Before Hiring an ISO Consultant, Figure Out Which Work Your Team Can Already Do

ISO 27001 is not something startups should be thinking about for many years. An email from an enterprise client wants to know your ISO 27001 certification as part our security review of vendors.

The certification issue is no longer a topic that will be discussed next year. It’s tied to a deal that the company is looking to end.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. The challenge is figuring out what actually needs to happen without changing a simple security program into an enterprise-sized compliance program.

The first week of the week should be focused on Scope, not shopping

First instincts may prompt you to begin comparing the platforms and consultants for compliance. An alternative is to figure out what the Information Security Management System, or ISMS should cover.

It is important to know the scope because trying include unneeded systems, locations, or processes can create additional documentation and requirements for evidence.

A small SaaS business, for instance might have a focused environment built around cloud infrastructure including employee devices, customer information, and a few of important vendors. Understanding the environment will assist in determining which certification is needed.

Look over the Security You Already Possess

Companies that are researching ISO 27001 for startups sometimes assume they need to build an entirely new security program.

This may not be the case.

A modern-day startup may require multi-factor authentication, deter employees’ rights, manage records of system activity, control backups in the document onboarding process as well as offboarding, and also use well-established cloud providers. Current practices need to be assessed against ISO 27001 requirements, but by starting with what’s being used can stop unnecessary duplicates.

The documentation of policies, the risk assessment, determining the applicable Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.

What is the best way to determine which invoice pays for what

When costs are not combined in one figure, it is simpler to grasp the ISO 27001 cost.

The initial costs for a small company could range from $10,000 to $30,000, depending on the time spent by employees, the use of software to ensure compliance, and independent audits of certification. Consulting can add another expense however it’s an option rather than an automatic necessity.

The ISO 27001 Certification Cost charged by a certification agency that is accredited is crucial to differentiate from software charges. A compliance platform can help manage the process, but it cannot award the certificate. The process of independent auditing is what validates the certificate.

Next, the evidence

It’s not enough simply to draft a policy that stipulates that employees cannot access information after they leave. An auditor needs evidence that the system actually functions.

ISO 27001 is concerned with the difference between stating something and then demonstrating it.

CertAssist helps to manage this work without needing to directly connect to an actual system. It offers all 93 ISO 27001 Annex A controls in one board. It also has customizable templates for policies and proof, as well as a Declaration of Applicability.

Templates can be used by small groups to avoid the lengthy process of creating each policy from scratch.

Certification Day isn’t the Final Line

A new company may spend approximately three to six months working towards certification, depending on its existing security practices and available resources. The body that certifies conducts its audits in Stage 1 and Stage 2.

The ISMS will not be forgotten simply because you pass the audits. After certification, controls and evidence must be maintained. Audits for surveillance will follow.

It is important to consider this when creating the program. Small-sized businesses don’t need an ISMS it could afford to create. It needs one its team is able to operate once the initial project has ended.

It is rare that an organization with the most employees has the best ISO 27001 program. It’s the one that meets the requirements, is based on genuine security practices, survives independent scrutiny, and is easily manageable after everyone has returned back to their work.