Spend the Compliance Budget on the Audit, Not an Oversized Technology Stack

A startup can go years without thinking seriously about ISO 27001. An enterprise customer who is a good fit will send an email saying “Please send us ISO 27001 as part of our review of the vendor.”

The certification process isn’t something you need to be thinking about for the next year. The company is looking to complete the specific contract.

ISO 27001 can be a good starting point, especially for businesses that are growing. The trick is figuring out the actual requirements without making a small security project into a massive compliance program.

Week One should be about Scope, not Shopping

Your first instincts could lead you to start comparing the platforms and consultants for compliance. A better starting point is to figure out what the Information Security Management System, or ISMS must cover.

It is important to consider the extent of the project, since adding systems, locations, or processes that aren’t required can lead to additional documentation or evidence requirements.

Small SaaS businesses, for example they may have an environment that’s centered around cloud infrastructures, employee devices, client information, and few key vendors. Understanding the specific environment can help you determine what the certification process should cover.

Look over the Security You Already Have

Many companies researching ISO 27001 to start ups believe they’ll need to create a brand new security system.

It could be that it is not the situation.

A modern startup might already require multi-factor authentication, restrict the access of employees, keep records of system activity, control backups in the document onboarding process and offboarding, and use established cloud providers. The current practices must be evaluated against ISO 27001 requirements, but using what’s already effective can avoid unnecessary duplicates.

The remainder of the work involves establishing policies, performing the risk assessment, determining applicable Annex A controls, completing the Statement of Applicability and obtaining the necessary evidence.

How do you know which invoice is credited for what?

If the expenses aren’t combined in one figure it becomes easier to see the ISO 27001 cost.

Initial expenses for a small-sized business could range from $10,000 to $30,000 once the independent certification audit, compliance software, as well as internal staff time are taken into consideration. Consulting is an additional cost, but it is not an obligation.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. While compliance platforms can help in the process of organizing work, it’s not able to issue the certificate. Certification is granted by an audit conducted by an independent company.

Then comes the proof

It’s not enough to write an policy that states employees are not allowed access after they leave. The auditor will need to be able to verify that the system is implemented.

ISO 27001 is based on the distinction between saying and showing.

CertAssist was created to assist to manage this process without having to connect to the systems that live in a company. It contains all 93 ISO 27001 Annex A controls in one board. It also has editable templates for policy and evidence, and a statement of Applicability.

Templates can be employed by small groups of people to reduce the lengthy process of creating each policy by hand.

The Final Line isn’t Certification Day

Based on the current security procedures and capabilities depending on their security policies and resources, it can take between 3 and 6 month to prepare for certification. The certification body conducts Stage 1 and Stage 2 audits.

Passing those audits isn’t permission to forget about the ISMS. After certification, the controls and evidence have to be maintained. Audits of surveillance will follow.

This is an important element to think about when designing the program. Smaller businesses do not only have to possess an ISMS they can afford. It’s in need of one that can actually operate after the initial project is completed.

It’s not often that the largest organization has the best ISO 27001 program. The best ISO 27001 system is one that adheres to the standard, incorporates real security practices, can be able to withstand scrutiny by an independent third party and be manageable when everyone returns to work.

Scroll to Top