Procedure for AMS Document Control

Details

DateVersionStatusInformation ClassificationDocument Template IDDocument No
15-11-20191.8ApprovedInternalAMS DOCAMS-CP-01

Revision History

DateVersionDescriptionAuthorReviewed byApproved byApproved date
29-03-20121.0This procedure supersedes and replaces procedure QP 018 – procedure for control of documents and records.Procedure revised to integrate related ISO 9001:2008 and ISO 27001:2005 ISMS requirements
14-01-20131.1Document Change Request Form: AMS-CF-01 for Major changes and e-mail communication with details of changes incorporated withinPremanandPremanandPremanand
24-06-20131.2Document owner to check the correctness of the changed and approved document uploaded by MR in the active folder of the repository. Document owner to intimate MR for any discrepancies with respect to version control and approval
04-06-20151.3Changed ISO/IEC 27001:2005 to ISO/IEC 27001:2013. Ref internal audit finding of May 2015.
15-07-20151.4Changed as per BSI audit findings
17-03-20161.5Reviewed, no changes recommended
09-08-20171.6Reviewed, word “shall” has been replaced suitably
23-11-20181.7No Changes
14-11-20191.8Changes made as per the standard DocumentShailaShaila/UshaSuresh Kumar B V15-11-2019

Acronym Used

AcronymExpanded Form
QMSQuality Management System
ISMSInformation Security Management System
AMSAntares Management System (QMS + ISMS)
ASLAntares Systems Limited, Bangalore
CISOChief Information Security Officer
M.RManagement representative
HODHead of the Department
CEOChief Executive Officer

Introduction

This procedure describes the procedures for control of AMS documents. The purpose of this procedure is to define the activities required to ensure all documents, and records of quality and information security management systems are reviewed and approved by authorized personnel prior to issue and that they are protected and controlled

Reference

  • ISO 27001:2013 Clause 7.5

  • ISO 9001:2015 Clause 7.5

Key Practices & Responsibility

The key practices and responsibilities are as follows:

Srl.Key PracticeResponsibility
Responsibility for Developing and Maintaining AMSProcess Owners, Quality Team
AMS Document IdentificationProcess Owners, Quality Team
Developing and Maintaining AMSQuality Team, Process owners
ISMS Document Storage and ArchivalQuality Team
ISMS Document Issue and ControlQuality Team

Key Practice Details

Responsibility for Developing and Maintaining AMS

  • Development of AMS is facilitated by Quality Team.

  • Quality Team will provide the process documentation standards and templates for developing the AMS documents.

  • The developments of AMS documents are done by Quality Team and process owners identified from various functions of the organization.

  • Quality Team will also verify the AMS artifacts developed by process owners are consistent with ASL's process documentation standards.

  • Quality Team will be the custodian for AMS artifacts.

  • Quality Team will maintain a master list of AMS artifacts Vs the process owners Vs reviewers and approvers for maintaining and approving AMS artifacts using the Master List of Documents template.

AMS Document Identification

  • Process Owners in consultation with Quality Team are responsible for identifying the documents required for defining and establishing the AMS.

  • The AMS documents include the following:

+-------------+-----------------+-----------------+-----------------+ | Sl. No. | > Document | > Numbering | > Remarks | | | > Description | > System | | +-------------+-----------------+-----------------+-----------------+ | | > Level 1 | | | +-------------+-----------------+-----------------+-----------------+ | | > Integrated | > AMS 01 | > AMS = | | | > Management | | > Integrated | | | > System (AMS) | | > Management | | | > Manual | | > System | +-------------+-----------------+-----------------+-----------------+ | | > Quality | > AMS-- | > QMS -- | | | > Policy | > QMS-PL-01 | > Quality | | | | | > Management | | | | | > System | +-------------+-----------------+-----------------+-----------------+ | | > ISMS Policy | > A | > ISMS = | | | | MS-ISMS-PL-01 | > Information | | | | | > Security | | | | | > | | | | | > Management | | | | | > System | | | | | > | | | | | > PL = | | | | | > Policy | | | | | > | | | | | > XX = Serial | | | | | > number | | | | | > assigned to | | | | | > it | +-------------+-----------------+-----------------+-----------------+ | | > Quality | > AMS-- QMS-- | > QO = | | | > Objectives | > QO-XX | > Quality | | | | | > Objectives | +-------------+-----------------+-----------------+-----------------+ | | > ISMS | > AMS-- | > QO = | | | > Objective | > ISMS-- | > Quality | | | | > QO-XX | > Objectives | +-------------+-----------------+-----------------+-----------------+ | | > Statement of | > AM | > ISMS = | | | > Applicability | S-ISMS-SOA-XX | > Information | | | > (ISMS) | | > Security | | | | | > | | | | | > Management | | | | | > System | | | | | > | | | | | > SOA = | | | | | > Statement of | | | | | > | | | | | Applicability | | | | | > | | | | | > 01 = Serial | | | | | > number | | | | | > assigned to | | | | | > it | +-------------+-----------------+-----------------+-----------------+ | | > Level 2 | | | +-------------+-----------------+-----------------+-----------------+ | | > AMS System | > AMS -- QP- | > QP = | | | > Procedures | > XX | > Quality | | | | > | > Procedure | | | | > AMS -- SP | > | | | | > -- XX | > SM -- | | | | > | > Security | | | | > AMS -- CP | > Procedure | | | | > -XX | > | | | | | > XX = Serial | | | | | > Number | | | | | > assigned to | | | | | > it | +-------------+-----------------+-----------------+-----------------+ | | > Business | > | > XX = Serial | | | > Continuity | AMS-BCP-XX | > Number | | | > Plan | | > assigned to | | | | | > it | +-------------+-----------------+-----------------+-----------------+ | | > Level 3 | | | +-------------+-----------------+-----------------+-----------------+ | | > Master List | > AMS-ML-01 | > AAA = | | | | > | > Originator / | | | | > | > Function or | | | | AMS-ML-EXT-01 | > Dept. | | | | | > | | | | | > ML = Master | | | | | > list | | | | | > | | | | | > EXT = | | | | | > External | +-------------+-----------------+-----------------+-----------------+ | | > Check List | > | > CL=Check | | | | AMS-AAA-CL-XX | > List | +-------------+-----------------+-----------------+-----------------+ | | > Asset | > AMS-AR-XX | > AR= Asset | | | > Register | | > Register | +-------------+-----------------+-----------------+-----------------+ | | > Risk | > AMS-RA-XX | > RA=Risk | | | > Assessment | | > Assessment | | | > Register | | | +-------------+-----------------+-----------------+-----------------+ | | > Risk | > | > RTP=Risk | | | > Treatment | AMS-RTP-XX | > Treatment | | | > Plan | | > Plan | +-------------+-----------------+-----------------+-----------------+ | | > Work | > A | > AAA = | | | > Instructions | MS-AAA-SOP-XX | > Originating | | | > / Standard | | > Function or | | | > Operating | | > Dept. | | | > Procedures | | > | | | | | > SOP = | | | | | > Standard | | | | | > Operating | | | | | > Procedure | | | | | > | | | | | > XX = Serial | | | | | > Number | | | | | > assigned to | | | | | > it | +-------------+-----------------+-----------------+-----------------+ | | > Level 4 | | | +-------------+-----------------+-----------------+-----------------+ | | > | > AMS-QF-XX | | | | Forms/Templates | > | | | | | > AMS-SF- | | | | | > XX | | | | | > | | | | | > AMS-CF-XX | | +-------------+-----------------+-----------------+-----------------+ | | > | > Identified | | | | Miscellaneous: | > by Title and | | | | > | > Date | | | | Communications | | | | | > etc., | | | +-------------+-----------------+-----------------+-----------------+

  • The AMS documents may be in one of two states:

    • Draft: An unapproved document will be in "Draft" state.

    • Controlled: An approved document will be in "Controlled" state.

  • All AMS documents will have a version number in X.Y format where Xis the major release number and Y is the minor release number. The major release number (X) will be incremented for every major change of ISMS where revisions across AMS documents are seen whereas the minor release number (Y) will be incremented for revision/change of individual documents. The decision on what constitutes a major release is taken by the Antares Management Forum/CISO.

  • All AMS documents will include revision history that describes the following:

    • Date of revision

    • Version number

    • Description of changes

    • References to change (e.g. Document Change Request)

    • Author for the revision

    • Reviewers for the revision

    • Approver name

Developing and Maintaining AMS

  • The initial version of AMS is developed by the Process Owners (Respective Department Representatives) and Quality Team.

  • Requests for changes to AMS are submitted to Quality team using Document Change Request form. The request for changes may arise from:

    • Planned process improvement initiatives.

    • Findings from internal and external audits and assessments.

    • Suggestions from employees for process improvements.

  • The document preparation and approval authority is as follows:

+---------+----------+----------+----------+----------+----------+ | Sl. | > Do | > Pre | > | > Ap | > | | | cument | paration | Review | proval | Issue | | No. | | > / | > | > | > | | | | > Re | Responsi | > Aut | Responsi | | | | vision | bility | hority | bility | | | | > | | | | | | | > | | | | | | | Responsi | | | | | | | bility | | | | +=========+==========+==========+==========+==========+==========+ | 1 | > AMS | > MR | > | > CEO | > MR | | | > Manual | > /CISO | MR/CISO | | > /CISO | +---------+----------+----------+----------+----------+----------+ | 2 | > ISMS | > MR./ | > CEO | > CEO | > MR | | | > Policy | > CISO | | | > /CISO | | | > / | | | | | | | > | | | | | | | Quality | | | | | | | > Policy | | | | | +---------+----------+----------+----------+----------+----------+ | 3 | > | > MR. | > CEO | > CEO | > MR | | | Quality | | | | | | | > Ob | | | | | | | jectives | | | | | +---------+----------+----------+----------+----------+----------+ | 4 | > S | > CISO | CISO | CEO | CISO | | | tatement | | | | | | | > of | | | | | | | > Appli | | | | | | | cability | | | | | +---------+----------+----------+----------+----------+----------+ | 6 | > AMS | > Re | > Re | > | > MR | | | > Pr | spective | spective | CEO/CISO | > /CISO | | | ocedures | > Dept. | > Dept. | | | | | | > Rep | > | | | | | | | Rep/CISO | | | +---------+----------+----------+----------+----------+----------+ | 7 | > BCP | > | CISO & | CEO | CISO | | | | CRO/BCP | Dept | | | | | | > Mai | Heads | | | | | | ntenance | | | | | | | > coo | | | | | | | rdinator | | | | +---------+----------+----------+----------+----------+----------+ | 8 | > | > Re | > Re | > | > CISO | | | ISMS/QMS | spective | spective | CISO/CEO | | | | > Domain | > Dept. | > Dept. | | | | | > | > Rep | > | | | | | Specific | | Rep/CISO | | | | | > Pol | | | | | | | icies/Pr | | | | | | | ocedures | | | | | +---------+----------+----------+----------+----------+----------+ | 9 | > Level | > Re | > Re | > Fu | > MR | | | > 2/3/4 | spective | spective | nctional | > /CISO | | | > D | > Dept. | > Dept. | > Head | | | | ocuments | > Rep | > Rep | | | +---------+----------+----------+----------+----------+----------+

  • Initial analysis of the Change Request will be done by the Quality Team to identify the area of impact and the impacted items. The Process Change Request is then forwarded to the identified Process Owner for further analysis and approval.

  • A detailed analysis of the change request is done by relevant Process Owner in consultation with Quality Team (if required). The results of the detailed analysis are reviewed with Quality Team to decide on approval/rejection, priority for implementation and owner for the process change.

  • If the change request is approved for implementation:

    • Quality Team will check out the impacted AMS artifacts from Common Repository for revision and update.

    • The Process Owner/ Quality Team will modify/revised the impacted AMS artifacts.

    • The revised/updated AMS artifacts are reviewed by identified reviewers.

    • The reviewed artifacts will be approved by the respective process owner.

    • Quality Team will check-in the approved artifacts into Common Repository.

    • Quality Team will send change request to the requestor for closure.

  • Irrespective of the revisions made, the complete AMS documentation will be subjected to review at least once a year to determine its continued suitability or the need for revision.

AMS Document Storage and Archival

  • The AMS documents are placed under configuration control Common Repository.

  • Quality Team is responsible for AMS document control.

  • Quality Team will backup and archive AMS documents whenever new releases are made.

  • The Organisation/respective functions may retain a copy of obsolete documents in electronic media for legal or reference purpose. Whenever obsolete documents are retained in hard copy, such documents will be duly identified as "OBSOLETE".

AMS Document Issue and Control

  • AMS Document issue will be in soft copy mode though controlled access to employees via the organization's Intranet or through controlled access to Common repository.

  • AMS Documents will not be issued in hard copy

  • Quality Team is responsible for deploying the revised AMS documents in the organization's Intranet.

  • Quality Team will notify the changes to all or impacted employees.

  • If significant changes are made to the AMS, the Process Owners, in coordination with HR/Training Function, conduct training sessions to train the affected groups.

  • Responsibility for the control of various documents of external origin is as given below:

+---------+------------------+------------------+------------------+ | Sl. | Type of | Custodian | > Distribution | | | external | | > Control | | No. | document | | | +=========+==================+==================+==================+ | 1 | Management | MR/ CISO | > Copies can be | | | System | | > issued for | | | Standards | | > training | | | | | > purpose only. | | | | | > When published | | | | | > on intranet, | | | | | > it will be | | | | | > protected | | | | | > against | | | | | > printing | | | | | > /copying | | | | | > /downloading. | +---------+------------------+------------------+------------------+ | 2 | Equipment | Concerned user | > Copies can be | | | manual / OEM | department | > issued for | | | guidelines | | > internal use | | | | | > only. When | | | | | > published on | | | | | > intranet, it | | | | | > will be | | | | | > protected | | | | | > against | | | | | > printing | | | | | > /copying | | | | | > /downloading. | +---------+------------------+------------------+------------------+ | 3 | Legal Consents | Concerned HOD | > Copy | | | / Permits | | > distribution | | | | | > should be | | | | | > restricted to | | | | | > relevant | | | | | > authorities | +---------+------------------+------------------+------------------+ | 4 | National / | Concerned user | > Copies can be | | | International | department | > issued for | | | Standards | | > training | | | relating to | | > purpose only. | | | product / | | > When published | | | process | | > on intranet, | | | | | > it will be | | | | | > protected | | | | | > against | | | | | > printing | | | | | > /copying | | | | | > /downloading. | +---------+------------------+------------------+------------------+ | 5 | Legal | Concerned user | > Copies can be | | | notifications | department | > issued for | | | and copies of | | > training | | | applicable laws | | > purpose only. | | | | | > When published | | | (Priced | | > on intranet, | | | edition) | | > it will be | | | | | > protected | | | | | > against | | | | | > printing | | | | | > /copying | | | | | > /downloading. | +---------+------------------+------------------+------------------+ | 6 | Legal | Concerned user | > Controls | | | notifications | department | > currently not | | | and copies of | | > applicable as | | | applicable laws | | > it is freely | | | | | > available in | | | (Free download | | > public | | | edition | | > domain. | | | published on | | | | | internet) | | | +---------+------------------+------------------+------------------+

References

Srl.Document/Section Name
Procedure for Information Classification and Handling
Procedure for Safeguarding Organizational Records
Procedure for Backup and Recovery

Implementation Artifacts

Srl.Template IDArtifact Name
F-DCRDocument Change Request