Spend the Compliance Budget on the Audit, Not an Oversized Technology Stack

ISO 27001 is not something that startups need to think about for many years. An email from an enterprise customer solicits your ISO 27001 certification as part our security review of vendors.

The certification issue isn’t one to consider next year. The company needs to conclude an agreement.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. The challenge is to identify what’s needed without turning a manageable compliance program into a massive security program.

This Week, affixed to Scope, not Shopping

The initial reaction is to begin comparing compliance systems and consultants. The best way to begin is to define what ISMS or Information Security Management System needs to be able to contain.

Scope is crucial because trying to add unnecessary locations, systems or processes may result in further documentation requirements and proof requirements.

A small SaaS company, for example could have a focused environment built around cloud infrastructure as well as employee devices, customers details, and even a handful of critical vendors. Understanding that environment helps establish what the certification project actually must address.

Review the Security You Already Have

Companies looking into ISO 27001 for startups sometimes assume they need to build an entirely new security operation.

This could not be the case.

Modern startups might already have established cloud providers that require multi-factor identification, limited access to employees, system logs to manage the onboarding process and documentation for offboarding. The current procedures must be evaluated against ISO 27001 requirements. However starting with things that work will help avoid unnecessary duplicates.

The remaining tasks include establishing guidelines, conducting the risk assessment, finding the applicable Annex A controls, completing the Statement of Applicability and obtaining the necessary evidence.

What is the best way to determine which invoice is credited for what?

If expenses aren’t bundled into a single number It is much simpler to grasp the ISO 27001 cost.

When you look at the cost of an audit by an independent certifier, tools for compliance and the time of staff members the first-year cost could be anything from $10,000 to $30,000. Consulting can add another expense however it’s an option rather than a mandatory requirement.

The ISO 27001 Certification Cost charged by a certified certification body is particularly significant to distinguish from software charges. A compliance platform can help with the task, but it’s not able to issue the certificate. Certification comes through the independent audit procedure.

Next, the evidence

It’s not enough simply to draft an policy that states employees can’t access the system after they leave. The auditor needs to examine evidence to prove that the procedure is in place.

This distinction between saying and demonstrating is the main point of ISO 27001.

CertAssist was created to assist to manage this process without having to connect to the live systems of an organization. It contains all 93 ISO 27001 Annex A controls on one screen. It also provides editable templates for policy and documentation, along with a Statement of Applicability.

Templates are a great tool for a small group to eliminate the lengthy process of creating every policy from scratch.

Certification Day isn’t the End Line

Based on the current security policies and resources, it may take a new company between 3 and 6 month to prepare for certification. The certification body conducts audits in Stage 1 and Stage 2.

After passing the audits, you should not just ignore your ISMS. Following certification, controls and proofs must be maintained. Surveillance audits are to follow.

This is an important aspect to take into consideration when developing the program. A small business doesn’t only require an ISMS it can afford to build. It’s in need of one that is able to operate once the initial phase is over.

It’s rare to find that the largest organization has the best ISO 27001 program. The most effective ISO 27001 program is the one that meets the standard, reflects the best practices in security, and can stand up to scrutiny from an outsider and remain manageable after everyone returns to work.