From Security Questionnaire to Certificate: The ISO 27001 Road Ahead

ISO 27001 is not something that a startup should think about for many years. An enterprise customer who is a good fit will send an email saying “Please provide ISO 27001 as part of our vendor review.”

Certification is suddenly not something you’re supposed to think about in the coming year. It’s tied to a deal that the company would like to terminate.

ISO 27001 can be a good starting point, especially for growing businesses. The problem is to figure out what actually needs to happen without turning a manageable security project into a massive compliance program.

The first week of the week should be focused on Scope, Not Shopping

It is common to look at compliance platforms and consultants. It is preferable to identify what ISMS (Information Security Management System) must be able to cover.

The scope of the document is important because trying to include unnecessary systems, locations, or processes can create further documentation requirements and proof requirements.

A small SaaS company, for example it may have a concentrated environment based around cloud infrastructure as well as employee devices, customers data, and a couple of critical vendors. Understanding the current environment can help you determine which certification is required.

Create a list of all the security features you already have

Companies researching ISO 27001 for startups sometimes assume they need to build an entirely new security operation.

However, this may not be the case.

Modern startups may already use cloud providers, and may require multi-factor authentication and restrict access for employees. They might also maintain system logs and manage backups. These practices should be compared against ISO 27001 requirements. However by starting with the practices that work already will prevent unnecessary duplication.

Writing policies, conducting a risk analysis, determining which Annex A Controls, completing the Statement for Applicability and gathering evidence are all the remaining tasks.

Find out which invoice pays for What?

The ISO 27001 cost becomes much easier to understand when expenses aren’t combined into a single number.

The initial costs for a small business may range from $10,000 to $30,000 based on the time spent by employees, the use of software to guarantee compliance, and independent audits of certification. The consulting fee could be added, but this isn’t considered a necessary expense.

The ISO 27001 certification cost charged by an accredited certification body is important to distinguish from software-related fees. While a compliance platform may help in the process of organizing work, it cannot issue a certificate. The certification process is an independent audit process.

Then comes the proof

A policy that states employees’ access rights to company resources will be revoked following their departure is not sufficient. Auditors need proof that the process is actually working.

ISO 27001 is based on the distinction between showing and saying.

CertAssist facilitates this process without needing to connect directly to the live system. It includes all 93 ISO 27001 Annex A controls in one board. It also offers customizable templates for policies and evidence, as well as a Statement of Applicability.

Templates are a great tool for small groups to avoid the tedious task of creating every policy from scratch.

Certification Day is Not the Day to Cross the Finish Line

A business that is beginning at the beginning may need to spend between three to six months getting prepared for certification. This will depend on their existing security practices, and the available resources. The certification body conducts audits at Stage 1 and Stage 2.

Achieving these audits doesn’t mean you have the right to ignore the ISMS. The ISMS must be able to monitor controls and provide evidence. After certification, surveillance audits must be carried out.

This is an important factor to be considered when creating the program. Smaller businesses do not only have to have an ISMS they can afford. It’s required one of its teams can actually operate after the initial project ends.

The most effective ISO 27001 program for a smaller business isn’t necessarily the largest. It’s the one that satisfies the requirements of the standard, incorporates real security practices, stands up to independent scrutiny, and remains feasible when employees return back to their work.

You may also like