 2854]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry111014-130631</id>
		<issued>2011-10-14T00:00:00Z</issued>
		<modified>2011-10-14T00:00:00Z</modified>
	</entry>
	<entry>
		<title>Risk Assessment Guiding Principles - Baseline Audit</title>
		<link rel="alternate" type="text/html" href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry110929-160858" />
		<content type="text/html" mode="escaped"><![CDATA[It is common practice for Organisations to develop and implement a health, safety and environmental management system.  The driving force is to put the organisation in a frontal position in tendering for contracts and for managing contractors, suppliers etc.  in meeting and maintaining your own organisations high standards.<br /><br />The first stage is to evaluate with a baseline audit those areas where they already meet the requirements of a corporate operation of a standard management system.<br /><br />Whereas the implementation of an Occupational Health and Safety Management system is a crucial part in an organisations ability to meet the health and safety legislation and setting targets to meet policy.  It is not at present a legal requirement for the organisation to be certified to <a href="http://www.assentriskmanagement.co.uk/ohsas18001/" target="_blank" >OHSAS 18001</a>, but organisations with <a href="http://www.assentriskmanagement.co.uk/iso9001/" target="_blank" >ISO 9001</a> will find common elements in all three systems 9001 – 18001 and 14001.<br /><br />The baseline audit sets out to establish the effectiveness of what is and evaluate closely the present system and documentation meet the Health and Safety at Work Act sections 2, 3, 4, and 7 primarily general duties of  Employers to their employees, the environmental legislation and Corporate Social Responsibility.  Each with their own policy statements and arrangements for carrying out and monitoring the arrangements.<br /><br />Areas for Review.  Health and Safety at Work Act Section 2<br /><br />Prepare and revise as appropriate a written policy statement, its operation and arrangements.<br /><br />Comprehensive Risk Assessments of the following:<br />Regulations and one all embracing Act that require a Risk Assessment.<br />•	The Health and Safety (Display screen equipment) Regulations 1992<br />•	The Manual Handling Operations Regulations 1992<br />•	The Personal Protective Equipment at Work Regulations 1992<br />•	The Workplace (Health, Safety and Welfare) Regulations 1992<br />•	The Construction (Design and Management) Regulations 1994<br />•	The Construction (Health, Safety and Welfare) Regulations 1996<br />•	The Lifting Operations and Lifting Equipment Regulations 1998<br />•	The Provision and Use of Work Equipment Regulations 1998<br />•	The Management of Health and Safety at work Regulations 1999<br />•	The Control of Lead at Work Regulations 2002<br />•	The Control of Noise at Work Regulations 2005<br />•	The Control of Vibration at Work Regulations 2005<br />•	The Work at Height Regulations 2005<br />•	The Control of Asbestos Regulations 2006<br /><br />Maintenance of a safe working environment.<br />S.F.A.R.P. regards any place of work, provision and maintenance of means of access and egress.<br /><br />Provision and maintenance of equipment and safe systems of work.<br /><br />Safety and absence of risk to health with use, handling, storage and transport of articles and substances.<br /><br />Provision of such information, training and supervision. S.F.A.R.P. for the Health and Safety of employees.<br /><br />Environmental, pollution prevention and control.<br /><br />Control and maintenance of air quality.<br />Use and maintenance of water – drinking etc.<br />Waste streams – packaging – recycling etc.<br />Chemical use and disposal<br />Statutory nuisance and noise.<br />Land contamination.<br />Environment work place assessment.<br />Corporate social responsibility.<br /><br />Typical Topics<br />Staff Support – The Community – The Environment<br /><br />Corporate Social Responsibility)  The Board<br />	Published and operating<br />	<br />	Society – Environmental impact<br />		Measure reduction in cost<br />		Economy in use of fuel<br />	Vehicles – Plants/Equipment – lighting – Heating<br />	<br />Energy management &amp; consumption reduction<br />	Reduce – reuse- recycle- eliminate waste<br /><br />Set up a C.R.S. Group<br />	Consideration of existing core values<br />	Prepare a written strategy plan<br />	Agree and adopt a mission statement<br />	Set Targets<br />	Appoint a Support Team – senior members<br /><br />Target key elements<br /><br />Environmental Considerations  )   Senior Management<br /><br />Economy Fuels: - heat – light – vehicles<br /><br />Regular internal audits followed by compliance certification.<br /><br />Directors/Senior managers.<br /><br />	Responsibilities and accountability.<br /><br />Corporate Governance ACA – IoD – External audits.<br />Records Management, Statutory retention.<br />Monitoring by senior management and independently.<br /><br /><br />Contact Us for more information on a baseline audit, 020 3432 2854.<br />]]></content>
		<id>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry110929-160858</id>
		<issued>2011-09-29T00:00:00Z</issued>
		<modified>2011-09-29T00:00:00Z</modified>
	</entry>
</feed>

