When a Security Certificate Becomes Part of the Sales Process

A startup can go years without considering ISO 27001. An enterprise customer who is a good fit sends an email “Please supply ISO 27001 as part of our vendor evaluation.”

The issue of certification has been resolved and is going to be discussed in the coming year. The company is looking to complete an agreement.

ISO 27001 is a good starting point for many small enterprises. The challenge is to determine what’s necessary without transforming a simple compliance program into a massive security plan.

Week One should be about Scope, not Shopping

The first thought is to start comparing compliance platforms and consultants. The best way to begin is by defining the requirements that an ISMS or Information Security Management System needs to incorporate.

It is important to consider the scope, because adding locations, systems, and processes that are not essential can result in the need for further documentation or requirements for evidence.

Small SaaS businesses, for example might have a system that is focused on cloud infrastructures, employee devices, client data, and only some key vendors. Understanding the specific environment could assist you in determining the areas your certification project should address.

Take Inventory of Security You Already Have

Companies researching ISO 27001 for startups sometimes assume they need to build an entirely new security operation.

It could be that it is not the scenario.

Modern startups could already have established cloud providers that require multi-factor identification, limited employee permissions and system logs that can be used to manage the onboarding process and documentation for offboarding. The current practices must be assessed against ISO 27001 requirements, but beginning with what is in place can help avoid unnecessary duplicates.

The documentation of policies, the risk analysis, determining which Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.

How do you know which invoice pays for what

It’s easier to understand ISO 27001 costs when they aren’t summed up in a single figure.

If you take into account the costs of an independent certification audit, compliance tools and time for staff the first-year expense could range from $10,000 to $30,000. Consulting can add another expense but it’s not mandatory rather than an automatic necessity.

It is important to differentiate between ISO 27001 certification costs charged by a certified certification body and the software costs. A compliance platform may help manage the process, but it’s not able to issue the certificate. The independent auditing process is what validates the certificate.

Following the proof is presented, the accusation

It’s not enough to create the policy that states that employees are not allowed access upon their departure. The auditor needs evidence that the process actually effective.

ISO 27001 is based on the distinction between showing and saying.

CertAssist is designed to facilitate this work without connecting directly to live systems in a company. It contains all the 93 ISO 27001 Annex A controls on one screen. It also has editable templates for policy and proof, and a statement of Applicability.

Templates are a great tool for a small group to eliminate the lengthy process of creating each policy from scratch.

Certification Day Isn’t the Finish Line

Depending on the company’s existing security policies and resources, it may take a company that is new between three and six month to be ready for certification. The certification body then conducts Stage 1 and Stage 2 audits.

The fact that these audits are passed isn’t a reason to completely forget about the ISMS. After certification, control and evidence have to be maintained. Surveillance audits will follow.

That’s an important consideration when developing the program. It’s not enough for a small-sized business to simply have an ISMS that they can afford. It must have an ISMS that its team will be able to use once the project is completed.

It’s rare to find that an organization with the most employees has the most effective ISO 27001 program. The most reliable ISO 27001 programme is one that conforms to the requirements, has actual security practices, and is able to be able to withstand scrutiny by an independent third party and be manageable when everyone returns to work.

Latest news

Scroll to Top