ISO 27001 Isn’t a Software Integration Project So Why Treat It Like One?

It’s possible for a startup to remain in business for years without seriously considering ISO 27001. A potential enterprise client will send an email saying “Please give us ISO 27001 as part of our vendor review.”

The issue of certification is no longer something that will be debated next year. It’s tied to a deal the company wants to close.

ISO 27001 is a good base for small firms. The issue is understanding the actual requirements without changing a simple security program into a large-scale compliance program.

Week One should be all about Scope, not shopping

It is common to evaluate compliance platforms and consultants. The most effective place to start is by defining the requirements that an ISMS or Information Security Management System needs to incorporate.

It is important to know the scope because trying include ineffective systems, locations or processes could result in additional documentation and evidence requirements.

For instance, a smaller SaaS company may have an environment predominantly concentrated on cloud infrastructure including employee devices, customer information. It could be also controlled by a few key suppliers. Understanding the environment will help determine what certification project is required.

Create a list of all the security features you already have

Companies who are looking at ISO 27001 for startups sometimes think they will need to create an entirely new security operation.

This may not be accurate.

Modern startups may already be using established cloud providers and require multi-factor identification, limited access to employees as well as system logs to track the process of onboarding and offboarding. Current practices need to be evaluated against ISO 27001 requirements, but using what’s already effective can avoid unnecessary duplicates.

The remaining work includes documenting policies, performing the risk assessment, finding the applicable Annex A controls, completing the Statement of Applicability and obtaining evidence.

Which invoice pays for what?

If expenses aren’t bundled in one figure and are not bundled into one number, it’s easier to see the ISO 27001 cost.

The initial costs for a small-sized business can range from $10,000 to $30,000, depending on the amount of time required by employees, the use of software to monitor compliance, and an independent audits of certification. The cost of consulting is an additional expense, but it’s not required.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. The compliance platform functions as a device that allows for the organization of work but it is not able to issue the certification. The certification is granted through an audit conducted by an independent company.

Then comes the evidence

It’s not enough simply to draft the policy that states that employees can’t access the system upon their departure. An auditor needs evidence that the system actually functions.

ISO 27001 is based on the distinction between showing and saying.

CertAssist is designed to help you organize this task without connecting directly to live systems of a company. It displays all 93 ISO 27001-2022 Annex A control templates on one screen. An editable policy as well as an evidence templates are also offered.

For small teams, templates could also help to be a great way to avoid the inefficient task of writing every policy on a blank document.

Certification Day isn’t the Finish Line

A new company can take between three and six months working towards certification, depending on its existing security practices and available resources. The certification body will then conduct Stage 1 and Stage 2 audits.

Once you’ve passed the audits you should not just put aside your ISMS. Controls and evidence must be maintained as well as surveillance audits that follow following certification.

It is important to take this into consideration while designing the program. A small company doesn’t merely need an ISMS it could afford to create. It should have an ISMS that its team can utilize after the project has ended.

The most intelligent ISO 27001 program for a smaller business isn’t necessarily the most comprehensive. It’s the one that meets the requirements of the standard, incorporates the true security standards, is able to withstand independent scrutiny, and is feasible when employees return to their regular jobs.

Scroll to Top