Otter Feed

What Your Team Will Be Doing During a Three-to-Six-Month ISO 27001 Project

ISO 27001 is not something that startups need to be thinking about for many years. A few days later, an email is sent from a prospective enterprise customer: “Please provide your ISO 27001 certificate as part of our vendor security assessment.”

Then, it’s not something to be considered next year. It’s related to a contract the company is trying to end.

In the case of many companies that are growing, that’s the practical starting point for ISO 27001 for small business. The challenge is to identify what’s required without turning a manageable compliance program into an enterprise-sized security program.

Week One is supposed to be about Scope, not shopping

It may be instinctive to assess compliance platforms as well as consultants. It is preferable to identify what ISMS (Information Security Management System) must provide.

It is important to look at the scope of your project, as the addition of locations, systems, and processes that aren’t needed can create further documentation or requirements for evidence.

For instance, a small SaaS company might be operating in an environment largely concentrated on cloud infrastructure employees’ devices, as well as customer data. It could also be dominated by handful of key vendors. Understanding the environment can help determine what the certification project actually will need to focus on.

List the security that you have already

Companies who are looking at ISO 27001 for startups sometimes believe that they require an entirely new security program.

This could not be true.

Modern startups may already have established cloud providers that require multi-factor identification, restricted employee access and system logs that can be used to manage the process of onboarding and offboarding. Current practices need to be assessed against ISO 27001 requirements, but beginning with what is working can prevent unnecessary duplication.

The remainder of the job is preparing policies, completing risk assessments, determining Annex A controls applicable, complete Statements of Applicability (SOA) and obtaining evidence.

Be aware of which invoices pay for What?

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

When you look at the cost of an audit by an independent certifier, tools for compliance and staff time the first-year cost could be anything from $10,000 to $30,000. Consulting may be an additional expense but it’s not mandatory rather than an automatic requirement.

It is crucial to distinguish between ISO 27001 certification costs charged by a certified certification organization and software fees. A compliance platform may help in the organization of work, however it is not able to award the certification. The process of independent auditing is the process that validates the certification.

After the evidence is presented, the accusation

A policy that says employees’ access rights to company resources is suspended after their departure isn’t enough. The auditor must see evidence that the procedure is implemented.

ISO 27001 is based on the distinction between showing and saying.

CertAssist is designed to manage the work of CertAssist without directly connecting to the live systems of a business. It presents all ISO 27001:2022 Annex A controls on one screen, provides editable policy and evidence templates It also supports the Statement on Applicability and also allows read-only auditor access.

For a small team, templates can help eliminate the inefficient process of writing each policy from the beginning of a blank document.

Certification Day is Not the Finish Line

Depending on the company’s existing security procedures and capabilities depending on the company’s security practices and resources, it could take between three and six month to get ready for certification. The certification body conducts its audits at the stages 1 and Stage 2.

After you have passed the audits, you should not just put aside your ISMS. The ISMS must continue to ensure that it has adequate controls and proof. After the certification, surveillance audits are carried out.

That’s an important consideration when developing the program. Small-sized businesses don’t require an ISMS it can afford to build. It should have an ISMS that its team will be able to use once the project is completed.

It’s rare to find the ISO 27001 programme for smaller organisations the most intelligent. It’s one that is in line with the standards, has real security practices, stands up to independent scrutiny, and remains easily manageable after everyone has returned back to their work.