Spend the Compliance Budget on the Audit, Not an Oversized Technology Stack

ISO 27001 is not something that startup companies should be thinking about for a number of years. When an email arrives from a prospective enterprise customer: “Please provide your ISO 27001 certificate to us as part of our vendor security audit.”

The certification issue is no longer a topic that is going to be discussed in the coming year. It’s related to a contract the company is trying to terminate.

ISO 27001 is a good starting point for many small-scale firms. The challenge is figuring out what actually needs to happen without becoming a manageable security initiative into an enterprise-sized compliance program.

Week One is supposed to be about Scope, not about shopping.

First instincts may lead you to start comparing the platforms and consultants for compliance. The better place to begin is to determine what the Information Security Management System, or ISMS is required to cover.

It is important to look at the scope, because the addition of systems, locations and procedures that aren’t necessary can result in further documentation or requirements for evidence.

Small SaaS companies, for instance, may have an environment that is focused on cloud infrastructures employees’ devices, client information, and few key vendors. Understanding the context helps determine the issues that the certification program requires to tackle.

Review the Security You Already Have

Companies looking into ISO 27001 for startups sometimes think they will need to create an entirely new security system.

This could not be the instance.

A modern startup might already require multi-factor authentication, limit employees’ access, keep system logs, manage backups in the document onboarding process as well as offboarding, and also use established cloud providers. The existing practices need to be compared against ISO 27001 requirements. However beginning with the elements which are working already will help avoid unnecessary duplicates.

Writing policies, conducting a risk analysis, determining which Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.

How to Know which invoice is paid for by what

The ISO 27001 cost becomes much simpler to comprehend when costs aren’t all lumped together into a single number.

If you take into account the costs of an independent certification audit, compliance tools and staff time A small business’s initial expenses could range from $10,000 and $30,000. Consulting costs are an additional expense, but not a requirement.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. A compliance platform can help with the task, but it’s not able to issue the certificate. Certification is granted through an independent audit procedure.

Then, the proof

The mere fact of a policy that says access to employees is terminated upon departure isn’t enough. The auditor must be able to verify that the system is in place.

ISO 27001 is based on the distinction between showing and saying.

CertAssist facilitates this process without the need to directly connect to an actual system. It contains all the 93 ISO 27001 Annex A controls in one board. It also provides customizable templates for policies and evidence, as well as a Statement of Applicability.

Templates are a great tool for an enclave of people to cut out the tedious task of creating every policy by hand.

Certification Day is Not the End Line

An organization that is just starting from the ground up may have to invest between three and six month getting prepared for certification. It will be contingent on their security policies and procedures, as well as available resources. The certification body conducts the Stage 1 and Stage 2 audits.

After passing the audits you can’t just put aside your ISMS. The ISMS must continue to maintain controls and evidence. Following certification, surveillance audits must be conducted.

This is an important factor to be considered when creating the program. Small businesses don’t just need an ISMS it could afford to create. It needs one its team can realistically operate after the initial phase is over.

Rarely is the ISO 27001 programme for smaller businesses the most efficient. It’s one that meets ISO 27001 standards and reflects real security practices, withstands independent audits, and is manageable once everyone returns to their normal jobs.

Recent Post