What Your Team Will Be Doing During a Three-to-Six-Month ISO 27001 Project

ISO 27001 is not something that a startup should be thinking about for years. A potential enterprise client is contacted via email “Please provide ISO 27001 as part of our vendor evaluation.”

Now, certification isn’t a thing to consider the next time. It’s tied to a contract that the company would like to terminate.

For a majority of companies growing this is the ideal beginning point for ISO 27001 for small business. It’s an uphill task to decide the steps to take without turning a manageable project into an invasive compliance programme for larger companies.

Week One is supposed to be about Scope, not about shopping.

The initial reaction is to start comparing compliance platforms and consultants. It is best to establish what ISMS (Information Security Management System) will need to be able to cover.

The project’s scope is crucial to consider, since adding unnecessary methods, locations or systems to the documentation may create additional evidence and documents requirements.

For instance, a smaller SaaS company might have an environment that is mostly focused on cloud infrastructure such as employee devices and information about customers. It might also be dominated by a few key suppliers. Knowing the specifics of the environment will assist you in determining the areas your certification plan should be addressing.

Take a list of the security you already have

A few companies who are studying ISO 27001 as a startup assume that they must build an entirely new security program.

This could not be true.

A modern startup might already require multi-factor authentication, restrict employee permissions, maintain system logs, manage backups as well as document onboarding and offboarding procedures, and make use of well-established cloud providers. The current practices must be evaluated against ISO 27001 requirements, but beginning with what is in place can help avoid unnecessary duplicates.

The remaining tasks include establishing policies, conducting the risk assessment, determining the appropriate Annex A controls, completing the Statement of Applicability, and gathering evidence.

You now know the invoices that pay what

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

If you think about the expense of an audit by an independent certifier, tools for compliance and time spent by staff, a small company’s first-year expenses could range from $10,000 to $30,000. Consulting fees can be included, but it isn’t an essential expense.

The ISO 27001 certification cost charged by an accredited certification agency is important to distinguish from the software costs. The compliance platform functions as a device which can manage work, but cannot issue the certification. The certification is granted through an audit conducted by an independent company.

Then, the evidence

An employee policy that states that employees’ access to corporate resources is revoked after their departure isn’t enough. An auditor requires evidence that the process is actually working.

ISO 27001 is concerned with the difference between stating that something, and proving it.

CertAssist is designed to facilitate the work of CertAssist without directly connecting to a company’s live systems. It presents all 93 ISO 27001:2022 Annex A controls on one page It also provides editable policy and evidence templates and supports the Statement of Applicability and provides auditing access only for read-only.

For a small team, templates could also help to be a great way to avoid the inefficient task of writing every policy on a blank document.

The Line to the Finish Line isn’t Certification Day.

Based on the existing security procedures and capabilities It could take between three and six month to get certified. The certification body conducts its audits in Stage 1 and 2.

Passing those audits isn’t permission to forget about the ISMS. The controls and evidence should be maintained and surveillance audits must be conducted after the certification.

That’s an important consideration when creating the program. It’s not enough for small businesses to simply have an ISMS which it can afford. It requires an ISMS that ensures its team can work effectively following the initial project ended.

The smartest ISO 27001 program for a smaller organization is rarely the biggest. It must meet the ISO 27001 requirements, is based on the best practices in security, is subject to independent scrutiny, and is manageable once everyone returns to their normal jobs.

Recent Post

Our Gallery