Why Your Compliance Platform and Certification Body Have Completely Different Jobs

It’s possible for a startup to go for years without taking seriously the idea of ISO 27001. A potential enterprise client will send an email saying “Please provide ISO 27001 as part of our vendor review.”

The certification issue is no longer a subject that will be discussed this year. It’s tied into a contract that the company is looking to end.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. The trick is figuring out what needs to be done without changing a simple security program into a large-scale compliance program.

Week One should be about Scope, not about shopping.

The first instincts can cause you to compare platforms and compliance consultants. The best way to begin is by defining what ISMS or Information Security Management System needs to incorporate.

The scope of the project is important since adding unneeded methods, locations or systems to the documentation may cause additional evidence or documentation requirements.

A small SaaS company, for example could have a concentrated environment based around cloud infrastructure employees’ devices, customer data, and a couple of essential vendors. Understanding the context helps determine what the certification project actually will need to focus on.

Make a list of the security features you already have

Companies that are researching ISO 27001 for startups sometimes believe they must build an entirely new security process.

This might not be correct.

Modern startups might already have established cloud providers and require multi-factor identification, restricted employee permissions and system logs for managing the onboarding process and documentation for offboarding. The current procedures must be evaluated in relation to ISO 27001 requirements. However beginning with the elements that are already working will prevent unnecessary duplication.

The remaining work is preparing policies, completing risk assessments in the determination of Annex A controls applicable, complete Statements of Applicability (SOA) and obtaining evidence.

How do you know which invoice is credited for what?

If expenses aren’t bundled in one figure, it is simpler to comprehend the ISO 27001 cost.

The first-year costs for a small business may be anywhere between $10,000 and $30,000, depending on the time devoted by employees, using software to guarantee compliance, and independent audits of certification. A consulting fee can be a part of the equation, but it isn’t an essential expense.

It is crucial to distinguish between the ISO 27001 certification costs charged by a certified body for certification and the software costs. A compliance platform may help organize the work, but it is not able to award the certification. Certification comes through the independent audit procedure.

Then, the evidence

It’s not enough simply to draft an policy that states employees are not allowed access after they have left. The auditor needs to examine evidence to prove that the procedure is implemented.

ISO 27001 is concerned with the difference between stating something and actually demonstrating it.

CertAssist was created to assist to manage this process without having to connect to live systems of an organization. It provides all 93 ISO 27001 Annex A controls in one board. It also provides customizable templates for policies and evidence, as well as a Statement of Applicability.

Templates are a great tool for small groups of people to reduce the lengthy process of creating each policy from scratch.

The Line to the Finish Line isn’t Certification Day

Based on the existing security practices and resources It could take between 3 and 6 months to get ready for certification. The certification body conducts audits at both Stage 1 and 2.

After you have passed the audits, you should not just put aside your ISMS. The ISMS has to continue to ensure that it has adequate controls and proof. After the certification, surveillance audits are conducted.

This is a crucial aspect to consider when developing the program. It’s not enough for a small company to simply have an ISMS which it can afford. It needs an ISMS that the team can utilize after the project has been completed.

It’s not often that even the biggest company is the one with the best ISO 27001 program. It’s one that meets ISO 27001 standards, reflects the best practices in security, is subject to independent audits, and is manageable once everyone returns to their normal jobs.

Scroll to Top