A Customer Wants ISO 27001: What Should a Small Company Do First?

It is possible for startups to remain in business for years without even thinking about ISO 27001. An email from a business customer requests your ISO 27001 certification as part our security review of vendors.

It’s not something you should be thinking about next year. It’s due to an agreement the business is trying to terminate.

For a majority of companies growing this is the ideal basis for ISO 27001 for small business. The challenge is to understand what’s required, without turning a scalable compliance program into an enterprise-sized security plan.

This week, concentrate on Scope and Not Shopping

First instincts may cause you to compare compliance consultants and platforms. It is more beneficial to know what ISMS (Information Security Management System) will need to provide.

The scope of the project is crucial, as adding unnecessary systems, locations or processes to the documentation could create additional evidence and requirements for documentation.

Small SaaS businesses, for example could have an environment that’s focused around cloud infrastructures, employee devices, client data, and only one or two key vendors. Understanding this environment will help establish the specific issues that the certification process will need to focus on.

Review the Security You Already Possess

Companies researching ISO 27001 for startups sometimes assume they need to build an entirely new security operation.

This could not be true.

Modern startups might already have established cloud providers and need multi-factor authentication, restricted employee permissions and system logs that can be used to manage the process of onboarding and offboarding. The current practices must be evaluated against ISO 27001 requirements, but using what’s already in place can help avoid unnecessary duplicates.

The remainder of the job is preparing policies, completing risk assessments, making decisions about Annex A controls applicable, complete Statements of Applicability (SOA) and collecting evidence.

You can now identify which invoices you pay for and what

The ISO 27001 cost becomes much simpler to comprehend when costs aren’t lumped into a single number.

The first year’s expenses for a small business can range from $10,000 to $30,000 when the independent certification audit, compliance software and staff time at the internal level are considered. Consulting is a different expense however, it’s optional instead of an automatic necessity.

It is important to differentiate between the ISO 27001 certification costs charged by a certified body for certification and the fees for software. A compliance platform is a great tool to in the organization of work, however it’s not able award the certificate. The certification is awarded through an independent audit process.

Then, we will look at the evidence

It’s not enough to write the policy that states that employees can’t access the system upon their departure. The auditor needs evidence that the process is actually working.

ISO 27001 is based on the distinction between saying and showing.

CertAssist organizes this work without having to connect directly to live systems. It includes all 93 ISO 27001 Annex A controls within one single board. It also has customizable templates for policies and evidence, as well as a Declaration of Applicability.

For a small team, templates can help eliminate the inefficient process of drafting every policy from a blank sheet.

Certification Day Isn’t a Finish Line

Depending on the company’s existing security procedures and capabilities It could take a new company between three and six months to get ready for certification. The certification body conducts the Stage 1 and Stage 2 audits.

The ISMS is not forgotten just because you pass the audits. After certification, the controls and evidence must be maintained. Surveillance audits are to follow.

This is an important element to think about when designing the program. Small-sized businesses don’t need an ISMS it could afford to create. It needs one its team is able to operate once the initial project is completed.

The smartest ISO 27001 program for a smaller company is not always the most comprehensive. It’s one that is in line with the requirements, is based on real security practices, stands up to independent scrutiny and is manageable when everyone returns to their regular jobs.

Subscribe

Recent Post