Spend the Compliance Budget on the Audit, Not an Oversized Technology Stack

It is possible for a new company to continue for years without seriously considering ISO 27001. Then an email arrives from a prospective enterprise customer: “Please provide your ISO 27001 certification as part of our vendor security audit.”

Then, it’s not something to be considered the next time. It’s because of an agreement that the company is trying to end.

ISO 27001 is a good starting point for many small-scale firms. It’s a challenge to determine the steps to take without turning an easily manageable project into a compliance plan that is geared towards enterprises.

The first week of the week should be focused on Scope, not shopping

The first instincts can lead you to start comparing compliance consultants and platforms. A better starting point is to identify what Information Security Management System, or ISMS is required to cover.

It is important to look at the scope, because adding systems, locations, and procedures that aren’t required can lead to further documentation or requirements for evidence.

Small SaaS companies, for instance, may have an environment that is focused on cloud infrastructures including employee devices, customer information, and a few critical vendors. Understanding the specific environment could help you determine what your certification project should address.

Take Inventory of Security You Already Have

Companies researching ISO 27001 for startups sometimes assume they need to build an entirely new security operation.

It might not be the scenario.

Modern startups might already have established cloud providers and need multi-factor authentication, restricted employee permissions and system logs for managing the process of onboarding and offboarding. These practices should be compared against ISO 27001 requirements. However starting with things that work can avoid unnecessary duplicates.

Writing policies, conducting a risk assessment, determining the appropriate Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.

How do you know which invoice is credited for what?

If expenses aren’t bundled into a single figure It is much simpler to grasp the ISO 27001 cost.

If you take into account the costs of an audit by an independent certifier, tools for compliance and staff time the first-year expenses could range from $10,000 to $30,000. A consulting fee can be included, but it isn’t a major expense.

The ISO 27001 Certification Cost charged by a certification agency that is accredited is particularly significant to distinguish from the software costs. The compliance platform is a tool which can manage work, but cannot issue the certification. The independent auditing process is what certifies the certification.

Then, we will look at the evidence

The mere fact of a policy that says access to employees is terminated upon leaving isn’t enough. An auditor requires evidence that the process is actually working.

ISO 27001 is concerned with the distinction between saying something and actually demonstrating it.

CertAssist was created to assist in coordinating this process, but without connecting to live systems of the company. It offers all 93 ISO 27001 Annex A controls in one board. It also offers customizable templates for policies and evidence, as well as a Statement of Applicability.

For a small team, templates could also help to remove the tedious task of writing every policy on an unfinished document.

Certification Day isn’t the Finish Line

A company starting from scratch could take anywhere from three to six months getting certified according to its current security policies and the resources available. The certification body conducts the Stage 1 and Stage 2 audits.

The ISMS will not be lost just because you pass the audits. The controls and evidence should be maintained, and surveillance audits follow after the certification.

This is an important factor to consider when creating the program. Small-sized businesses don’t need an ISMS it could afford to create. It needs an ISMS so that its team can work effectively when the initial project has been completed.

The most intelligent ISO 27001 program for a smaller company is not always the largest. It must meet the ISO 27001 requirements, is based on the best practices in security, is subject to independent audits and can be managed once everyone returns to their regular jobs.

Scroll to Top