全球标准分享下载-全场2元
客服微信:1093451816,欢迎大家分享、下载!

ISO刚刚发布管理咨询服务优化指南

从改进流程到提高利润,管理咨询公司能有效为客户带来实质性的影响。刚刚发布的新标准旨在帮助管理咨询公司及其客户提高其咨询项目的透明度和可理解度,以实现双赢。

  管理咨询提供专业知识、经验以及广泛的服务和支持,包括产品推广、员工培训和组织结构设计及优化等,所以越来越多企业倾向于与他们合作。近年来,企业和政府希望改善业绩改进流程,在管理咨询方面的支出显著增长。

ISO 20700管理咨询服务指南》借鉴了全球范围内广泛的管理咨询行业相关的研究和经验,旨在提高该行业与其客户的透明度和有效性。

该标准由国际标准化组织管理咨询委员会(ISO/PC280)制定,其秘书处由ISO成员国意大利的标准化协会(UNI)负责。委员会主席Robert Bodenstein,表示,该项标准是基于大量咨询公司的实践经验以及其客户的建议所制定的,汇集了行业最佳实践,能帮助管理咨询更有效地开展。

他说:“凭借着对行业的深入了解和丰富经验,管理咨询公司能为企业提供宝贵的专业知识,有助于企业取得更好的业绩,为经济做出了显著的贡献。制定新标准不仅可以帮助咨询公司更有效并高效地工作,还能够推动行业的发展。”

ISO 20700是根据成果来制定实用指南的,强调了解客户需求的重要性。管理咨询公司规模有大有小,对创新、差异化和道德行为的关注度都不同,但该标准对所有管理咨询公司都有着重要的意义。该标准对客户也同样重要,它能帮助客户更好地了解咨询项目中管理咨询公司所提供服务的价值。

 

Guidelines for optimizing use of management consultancies just published

From improving processes to boosting profits, management consultancies can make a huge difference to the organizations they work with. Clarity and transparency are the keys to success -for both parties. A new standard just published aims to help.

Offering specialist sector knowledge and experience, it is no wonder more and more organizations are turning to management consultancies. Whether it be bringing a product to market, training staff or advising on an organizational overhaul, management consultancies offer a wide range of services and support. Their use has grown dramatically in recent years as businesses and governments look to improve their performance and processes.

ISO 20700, Guidelines for management consultancy services, draws on research and experience from a wide range of management consultancies worldwide and aims to increase transparency and effectiveness for both client and consultancy.

Robert Bodenstein, Chair of ISO/PC 280, Management Consultancy, the ISO project committee that developed the standard, whose secretariat is held by UNI, ISO’s member for Italy, said that it brings together industry best practice to help make management consultancies more effective.

“Management consultancies can bring valuable expertise to an organization, with their in-depth knowledge and broad experience of an industry, to help clients bring about growth or change more effectively. In this way, they make a strong contribution to the economy,” he said.

“This new standard is aimed at not only helping consultancies work even more effectively and efficiently, but helping with the development of the profession.”

ISO 20700 gives practical guidelines based on outcomes and emphasizes the importance of understanding clients’ needs. It is useful to all management consultancies, regardless of size, and maintains a focus on innovation, differentiation and ethical behaviour. It is also useful for clients in that it helps them better understand what they can expect from a management consultant in a consultancy project.

关于职业健康和安全国际标准进入公众评意草案第二稿

英国标准协会(BSI)已发布ISO 45001职业健康与安全管理体系——要求标准草案第二稿。

这一尚未发布的国际标准规定了职业健康与安全(OH&S)管理体系的要求,并为该标准的使用提供指南,旨在使组织能够提供安全健康的工作环境,以防止与工作有关的伤害和生病。

在5月19日是正式评议期之前,BSI商店已提供最新标准草案,从这个日期开始,可以访问网站http://shop.bsigroup.com/ProductDetail?pid=000000000030358994,使感兴趣的人提出宝贵意见。 

每年有二百万人因工作事故死亡,工作影响身体健康的人数大幅上升。尽管目前国际劳工标准得到广泛应用,但这些令人痛心的数字表明,为确保组织能够管理风险,改善职业健康与安全体系,保护各级工作人员身体健康,制定专门标准迫在眉睫。

ISO 45001包括职业健康与安全(OH&S)政策的制定、实施和目标,考虑到适用的法律要求和组织认可的其他要求。

国际标准将有助于为规模不同的各类组织提供明确框架,希望改善其职业健康与安全(OH&S)绩效,保护代表组织工作或受组织活动影响的人员。这些组织包括除个体商户以外的任何组织,以及与多家承包商、多个网站、志愿者或临时员工等合作的组织。

ISO 45001标准的优点:

通过国际认可,适用于全球所有组织;

与其他管理体系重要标准一致
指导组织设计一个适合自己的职业健康和安全管理系统

ISO 45001的制定以合作及协商一致方法为基础,综合考虑了各类组织、政府机构、工会和工人代表组织的意见。该标准最终将取代现行标准OHSAS 18001,后者规定了职业健康和安全管理最佳实践的最低要求。虽然OHSAS 18001在英国和国际上使用广泛,但其并非一个完整的国际标准。

BSI治理与恢复部负责人安妮.海斯(Anne Hayes)对负责制定健康与安全标准的部门进行监督。

安妮.海斯在BSI负责ISO 45001标准的核心市场,她表示:“职业健康与安全对全球所有企业(不论其规模和行业)而言都是一个严肃的问题,BSI很荣幸能够为希望维护或改善工作场所安全的企业提供一个明确的框架。”

“ISO 45001要与其他管理体系标准(如ISO 9001和ISO 14001)保持一致,这非常重要。因此,ISO 45001的共同文本和结构将确保这些管理体系标准均保持一致。”

负责制定ISO 45001的国际委员会包括来自50多个国家和20个联络机构的专家,他们拥有丰富的职业健康和安全知识和实践经验,清楚这一领域面临的挑战。新标准的制定基于ISO针对其所有管理体系标准(MSS)制定的核心结构和共同文本,统筹考虑了目前OHSAS 18001的要求、其他国家标准(包括美国、中国和加拿大标准)和国际劳工组织文件——世界各地数百个国家通过的职业健康与安全指导方针。

标准最终版预计在2017年底发布。

 

International standard on occupational health and safety reaches second draft for public comment stage

 

BSI, the business standards company, has published the second draft of ISO 45001 Occupational health and safety management systems – Requirements.

The yet-to-be launched international standard specifies requirements for an occupational health and safety (OH&S) management system, with guidance for its use, to enable an organization to provide safe and healthy working conditions for the prevention of work-related injury and ill health.

The latest draft is now available on the BSI shop, ahead of the formal commenting period which beings on 19 May. From this date the draft will be accessible, enabling those with an interest to submit comment: http://shop.bsigroup.com/ProductDetail?pid=000000000030358994

Two million people die yearly from work-related incidents and the number of people suffering life altering health conditions caused by their work is exponentially higher. These harrowing figures are in spite of widespread adoption of International Labour Standards, indicating a pressing need for a standard specifically designed to ensure organizations manage the risk and improve their OH&S to protect workers at all levels.

ISO 45001 includes the development and implementation of an OH&S policy and objectives which take into account applicable legal requirements and other requirements to which the organization subscribes.

The international standard will help provide a single, clear framework for organizations of all types and sizes who wish to improve their OH&S performance and protect those working on their behalf or who may be affected by the organization’s activities. This includes any organization beyond that of sole trader – and those organizations working with multiple contractors, multiple sites, volunteers or temporary staff, etc.

Benefits of ISO 45001 include:

A single internationally-agreed standard suitable for all organizations worldwide

Alignment with other key management system standards

Requirements which direct organizations to design a management system uniquely suited to each organization’s occupational health and safety needs

ISO 45001 has been developed using a collaborative, consensus-based approach, taking into account the views of large and small organizations, government bodies, trades unions and worker representative organizations. It will eventually replace OHSAS 18001, an existing standard which sets out the minimum requirements for occupational health and safety management best practice. Although OHSAS 18001 is widely used both in the UK and internationally it is not a full international standard.

Anne Hayes, Head of Governance and Resilience at BSI, oversees the sector which develops health and safety standards.

Anne Hayes, Head of Governance and Resilience at BSI, has engaged with BSI’s core markets regarding ISO 45001. She said: “Occupational health and safety is a serious matter for all businesses worldwide, regardless of their size or sector. BSI is proud to be involved with developing a clear framework for businesses wishing to maintain or improve safety within their workplaces.

“It is important that ISO 45001 works in alignment with other management system standards, such as ISO 9001 and ISO 14001. Therefore the common text and structure in which ISO 45001 is written will ensure these management system standards are broadly aligned."

The international committee which developed ISO 45001 includes experts from over 50 countries and 20 liaison bodies, all with knowledge and practical experience of occupational health and safety issues and the challenges faced. The new standard is based on the core structure and common text developed by ISO for all of its management system standards (MSS), taking into account the requirements of the current OHSAS 18001, other national standards (including those from the US, China and Canada) and the ILO instruments – OH&S guidelines adopted by hundreds of countries across the world.

Publication of the final standard is anticipated towards the end of 2017. 

BSI发布关于供应链可持续采购国际标准

英国标准协会(BSI)已发布ISO 20400:2017可持续采购——指南,旨在帮助组织履行其可持续发展的职责。ISO 20400概述了可持续采购的相关内容,以及组织如何实施可持续采购。

这项新的国际标准的关键在于要使供应链成为组织可持续发展目标的一个组成部分。ISO 20400详细列出了采购活动不同方面纳入的可持续性影响和考虑因素,适用于任何公共或私人组织,不论其规模大小和工作地点。

ISO 20400取代了BS 8903:2010可持续采购的原则和框架指南,新标准化的重要变化之一是将可持续性纳入采购过程中。新标准在更新过程中考虑到了一些新概念,如生命周期分析,尽职调查,共谋和全球成本。

随着组织越来越多地展示其环境、社会和经济影响,ISO 20400的采用说明了组织优先将可持续采购作为其日常业务的组成部分。对于任何旨在加强环保认证的组织来说,供应链是一个关键考虑因素,采用ISO 20400可能会提高其在客户、利益相关方和广大公众中的声誉。

BSI可持续市场发展部负责人David Fatscher说道:“随着供应链透明化的需求日益增长,可持续采购的全球效益比以往任何时候都更加明显。ISO 20400已经在六大洲的40多个国家的专家那里获得了最佳实践,并为全球挑战提供了全球性解决方案。该项标准以现有英国标准BS 8903为原型,这应该是使英国组织早日采用的优势。”

ISO 20400的实施可能惠及建设、设备管理、酒店服务、餐饮、服装、食品、公共采购、制造业、木材、印刷和造纸,以及包装等行业。

ISO 20400的实施最有可能惠及的用户包括资深采购人员,商业董事,财务总监,合同、招标和供应经理,供应链管理人员,可持续发展经理,环境/垃圾管理人员,业务经理和设施管理人员。

重要的是,该标准虽然概述了组织将采购有效步骤整合到现有采购方法中的途径,但并未建议改变采购方法本身。

ISO 20400标准的制定离不开来自40多个参与国专家的共同努力,同时还得到了经济合作与发展组织(OECD)、联合国环境规划署(UNEP)、可持续采购领导委员会(SPLC)、国际独立认证组织(IIOC)和国际工会联合会(ITUC)等主要国际组织的支持与帮助。

 

Sustainable procurement in supply chains addressed by new international standard

 

BSI, the business standards company, has launched ISO 20400:2017 Sustainable procurement – Guidance. Designed to assist organizations to meet their sustainability responsibilities, ISO 20400 outlines what sustainable procurement is, and how an organization can implement sustainable procurement practically.

The overarching concern of the new international standard is to make the supply chain integral to an organization’s sustainability goals. ISO 20400 outlines in detail the sustainability impacts and considerations that should be incorporated across the different aspects of procurement activity, and is applicable to any organization, either public or private, irrespective of its size or location.

ISO 20400 replaces BS 8903:2010 Principles and framework for procuring sustainably. Guide, and one of the key changes in the new standard is a section dealing specifically with integrating sustainability into the procurement process. It has been updated to take into consideration new concepts such as life cycle analysis, due diligence, complicity and global cost.

With organizations increasingly driven to demonstrate their environmental, social and economic impact, adoption of ISO 20400 is a tangible signal that the organization prioritizes sustainable procurement as integral to its day-to-day operations. Supply chains are a critical consideration for any organization aiming to bolster their environmental credentials, and adopting ISO 20400 would likely boost the reputation of an organization amongst their customers, stakeholders and the wider public.

David Fatscher, Head of Market Development for Sustainability at BSI, said: “As the need for supply chain transparency grows, the global benefits of sustainable procurement are more evident than ever. ISO 20400 has captured best practice from experts from over 40 countries on six continents and delivers a global solution to a global challenge. It has been closely modelled on the existing British standard BS 8903, which should place UK organizations at an advantage in its early adoption.”

Sectors particularly likely to benefit from implementing ISO 20400 include construction; facilities management; hospitality; catering; clothing; food; public procurement; manufacturing; timber; print and paper; and packaging.

Users most likely to benefit from ISO 20400 include senior procurement and purchasing professionals; commercial directors; finance directors; contract, tender and supply managers; supply chain managers; sustainability managers; environment/waste managers; operations managers; and facilities managers.

Importantly, while the standard outlines how an organization can integrate efficient procurement steps into its existing procurement methods, it does not make recommendations for changing the procurement methods themselves. 

As well as experts from over 40 participating countries, ISO 20400 was created with additional input from leading international organizations including the Organization for Economic Co-operation and Development (OECD); United Nations Environment Programme (UNEP); the Sustainable Purchasing Leadership Council (SPLC); Independent International Organization for Certification; and the International Trade Union Confederation (ITUC). 

ANSI征求利益相关方关于六月举办审计数据标准会议

美国技术咨询组(TAG)负责ISOPC 295项目委员会工作,拟在ANSI纽约办事处举行会议。

国际标准化组织(ISO)审计数据搜集项目委员会(ISO/PC 295)正在制定从会计和企业资源规划系统(ERP systems)交换信息的新标准。作为ISO的美国成员机构,美国国家标准协会(ANSI)已经与提高结构信息标准组织(OASIS)合作,成立了美国技术咨询小组(American TAG)。美国TAG由受文件影响的美国利益相关者组成。

ANSI要求所有受影响的利益相关方在6月13日到14日于ANSI纽约办事处举行的US.TAG专题会议上开展审查工作并提供反馈意见。这一会议旨在帮助专家最终确定他们对草案的意见,并为U.S.TAG.的成员构建知识基础。

该关键性时间段重要性不言而喻,这次会议也对观察员和其他有意加入U.S.TAG的人员开放,以便7月后开始提出具体的反馈意见。该项目的初始阶段将会注重联合全球力量来创造第一。

审计数据供应链的利益相关方如果希望推动审计数据标准达到美国和全球所有利益相关者的要求,并有意参与到此次专题会议,可以联系Kemi Allston (kallston@ansi.org)以获得相关信息。鉴于会场空间有限,参会邀请将优先考虑会计软件开发领域的数据建模专家,除此以外将会以报名先后顺序为主。

 

家具、汽车玻璃清洁液(玻璃水)等安全标准今年上半年修改完成

 -4月20日,产品安全审议委员会对事故预防安全标准修改案进行审议-

□产业通商资源部国家技术标准署(署长郑东熙)于2017年4月20日组织召开产品安全审议委员会会议,邀请与会专家就家具、汽车玻璃清洁液(玻璃水)等产品的安全标准修正案进行审议。

□本次会议中审议的产品,均为去年消费者认为会造成人身危害或易引发事故的产品。为降低此类产品的影响、提高产品的安全系数,国标院召开了本次审议委员会。

○家具方面,去年发生抽屉柜倾倒,对儿童造成伤害的事件出现的频率增高,但韩国国内没有相应标准规定,因此采用了美国的相关标准,对产品进行了安全系数调查并(对有问题的产品)进行了召回。

○玻璃清洁液方面,玻璃水在使用时,其中的甲醇成分可能会进入车厢内部对人体造成伤害,消费者对此表示了忧虑。

□国家技术标准署从消除消费者顾虑的角度出发,从去年下半年开始就安全标准修订问题进行了多次审议,收集有关各方的意见,并公布了立案预告。本次修订的安全标准主要事项如下:

○鉴于儿童有攀爬的可能性,因此要求家具中高度超过762mm的抽屉柜在负重23kg时 ,也不会发生倾倒。

*鉴于儿童有攀爬的可能性,引用美国ASTM规则。

○汽车用玻璃清洁液甲醇含量不能超过0.6%。

○鉴于百叶窗易引发窒息事故,因此百叶窗下端应距地面80cm以上。

*但是,在百叶窗使用固定装置时,百叶窗下端应距地面120cm以上。

微型赛车标准征求公众意见

澳大利亚标准AS 3533.4.4 游乐乘骑装置和设施——具体要求——特许微型赛车,现第三次向公众征求意见。

目前的AS 3533.4.4标准草案由微型赛车行业和有关技术委员会ME-051“游乐乘骑装置和设施”经过协商制定而成。

AS 3533.4.4标准草案中的主要更新内容包括:

l   现在包含碰撞试验协议的法规属于信息类,用于提供建议而不做强制性要求。

l   性能要求从试验标准和试验方法中分离出来。

公众意见能确保广大群众有机会在草案通过前审查该草案。我们欢迎所有感兴趣的民众提出相关宝贵意见。

意见提交方法见此链接。公众意见征集截止日期为2017年6月19日。

媒体联络  托林.马夸特(Torrin Marquardt)

          公共事务主任 02 9237 6159

 

Seeking comments on go-karts standard

The Australian Standard AS 3533.4.4, Amusement rides and devices—Specific requirements—Concession go-karts, is now open for a third round of public comment.

 The current draft was developed following further consultation with the go-kart industry and the relevant technical committee ME-051, Amusement Rides and Devices. 

 Following this consultation a new draft of AS 3533.4.4 was developed. Key changes to the draft include:

• Provisions covering crash test protocol are now informative, providing recommendations rather than necessary requirements • Performance requirements are separated from test criteria and test methods

 Public comment ensures that the broader community has an opportunity to review the draft prior to completion. We encourage everyone with an interest to comment on the document. 

 Instructions on how to submit a comment can be found through this link. The closing date for public comment is 19 June 2017. 

ISO发布可持续采购的第一项国际标准

可持续采购可以改善供应商的关系——以及你的业务。刚刚出版了用于可持续采购的ISO 20400标准,以帮助公司进行可持续采购,形成一种生活方式。

无论公司大小,采购在公司里扮演着重要的角色。公司从哪里购买东西对其业绩的影响与它所购买的影响一样大。确保供应商运营良好,操作规范——从工作条件、风险管理到环境影响——不仅能让生意兴旺,还能改善社区里每个人的生活。

可持续的采购需要做出符合公司需求的采购决策,以造福于公司、社会和环境。它包括确保公司的供应商遵守职业道德,确保购买的产品和服务是可持续的,确保这样的购买决定有助于解决社会、经济和环境问题。

ISO 20400,可持续采购——指南,是世界上第一项关于可持续采购国际标准,旨在帮助公司制定和实施可持续采购规范和政策。

ISO /PC277主席雅克.施拉姆(Jacques Schramm)是制定这一标准的项目委员会主席,他说可持续采购的好处是深远的。“对于企业来说依靠供应商来提供他们想要的东西是不够的。公司开始了解自己的供应商将会受益匪浅——也要了解他们的需求——以确保他们的要求切合实际,合作的供应商有良好的职业道德。”,他解释道。

“不理解整个供应链,也不管整个过程中的行为,其风险是巨大的。最好的情况是,产品质量低劣,存货破损。最糟糕的情况是,像2013年孟加拉国的拉纳广场发生的灾祸可能会重演。可持续采购有助于减少诸如此类的风险,鼓励买家和供应商紧密合作,为所有人提供更好的结果。”

ISO 20400为公司提供了指导方针,将可持续性贯穿到企业的采购政策和流程中。它是对可持续采购原则如责任、透明度、人权的尊重、道德行为等的一个诠释。

 

You are what you buy – the first International Standard for sustainable procurement just published

Sustainable purchasing can improve supplier relations – and your business. ISO 20400 for sustainable procurement has just been published to help organizations make sustainable purchasing a way of life.

Procurement plays a large role in any organization, large or small. Who an organization buys from has just as big an impact on its performance as what it buys. Ensuring suppliers have sound and ethical practices – across everything from working conditions and risk management to their environmental impact – has the potential to not only make businesses work better, but to improve the lives of everyone in the communities where they are situated.

Sustainable procurement entails making purchasing decisions that meet an organization’s needs in a way that benefits them, society and the environment. It involves ensuring that a company’s suppliers behave ethically, that the products and services purchased are sustainable and that such purchasing decisions help to address social, economic and environmental issues.

ISO 20400, Sustainable procurement – Guidance, is the world’s first International Standard for sustainable procurement and aims to help organizations develop and implement sustainable purchasing practices and policies.

Jacques Schramm, Chair of ISO/PC 277, the project committee that developed the standard, says the benefits of sustainable procurement can be far-reaching. “It is no longer enough for businesses to rely on suppliers to provide them with what they want, no questions asked. Organizations benefit greatly from getting to know their suppliers – understanding what their requirements are as well – to ensure their demands are not unrealistic and that the suppliers they work with have good, ethical practices,” he explains.

“The risks of not understanding and managing practices throughout the whole supply chain are great. At best, poor quality products or ruptures of stock can result. At worst, disasters like the Rana Plaza in Bangladesh in 2013 can happen. Sustainable procurement helps to minimize risks such as these by encouraging buyers and suppliers to work closely together for a better result for all.”

ISO 20400 provides guidelines for integrating sustainability into an organization’s procurement policy strategy and process, defining the principles of sustainable procurement such as accountability, transparency, respect for human rights and ethical behaviour.

ISO解决巨大噪音问题

住在喧嚣街道附近的人都会认同交通噪音是一个严重的麻烦。据世界卫生组织(WHO)的数据显示,交通噪音也会影响我们的健康,导致过早死亡。

在欧洲地区的西方国家,交通噪声污染每年导致超过一百万人丧失健康,使得他们处于亚健康、残疾或早夭的境况。WHO针对这一主题作了报告。但这一问题不仅限于欧洲,因为任何一个有交通区域和车辆使用率较高的国家,都会受此影响。

这个问题的最大诱因之一是轮胎碰到路面时发出的声音。当车速大于等于50km/h时,会产生最糟糕的轮胎/公路相互作用。对于轻型车辆来说,车速达30km/h时,这种状况便会发生。而对于其他安静的电动汽车来说,每一个速度范围内都可能发生。

联合国欧洲经济委员会已经发布了法律文件来控制轮胎噪音。这些文件在大多数的工业化国家都已经实施。然而,路面也是一个重要的变量,它和轮胎、车辆一样影响着交通噪音。

一些国家已经开始在易受高噪音影响的地区修改路面,但仍有很长的路要走。目前协商正在进行,以合法地限制路面产生的噪音,这一举措也得到了汽车和轮胎制造商的支持。

但为了将这些要求付诸实践,我们需要国际标准来统一且可靠地测量和监测道路路面对交通噪音的影响。ISO 1997年发布了第一个标准,但随着技术的进步和需求的变化,ISO在ISO 11819 – 2中颁布了一个新的方法,声学——路面对交通噪声影响的测量——第2部分:近场测量的方法。

乌尔夫.桑德伯格(Ulf Sandberg)是这项新标准的项目负责人,他说“新的研究方法更实用,更容易操作,特别是对于长距离的路面来说。”

这种新方法导致了ISO / TS 11819 – 3关于参考轮胎技术规范的制定。桑德伯格(Ulf Sandberg)解释道:“意识到我们还需要正确识别轮胎来提供可靠的、可再生的数据时,我们正在制定新的ISO 11819 – 2, 并且起草了ISO / TS 11819 – 3。”

然而,制定这些标准的ISO委员会更进一步。最近的研究表明,温度影响轮胎和路面噪声的排放。制定一个新的文件—-ISO / TS 13471 – 1,以说明这是在测量轮胎/道路噪音的时候也同样考虑温度的影响。

“控制道路噪音的需求受到越来越多的关注。例如,欧盟委员会现在要求其成员国定期报告主要道路上的交通噪音排放;如果发现这些交通噪音过大,还要求成员国制定减排计划。”桑德伯格(Ulf Sandberg)说,“这三个新文件为弄清楚路面对噪音污染的影响提供了有效的帮助。”

 

ISO tackles loud traffic noise

Anyone living near a busy road will agree that traffic noise is a serious nuisance. According to the World Health Organization (WHO), it can also affect our health and lead to premature death.

Traffic-related noise pollution accounts for over one million healthy years of life lost annually to ill health, disability or early death in the western countries of the European Region, states a WHO report on the subject. But this problem is not limited to Europe as it affects any country with traffic areas and high vehicle usage.   

One of the biggest contributors to this issue is the sound created when a tyre touches the pavement. The worst type of tyre/road interaction occurs at speeds of, or above, 50 km/h. For light vehicles, it starts at speeds as slow as 30 km/h while, for the otherwise quiet electric vehicles, it happens at every speed range.

The United Nations Economic Commission for Europe has issued legal limits to control tyre noise and these are in place in most industrialized countries. However, road surfaces are also an important variable, influencing traffic noise as much as tyres and vehicles do.

A few countries have started to modify road surfaces in areas vulnerable to high noise, but there is still a long way to go. Negotiations are currently underway to legally limit how much noise a road surface should generate, a move that is also backed by vehicle and tyre manufacturers. 

But in order to put these requirements into practice, we need International Standards to uniformly and reliably measure and monitor the influence of road surfaces on traffic noise. ISO published a first standard in 1997, but advances in technology and changing needs have led to the development of a new methodology in ISO 11819-2, Acoustics – Measurement of the influence of road surfaces on traffic noise – Part 2: The close-proximity method.

Ulf Sandberg, Project Leader for the new standard, says that “the new methodology is much more practical and easier to use, especially for long stretches of road”.

This new method led to the development of technical specification ISO/TS 11819-3 on reference tyres. Sandberg explains: “We were developing the new ISO 11819-2 when we realized that we also needed to identify tyres correctly to give reliable and reproducible data, so we created ISO/TS 11819-3.”

However, the ISO committee developing these standards went even further. Recent research has shown that temperature influences noise emission as much as tyres and road surface. A new document, ISO/TS 13471-1, was developed to account for the influence of temperature when measuring tyre/road noise.

“The need to control road noise is getting more and more attention. The European Commission, for example, now requires that member states regularly report traffic noise emission along major roads and that they develop abatement programmes if these are found to be excessive,” says Sandberg. “The three new documents offer a solid toolbox for identifying the contribution of road surfaces to noise pollution.”

 

衡量信息安全的有效性

—-ISO / IEC 27004标准解释了如何制定,评价和报告信息安全指标的结果

克莱尔.马钱德报道

在信息安全方面,我们多么谨慎都不为过。保护个人档案及商业敏感信息非常重要。但你又如何证明ISO/IEC 27001信息安全管理体系(ISMS)正在发挥作用?一项新的ISO/IEC国际标准也许能帮到你。

一、关于信息安全

ISO/IEC 27004阐述了如何建立测量过程,以及如何评价并报道信息安全度量的结果。

二、关于ISO/IEC 27004新版本

近日修订的ISO/IEC 27004:2016,信息安全——安全技术——信息安全管理——监测、测量、分析及评价为如何评估ISO/IEC 27001:2013,信息安全——安全技术——信息安全管理系统——需求的效益提供了指南。它阐述了如何建立并运用测量流程,以及如何评价和报道一组信息安全度量的结果。

ISO/IEC JTC 1/SC 27标准制定组的召集人爱德华.汉弗莱(Edward Humphreys)教授说道:“网络攻击是企业面临的最大风险之一,许多企业都采用ISO/IEC 27001标准来保护自己不受当今面临的各种网络攻击之害。这也是为什么ISO/IEC 27001改良版要为这些企业提供基础且实用的支持。

三、ISMS有效性洞见

安全度量可以提供一个ISMS有效性的洞见,它也因此成为人们的关注点。不论你是负责管理安全及报道的工程师或顾问,或是需要更多信息以做决策的管理人员,安全度量都是企业网络风险状况的一个重要交流媒介。

汉弗莱教授说:“企业需要帮助解决企业在信息安全管理上的投资是否有效这一问题,并与以下目标相一致:对网络风险做出反应、提防并应对不断变化的风险环境。这也是ISO/IEC 27004标准能充分发挥其优势的地方。”

四、好处多多

ISO/IEC 27004:2016说明了如何建构一个信息安全测量项目、如何选择测量内容、以及如何运用必要的测量流程。还包括不同测量类型的大量实例、以及如何评价它们的有效性。

五、企业采用ISO/IEC 27004标准的好处有:

加强问责;

提高信息安全效益、优化ISMS流程;

ISO/IEC 27001需求满足凭证及恰当的法律、规定及章程。

ISO/IEC 27004:2016将代替2009版本;ISO/IEC 27004:2016已被更新与扩展,以匹配ISO/IEC 27001:2013修订版,为企业提供更大的附加价值与信心。

ISO/IEC 27004:2016 was developed by Subcommittee 27: IT security techniques, of ISO/IEC Joint Technical Committee (JTC) 1, Information technology.

ISO/IEC 27004:2016由第27分技术委员会制定:第一ISO/IEC联合技术委员会(JTC)信息技术,信息技术制定。

 

Measuring effectiveness of information security

ISO/IEC 27004 explains how to develop, assess and report results of information security metrics

By Claire Marchand

You simply can’t be too careful when it comes to information security. Protecting personal records and commercially sensitive information is critical. But how can you tell that your ISO/IEC 27001 information security management system (ISMS) is making a difference? A new ISO/IEC International Standard can help you out.

information security

ISO/IEC 27004 explains how to develop measurement processes and how to assess and report results of information security metrics

New edition of ISO/IEC 27004

The recently updated ISO/IEC 27004:2016, Information technology – Security techniques – Information security management – Monitoring, measurement, analysis and evaluation, provides guidance on how to assess the performance of ISO/IEC 27001:2013, Information technology — Security techniques — Information security management systems — Requirements. It explains how to develop and operate measurement processes, and how to assess and report the results of a set of information security metrics.

Prof. Edward Humphreys, Convenor of the working group that developed the standard (ISO/IEC JTC 1/SC 27), says: “Cyber-attacks are among the greatest risks an organization can face. This is why the much improved version of ISO/IEC 27004 provides essential and practical support to the many organizations that are implementing ISO/IEC 27001 to protect themselves from the growing diversity of security attacks that business is facing today.”

Insights into effectiveness of ISMS

Security metrics can provide insights regarding the effectiveness of an ISMS and, as such, have taken centre stage. Whether you’re an engineer or consultant responsible for security and reporting to management or an executive who needs better information for decision making, security metrics have become an important vehicle for communicating the state of an organization’s cyber risk posture.

In Prof. Humphreys’ own words, “Organizations need help to address the question of whether the organization’s investment in information security management is effective, fit for purpose to react, defend and respond to the continually changing cyber-risk environment. This is where ISO/IEC 27004 can provide numerous advantages.”

Many benefits

ISO/IEC 27004:2016 shows how to construct an information security measurement programme, how to select what to measure, and how to operate the necessary measurement processes. It includes extensive examples of different types of measures, and how the effectiveness of these measures can be assessed.

Among the many benefits to organizations of using ISO/IEC 27004 are:

Increased accountability

Improved information security performance and ISMS processes

Evidence of meeting requirements of ISO/IEC 27001, as well as applicable laws, rules and regulations

ISO/IEC 27004:2016 replaces the 2009 edition; it has been updated and extended to align with the revised version of ISO/IEC 27001:2013 to provide organizations with greater added value and confidence.

ISO/IEC 27004:2016 was developed by Subcommittee 27: IT security techniques, of ISO/IEC Joint Technical Committee (JTC) 1, Information technology.

 

衡量信息安全的有效性

—-ISO / IEC 27004标准解释了如何制定,评价和报告信息安全指标的结果

克莱尔.马钱德报道

在信息安全方面,我们多么谨慎都不为过。保护个人档案及商业敏感信息非常重要。但你又如何证明ISO/IEC 27001信息安全管理体系(ISMS)正在发挥作用?一项新的ISO/IEC国际标准也许能帮到你。

一、关于信息安全

ISO/IEC 27004阐述了如何建立测量过程,以及如何评价并报道信息安全度量的结果。

二、关于ISO/IEC 27004新版本

近日修订的ISO/IEC 27004:2016,信息安全——安全技术——信息安全管理——监测、测量、分析及评价为如何评估ISO/IEC 27001:2013,信息安全——安全技术——信息安全管理系统——需求的效益提供了指南。它阐述了如何建立并运用测量流程,以及如何评价和报道一组信息安全度量的结果。

ISO/IEC JTC 1/SC 27标准制定组的召集人爱德华.汉弗莱(Edward Humphreys)教授说道:“网络攻击是企业面临的最大风险之一,许多企业都采用ISO/IEC 27001标准来保护自己不受当今面临的各种网络攻击之害。这也是为什么ISO/IEC 27001改良版要为这些企业提供基础且实用的支持。

三、ISMS有效性洞见

安全度量可以提供一个ISMS有效性的洞见,它也因此成为人们的关注点。不论你是负责管理安全及报道的工程师或顾问,或是需要更多信息以做决策的管理人员,安全度量都是企业网络风险状况的一个重要交流媒介。

汉弗莱教授说:“企业需要帮助解决企业在信息安全管理上的投资是否有效这一问题,并与以下目标相一致:对网络风险做出反应、提防并应对不断变化的风险环境。这也是ISO/IEC 27004标准能充分发挥其优势的地方。”

四、好处多多

ISO/IEC 27004:2016说明了如何建构一个信息安全测量项目、如何选择测量内容、以及如何运用必要的测量流程。还包括不同测量类型的大量实例、以及如何评价它们的有效性。

五、企业采用ISO/IEC 27004标准的好处有:

加强问责;

提高信息安全效益、优化ISMS流程;

ISO/IEC 27001需求满足凭证及恰当的法律、规定及章程。

ISO/IEC 27004:2016将代替2009版本;ISO/IEC 27004:2016已被更新与扩展,以匹配ISO/IEC 27001:2013修订版,为企业提供更大的附加价值与信心。

ISO/IEC 27004:2016 was developed by Subcommittee 27: IT security techniques, of ISO/IEC Joint Technical Committee (JTC) 1, Information technology.

ISO/IEC 27004:2016由第27分技术委员会制定:第一ISO/IEC联合技术委员会(JTC)信息技术,信息技术制定。

 

Measuring effectiveness of information security

ISO/IEC 27004 explains how to develop, assess and report results of information security metrics

By Claire Marchand

You simply can’t be too careful when it comes to information security. Protecting personal records and commercially sensitive information is critical. But how can you tell that your ISO/IEC 27001 information security management system (ISMS) is making a difference? A new ISO/IEC International Standard can help you out.

information security

ISO/IEC 27004 explains how to develop measurement processes and how to assess and report results of information security metrics

New edition of ISO/IEC 27004

The recently updated ISO/IEC 27004:2016, Information technology – Security techniques – Information security management – Monitoring, measurement, analysis and evaluation, provides guidance on how to assess the performance of ISO/IEC 27001:2013, Information technology — Security techniques — Information security management systems — Requirements. It explains how to develop and operate measurement processes, and how to assess and report the results of a set of information security metrics.

Prof. Edward Humphreys, Convenor of the working group that developed the standard (ISO/IEC JTC 1/SC 27), says: “Cyber-attacks are among the greatest risks an organization can face. This is why the much improved version of ISO/IEC 27004 provides essential and practical support to the many organizations that are implementing ISO/IEC 27001 to protect themselves from the growing diversity of security attacks that business is facing today.”

Insights into effectiveness of ISMS

Security metrics can provide insights regarding the effectiveness of an ISMS and, as such, have taken centre stage. Whether you’re an engineer or consultant responsible for security and reporting to management or an executive who needs better information for decision making, security metrics have become an important vehicle for communicating the state of an organization’s cyber risk posture.

In Prof. Humphreys’ own words, “Organizations need help to address the question of whether the organization’s investment in information security management is effective, fit for purpose to react, defend and respond to the continually changing cyber-risk environment. This is where ISO/IEC 27004 can provide numerous advantages.”

Many benefits

ISO/IEC 27004:2016 shows how to construct an information security measurement programme, how to select what to measure, and how to operate the necessary measurement processes. It includes extensive examples of different types of measures, and how the effectiveness of these measures can be assessed.

Among the many benefits to organizations of using ISO/IEC 27004 are:

Increased accountability

Improved information security performance and ISMS processes

Evidence of meeting requirements of ISO/IEC 27001, as well as applicable laws, rules and regulations

ISO/IEC 27004:2016 replaces the 2009 edition; it has been updated and extended to align with the revised version of ISO/IEC 27001:2013 to provide organizations with greater added value and confidence.

ISO/IEC 27004:2016 was developed by Subcommittee 27: IT security techniques, of ISO/IEC Joint Technical Committee (JTC) 1, Information technology.

 

最全最新的标准分享平台

客服微信:1093451816返回首页