Building an ISMS That a Five-Person Team Can Actually Maintain

An entrepreneur can spend years without considering ISO 27001. Then an email arrives from an enterprise client who is promising: “Please provide your ISO 27001 certificate as a part of our vendor security audit.”

Certification is suddenly not something to think about next year. It’s due to a contract the company is attempting to end.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. The problem is to figure out the actual requirements without changing a simple security program into an enterprise-sized compliance plan.

Week One should be all about Scope, not shopping

It may be instinctive to look at compliance platforms and consultants. It is best to establish what ISMS (Information Security Management System) needs to protect.

The scope of the project is vital since adding unneeded systems, locations or processes to the documentation may result in additional evidence and requirements for documentation.

Small SaaS businesses, for example might have a system that is focused on cloud infrastructures employees’ devices, client information, and just some key vendors. Knowing the specifics of your environment will help you determine what your certification program should focus on.

Make a list of the security features you already have

Some companies looking into ISO 27001 as a startup suppose that they have to establish a new security operations.

However, this may not be the case.

A modern-day startup may require multi-factor authentication, restrict the access of employees, keep systems logs, maintain backups, document onboarding and offboarding, and utilize the most well-known cloud providers. It’s important to test current practices against ISO 27001, but if you begin with the best practices today, you can avoid unnecessary duplicates.

The remaining task is to document policies, conducting the risk assessment, determining the appropriate Annex A controls, completing the Statement of Applicability and obtaining evidence.

It is now possible to identify the invoices that pay what.

When expenses are not bundled into a single figure and are not bundled into one number, it’s easier to see the ISO 27001 cost.

If you take into account the costs of an independent certification audit, compliance tools and staff time the first-year cost could be anything from $10,000 to $30,000. Consulting costs are an additional expense, but it’s not an obligation.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software-related fees. Although a compliance platform can aid in the organization of task, it’s not capable of granting a certificate. Certification is granted by an independent audit.

Next, the evidence

Writing a policy stating that access to employees is terminated upon the departure of an employee isn’t enough. An auditor requires evidence that the process actually operates.

ISO 27001 is based on the distinction between saying and showing.

CertAssist is designed to organize this task without connecting directly to the live systems of a business. It contains all 93 ISO 27001 Annex A controls on one screen. It also includes customizable templates for policies and proof, as well as a Declaration of Applicability.

If you have a small group, templates can also eliminate the inefficient process of writing every policy from a blank document.

Certification Day is Not the Final Line

Based on the existing security policies and resources depending on the company’s security practices and resources, it could take between 3 and 6 month to prepare for certification. The certification body then conducts Stage 1 and Stage 2 audits.

The ISMS will not be lost just because you have passed the audits. Controls and evidence need to be maintained and surveillance audits are conducted after certification.

That’s an important consideration when developing the program. Small businesses don’t just require an ISMS it is able to afford to develop. It should have an ISMS that its team can use after the project has ended.

It’s not often that an organization with the most employees has the best ISO 27001 program. The best ISO 27001 system is the one that meets the standard, reflects the best practices in security, and can stand up to scrutiny from an outsider and be able to be managed after everyone has returned to work.

Recent Post