Which ISO certification is appropriate?

May 3rd, 2010

ISO (International Organization for Standardization) has published many management system standards that can by certified by a third party organization (Certification Body). Here is a listing of some of the popular management system standards:

ISO 9001:2008

This standard specifies the requirement of a quality management system for an organization. By applying this standard the organization can demonstrate that it is capable of consistently delivering products / services that meet customer as well as statutory and regulatory requirements. This standard can also help the organization to build a mechanism to enable continual improvements in the processes of the organization.

ISO 27001:2005

This standard provides a framework for an information security management system in an organizational setup. By applying this standard the organization can develop a framework to ensure protection of their critical information assets (not only IT assets). This helps the organization build a trust level within as well as with its customers that their information assets are protected from loss of confidentiality, integrity and availability.

ISO 20000-1:2005

This is a management system framework for ITIL. This is useful to organizations providing IT services to either internal or external customers. These IT teams first establish their own process, then follow ITIL and then implement the management system prescribed within ISO 20000. This does not mean that the organizations need to implement ITIL first. They can refer the ISO 20000 directly. A compliance to ISO 20000 reflects that the organization is practicing ITIL processes.

ISO 22000:2005

This standard specifies requirements for a food safety management system. The standard can be applied by any organization in the entire food supply chain that includes crop producers, feed producers, food processors, wholesalers / retailer as well as the support stream including producers for pesticides/fertilizers/veterinary drugs, producers of food ingredients / additives, transporters / storage operators, producers of equipments, producers of cleaning agents, producers of packaging materials, service providers and other suppliers to food chain. By applying this standard the organization can assure the consumers and customers that it is taking all measures to avoid any potential food safety hazard.

ISO 14001:2004

This standard specifies the requirements for an environmental management system. By applying this standard the organizations can demonstrate that they are taking all possible measures to prevent, eliminate or reduce the impacts of their products and services on the environment.

The decision to implement any of these standards is entirely voluntary and should depend on the need to demonstrate the capability to the organization’s stakeholders including customers, owners, suppliers, statutory / regulatory bodies, employees, etc.