Simplify the process of identifying and understanding changes between standards revisions with ANSI's ISO Redlines packages. These collections combine current and previous editions of leading ISO standards with redline documents that clearly identify revisions, additions, and deletions between versions. Ideal for quality, environmental, occupational health and safety, energy, and other management system professionals, ISO Redlines packages simplify standards comparison, support transition planning, and help organizations understand new requirements with greater efficiency and confidence. Whether you are preparing for certification updates, assessing compliance impacts, or managing system changes, these packages provide a streamlined approach to standards revision analysis and implementation.
This document specifies requirements for a quality management system when an organization: a) needs to demonstrate its ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements, and b) aims to enhance customer satisfaction through the effective application of the system, including processes for improvement of the system and the assurance of conformity to customer and applicable statutory and regulatory requirements. All the requirements of this document are generic and are intended to be applicable to any organization, regardless of its type or size, or the products and services it provides. (INCLUDES REDLINE VERSION)
This document establishes the fundamental concepts and principles of quality management which are universally applicable to the following: organizations seeking sustained success through the implementation of a quality management system (QMS); customers seeking confidence in an organization’s ability to consistently provide products and services conforming to their requirements; organizations seeking confidence in their supply chain that product and service requirements will be met; organizations and interested parties seeking to improve communication through a common understanding of the vocabulary used in quality management; organizations performing conformity assessments against the requirements of ISO 9001; providers of training, assessment or advice in quality management; developers of related standards. This document defines terms that apply to all quality management documents and QMS standards developed by ISO/TC 176. This document is applicable to all organizations, regardless of size, complexity or business model.
This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.
ISO/IEC 17025:2017 specifies the general requirements for the competence, impartiality and consistent operation of laboratories. ISO/IEC 17025:2017 is applicable to all organizations performing laboratory activities, regardless of the number of personnel. Laboratory customers, regulatory authorities, organizations and schemes using peer-assessment, accreditation bodies, and others use ISO/IEC 17025:2017 in confirming or recognizing the competence of laboratories.
ISO 14001 specifies the requirements for an environmental management system that an organization can use to enhance its environmental performance. ISO 14001 is intended for use by an organization seeking to manage its environmental responsibilities in a systematic manner that contributes to the environmental pillar of sustainability. ISO 14001 helps an organization achieve the intended outcomes of its environmental management system, which provide value for the environment, the organization itself and interested parties. Consistent with the organization's environmental policy, the intended outcomes of an environmental management system include: · enhancement of environmental performance; · fulfillment of compliance obligations; · achievement of environmental objectives. ISO 14001 is applicable to any organization, regardless of size, type and nature, and applies to the environmental aspects of its activities, products and services that the organization determines it can either control or influence considering a life cycle perspective. ISO 14001 does not state specific environmental performance criteria. ISO 14001 can be used in whole or in part to systematically improve environmental management. Claims of conformity to ISO 14001, however, are not acceptable unless all its requirements are incorporated into an organization's environmental management system and fulfilled without exclusion.
ISO/IEC 27000:2018 provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, not-for-profit organizations).
The terms and definitions provided in this document
- cover commonly used terms and definitions in the ISMS family of standards;
- do not cover all terms and definitions applied within the ISMS family of standards; and
- do not limit the ISMS family of standards in defining new terms for use.
This document gives guidance on auditing management systems, including the principles of auditing, managing an audit programme and conducting management system audits, as well as guidance on the evaluation of competence of individuals involved in the audit process. These individuals include those managing the audit programme, auditors and audit teams. It is applicable to all organizations that need to plan and conduct audits of management systems or manage an audit programme. The application of this document to other types of audits is possible, provided that special consideration is given to the specific competence needed and the objectives to be achieved.
This document specifies terminology, principles and a process for risk management of medical devices, including software as a medical device and in vitro diagnostic medical devices. The process described in this document intends to assist manufacturers of medical devices to identify the hazards associated with the medical device, to estimate and evaluate the associated risks, to control these risks, and to monitor the effectiveness of the controls. The requirements of this document are applicable to all phases of the life cycle of a medical device. The process described in this document applies to risks associated with a medical device, such as risks related to biocompatibility, data and systems security, electricity, moving parts, radiation, and usability. The process described in this document can also be applied to products that are not necessarily medical devices in some jurisdictions and can also be used by others involved in the medical device life cycle. This document does not apply to: — decisions on the use of a medical device in the context of any particular clinical procedure; or — business risk management. This document requires manufacturers to establish objective criteria for risk acceptability but does not specify acceptable risk levels. Risk management can be an integral part of a quality management system. However, this document does not require the manufacturer to have a quality management system in place. NOTE Guidance on the application of this document can be found in ISO/TR 24971.
This document provides a reference set of generic information security controls including implementation guidance. This document is designed to be used by organizations: a) within the context of an information security management system (ISMS) based on ISO/IEC27001; b) for implementing information security controls based on internationally recognized best practices; c) for developing organization-specific information security management guidelines.
ISO 31000:2018 provides guidelines on managing risk faced by organizations. The application of these guidelines can be customized to any organization and its context. ISO 31000:2018 provides a common approach to managing any type of risk and is not industry or sector specific. ISO 31000:2018 can be used throughout the life of the organization and can be applied to any activity, including decision-making at all levels.
This document specifies a methodology and provides related requirements, recommendations and guidance for the design and integration of safety related parts of control systems (SRP/CS) that perform safety functions, including the design of software. This document applies to SRP/CS for high demand and continuous modes of operation including their subsystems, regardless of the type of technology and energy (e.g. electrical, hydraulic, pneumatic, and mechanical). This document does not apply to low demand mode of operation. NOTE 1 See 3.1.44 and the IEC 61508 series for low demand mode of operation. This document does not specify the safety functions or required performance levels (PL r ) that are to be used in particular applications. NOTE 2 This document specifies a methodology for SRP/CS design without considering if certain machinery (e.g. mobile machinery) has specific requirements. These specific requirements can be considered in a Type C standard. This document does not give specific requirements for the design of products/components that are parts of SRP/CS. Specific requirements for the design of some components of SRP/CS are covered by applicable ISO and IEC standards. This document does not provide specific measures for security aspects (e.g. physical, IT-security, cyber security). NOTE 3 Security issues can have an effect on safety functions. See ISO/TR 22100-4 and IEC/TR 63074 for further information.
This Redline version compares the Second edition to First edition. This document specifies principles and requirements at the organization level for the quantification and reporting of greenhouse gas (GHG) emissions and removals. It includes requirements for the design, development, management, reporting and verification of an organization's GHG inventory. The ISO 14064 series is GHG programme neutral. If a GHG programme is applicable, requirements of that GHG programme are additional to the requirements of the ISO 14064 series.
This document provides guidance on the development, implementation and maintenance of a risk management system for medical devices according to ISO 14971:2019. The risk management process can be part of a quality management system, for example one that is based on ISO 13485:2016 [ 24 ] , but this is not required by ISO 14971:2019. Some requirements in ISO 13485:2016 (Clause 7 on product realization and 8.2.1 on feedback during monitoring and measurement) are related to risk management and can be fulfilled by applying ISO 14971:2019. See also the ISO Handbook: ISO 13485 : 2016 Medical devices A practical guide [ 25 ] .
This Redline version compares the Second edition to First edition This document is intended to be applied to safety-related systems that include one or more electrical and/or electronic (E/E) systems and that are installed in series production road vehicles, excluding mopeds. This document does not address unique E/E systems in special vehicles such as E/E systems designed for drivers with disabilities. NOTE Other dedicated application-specific safety standards exist and can complement the ISO 26262 series of standards or vice versa. Systems and their components released for production, or systems and their components already under development prior to the publication date of this document, are exempted from the scope of this edition. This document addresses alterations to existing systems and their components released for production prior to the publication of this document by tailoring the safety lifecycle depending on the alteration. This document addresses integration of existing systems not developed according to this document and systems developed according to this document by tailoring the safety lifecycle. This document addresses possible hazards caused by malfunctioning behaviour of safety-related E/E systems, including interaction of these systems. It does not address hazards related to electric shock, fire, smoke, heat, radiation, toxicity, flammability, reactivity, corrosion, release of energy and similar hazards, unless directly caused by malfunctioning behaviour of safety-related E/E systems. This document describes a framework for functional safety to assist the development of safety-related E/E systems. This framework is intended to be used to integrate functional safety activities into a company-specific development framework. Some requirements have a clear technical focus to implement functional safety into a product; others address the development process and can therefore be seen as process requirements in order to demonstrate the capability of an organization with respect to functional safety. This document defines the vocabulary of terms used in the ISO 26262 series of standards.