Why Your Compliance Platform and Certification Body Have Completely Different Jobs

An entrepreneur can spend years without considering ISO 27001. An email from an enterprise customer requests your ISO 27001 certification as part our security inspection of the vendor.

Now, certification isn’t a thing to consider next year. It’s related to a contract the company is trying to close.

For a majority of companies growing it’s the best beginning point for ISO 27001 for small business. It’s not easy to identify what’s required without turning an easily managed project into a strict compliance program for enterprises.

Week One should be about Scope, not Shopping

The first instincts can make you start looking at the platforms and consultants for compliance. The most effective place to start is by defining the requirements that an ISMS or Information Security Management System needs to include.

It is important to know the scope because trying include unnecessary systems, locations or procedures can result in further documentation requirements and proof requirements.

Small SaaS businesses, for example, may have an environment that is focused on cloud infrastructures and employee devices, as well as customer information, and one or two key vendors. Understanding the specific environment could assist you in determining the areas your certification project should address.

Take a list of the security features you already have

Many businesses that are researching ISO 27001 to start ups think they’ll have to develop a completely new security operation.

However, this may not be the case.

Modern startups may already have established cloud providers and need multi-factor authentication, a restricted set of employee permissions and system logs for managing the process of onboarding and offboarding. It’s still important to assess existing practices against ISO 27001, but if you begin with the best practices today, you can avoid unnecessary duplication.

The remainder of the work involves establishing policies, conducting the risk assessment, finding the applicable Annex A controls, completing the Statement of Applicability, and gathering evidence.

You now know which invoices pay for what

When expenses are not bundled into a single figure and are not bundled into one number, it’s easier to understand the ISO 27001 cost.

The first year costs for a small company could be anywhere between $10,000 and $30,000, depending on the amount of time required by employees, the use of software to monitor compliance, and an independent audits of certification. Consulting costs are an additional expense, but it’s not a requirement.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. The compliance platform functions as a tool that organizes work but is unable to issue a certification. Certification is granted through an independent audit process.

Then Comes the Evidence

Writing a policy stating that employee access is removed after the employee’s departure isn’t enough. An auditor requires evidence that the process is actually working.

ISO 27001 is concerned with the difference between stating that something, and proving it.

CertAssist was created to assist to manage this process without having to connect to live systems of an organization. It includes all the 93 ISO 27001 Annex A controls on one screen. It also includes editable templates for policy and documentation, as well as a Declaration of Applicability.

If you have a small group, templates could also help to eliminate the inefficient process of drafting every policy from a blank sheet.

Certification Day Isn’t a Finish Line

A new company can spend anywhere from three to six months getting certified dependent on its current security practices and resources. The certification body conducts Stage 1 and Stage 2 audits.

After you have passed the audits, you can’t just forget about your ISMS. After certification, controls and evidence have to be maintained. Surveillance audits are to follow.

It is important to take this into consideration when creating the program. Small businesses don’t only need to have an ISMS they can afford. It should have an ISMS that its team can access after the project is completed.

Rarely is the ISO 27001 programme for smaller companies the most effective. The most reliable ISO 27001 programme is one that adheres to the standards, is based on real security practices, can be able to withstand scrutiny by an independent third party and be able to be managed after everyone has returned to work.