您被要求对客户公司的 QA 系统进行审核,概述并讨论您将进行的审核的关键要素。说明如果审核的某些方面不符合 ISO9001 标准,您可能采取的 QA 预防措施(10 分) 关键要素:

  1. 物理和环境审查——这包括物理安全、电源、空调、湿度控制和其他环境因素。
  2. 系统管理审查——这包括对操作系统、数据库管理系统、所有系统管理程序和合规性的安全审查。
  3. 应用软件审查——业务应用可以是工资单、发票、基于网络的客户订单处理系统或实际运行业务的企业资源规划系统。
  4. 网络安全审查——审查与系统的内部和外部连接、周边安全、防火墙审查、路由器访问控制列表、端口扫描和入侵检测是一些典型的覆盖领域。
  5. 业务连续性审查——这包括容错和冗余硬件、备份程序和存储的存在和维护,以及记录和测试的灾难恢复/业务连续性计划。
  6. 数据完整性审查——其目的是审查实时数据,以验证控制的充分性和弱点的影响,正如上述任何审查所注意到的那样。这种实质性测试可以使用通用审计软件(例如,计算机辅助审计技术)来完成。 审计的覆盖范围可能会有所不同。例如,它可能只检查这些元素中的一个或上一张幻灯片中描述的所有或部分组件的程度。覆盖所有元素很重要,但它们不需要在一个作业中完成。每个元素所需的技能组合是不同的。有时可能取决于客户


You have been asked to conduct an audit of the QA system in a client company, outline and discuss the key elements of the audit you will conduct. Explain the QA precautionary actions you may take if some aspects of the audit are not to ISO9001 standards (10 marks) Key elements:

  1. Physical and environmental review— this includes physical security, power supply, air conditioning, humidity control and other environmental factors.
  2. System administration review— this includes security review of the operating systems, database management systems, all system administration procedures and compliance.
  3. Application software review— the business application could be payroll, invoicing, a web-based customer order processing system or an enterprise resource planning system that actually runs the business.
  4. Network security review—Review of internal and external connections to the system, perimeter security, firewall review, router access control lists, port scanning and intrusion detection are some typical areas of coverage.
  5. Business continuity review— this includes existence and maintenance of fault tolerant and redundant hardware, backupprocedures and storage, and documented and tested disaster recovery/business continuity plan.
  6. Data integrity review— the purpose of this is scrutiny of live data to verify adequacy of controls and impact of weaknesses, as noticed from any of the above reviews. Such substantive testing can be done using generalized audit software (e.g., computer assisted audit techniques).

An audit may vary in how much is covered. For instance, it may only scrutinize only one of these elements or a degree of all or some components described on the previous slide .It is important to cover all elements but they do not need to be done in one assignment. Skills sets required for each element are different. It could depend on the client sometimes


如果审核的某些方面不符合 ISO9001 标准,我会在审核时将其设置为高优先级,并执行以下步骤: 1. 定位问题 例如,如果其中一个应用软件不符合ISO9001,我们应该了解该软件的条件、特点和功能,找出它不符合标准的原因,是技术原因,还是管理原因,或者人的问题。 2. 学习 ISO 9001 我们应该确保我们已经充分理解了 ISO 9001 的性质和范围,以便我们能够发现差异和缺陷并加以改进以达到标准。 三、会议讨论 在我的审计团队内组织会议,讨论问题并制定解决方案。 4. 生成结论 正式生成问题的结论。 五、实施方案 向我的客户公司提供实施计划,报告我们的调查结果和具体的评估和建议。

QA precautionary action: If some aspects of audit are not to standard ISO9001, I will set them as high priority when conduct audit and implement the following steps:

  1. Locate the issues For example, if one of the application software does not meet the ISO9001, we should understand the conditions, characteristics and functions of the software, and find out reasons why it fails to meet standard, if it is due to technologies, or management, or human issues.
  2. Study the ISO 9001 We should ensure that we have fully understood the nature and scope of the ISO 9001, so that we can find the differences and defects and improve them to meet the standard.
  3. Meeting and discussion Organize meeting within my audit team to discuss the problems and work out the solutions.
  4. Generate conclusion Generate the conclusion of the issues formally.
  5. Implementation plan Provide the implementation plan to my client company, with report about our findings and specific evaluations and suggestions.