ISO 27001 Isn’t a Software Integration Project So Why Treat It Like One?

Startups can go for years without thinking about ISO 27001. A promising enterprise customer sends an email to “Please provide ISO 27001 as part of our review of the vendor.”

Now, certification isn’t a thing to think about the next time. It’s due to an agreement the business is attempting to end.

ISO 27001 is a good start for many small companies. The problem is to figure out what needs to be done without changing a simple security program into a large-scale compliance program.

Week One should be all about Scope, not shopping

The first reaction could be to begin comparing compliance platforms and consultants. An alternative is to identify what the Information Security Management System, or ISMS should cover.

Scope is crucial because trying to include ineffective systems, locations, or processes can create additional documentation and requirements for evidence.

For instance, a small SaaS firm might be operating in an environment heavily concentrated on cloud infrastructure, employee devices and information about customers. It could be also dominated by a handful of key suppliers. Understanding this environment will help establish the specific issues that the certification process will need to focus on.

Review the Security You Already Have

Many companies who are looking into ISO 27001 to start ups think they’ll have to create a brand new security company.

It may not be the instance.

Modern startups could already utilize cloud providers, and may require multi-factor authentication, and limit access for employees. They may also keep system logs and manage backups. It’s still important to evaluate current practices against ISO 27001, but if you start with what works now, it can save unnecessary duplicates.

The remaining work involves the preparation of policies, completing risk assessments, finding Annex A controls applicable, making Statements of Applicability (SOA), and obtaining evidence.

You can now identify the invoices that pay what

When costs are not combined into a single figure It is much easier to understand the ISO 27001 cost.

A small-sized business could range from $10,000 to $30,000 once the independent certification audit, compliance software, as well as internal staff time are considered. Consulting is an additional expense, but it’s not required.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. The compliance platform functions as a tool that organizes work but cannot issue the certification. Certification is granted by an audit conducted by an independent company.

Then Comes the Evidence

A policy that says employees’ access to company resources will be revoked following the employee’s departure is not enough. The auditor will need to see evidence that the system is in place.

ISO 27001 is based on the distinction between saying and showing.

CertAssist is designed to manage this process without connecting directly to a company’s live systems. It contains all 93 ISO 27001 Annex A controls all in one place. It also includes customizable templates for policies and proof, and a statement of Applicability.

If you have a small group, templates could also help to remove the tedious task of drafting every policy from the beginning of a blank document.

Certification Day isn’t the End Line

A business that is beginning from scratch may spend approximately three to six months preparing for certification dependent on its current security practices and available resources. The body that certifies conducts its audits at Stage 1 and 2.

The ISMS isn’t forgotten because you pass the audits. The ISMS has to continue to maintain controls and evidence. Following certification, surveillance audits are performed.

This is an important aspect to take into consideration when creating the program. A small company doesn’t merely require an ISMS it can afford to create. It’s required one of its teams will be able to run after the initial project has ended.

It’s rare to find that the biggest company has the top ISO 27001 program. It’s one that is in line with the standards, has the true security standards, is able to withstand independent scrutiny and is in control when people return to their regular jobs.

Newsletter

Join over 150,000 marketing managers who get our best social media insights, strategies and tips delivered straight to their inbox.