Spend the Compliance Budget on the Audit, Not an Oversized Technology Stack

A start-up can be a long time without thinking seriously about ISO 27001. A promising enterprise customer will send an email saying “Please provide ISO 27001 as part of our vendor review.”

Now, certification isn’t a thing to look at the next time. It’s related to a contract that the company is trying to terminate.

ISO 27001 can be a ideal starting point for companies that are growing. The problem is to understand what’s necessary without transforming a simple compliance program into an enterprise-sized security program.

Week One is about Scope, Not Shopping

The first instincts can make you start looking at compliance consultants and platforms. It is more beneficial to know what ISMS (Information Security Management System) needs to provide.

It is important to consider the scope, since the addition of systems, locations or processes that aren’t required can lead to additional documentation or evidence requirements.

Small SaaS businesses, for example, may have an environment that’s focused around cloud infrastructures employees’ devices, customer information, and a few critical vendors. Understanding the specific environment can help you determine what your certification plan should be addressing.

Check out the Security You Already Possess

Some companies researching ISO 27001 as a startup think that they will need to build a new security operation.

This could not be the instance.

Modern startups may already be using established cloud providers that require multi-factor authentication, a restricted set of employee access as well as system logs to track the onboarding process and documentation for offboarding. The current practices must be assessed against ISO 27001 requirements, but beginning with what is being used can stop unnecessary duplicates.

The remaining work includes documenting policies, performing a risk assessment, determining the appropriate Annex A controls, completing the Statement of Applicability and obtaining evidence.

You will now be able to determine the invoices that pay what

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

The initial cost for a small business may be anywhere between $10,000 and $30,000 based on the time devoted by employees, using software to monitor compliance, and an independent certification audit. Consulting can be a cost in addition however, it’s optional instead of an automatic requirement.

It is crucial to distinguish between ISO 27001 certification costs charged by a certified certification body and the software costs. A compliance platform may help manage the process, but it’s not able award the certificate. Certification is granted by an independent audit.

Then, the evidence

Writing a policy stating that employee access is removed after the departure of an employee isn’t enough. Auditor needs proof that the process actually working.

The difference between proving and saying is the defining factor of ISO 27001.

CertAssist organizes this work without the need to connect directly to live systems. It provides all the 93 ISO 27001 Annex A controls on one screen. It also provides customizable templates for policies and evidence along with a Statement of Applicability.

If you have a small group, templates could also help to reduce the time-consuming process of writing every policy on an unfinished document.

Certification Day Isn’t a Finish Line

Based on the current security policies and resources depending on the company’s security practices and resources, it could take a new company between 3 and 6 months to get certified. The body that certifies conducts audits at both Stage 1 and Stage 2.

It isn’t enough to forget about the ISMS. Controls and evidence have to be maintained, and surveillance audits follow after the certification.

This is an important factor to be considered when creating the program. It’s not enough for a small business to simply use an ISMS which it can afford. It needs an ISMS so that its team will be able to be able to operate in a realistic manner following the initial project concluded.

It’s rare to find that the biggest organization is the one with the best ISO 27001 program. It’s the one that meets the standards, has authentic security practices, withstands independent scrutiny, and is in control when people return to their jobs.

Scroll to Top