The ISO 27001 Scope Decision That Can Change Your Budget and Timeline

A startup can go years without thinking seriously about ISO 27001. A few days later, an email is sent from a prospective enterprise customer: “Please provide your ISO 27001 certificate to us as part of our vendor security review.”

It’s not something to think about in the coming year. The company would like to close the contract.

ISO 27001 is a good base for small companies. It’s a challenge to understand what’s required, without turning a scalable compliance program into an enterprise-sized security program.

This Week, affixed to Scope and Not Shopping

It may be instinctive to evaluate compliance platforms and consultants. The best place to start is by defining what ISMS or Information Security Management System needs to be able to contain.

It is important to know the scope because trying include unnecessary systems, locations, or processes can create further documentation requirements and proof requirements.

Small SaaS companies, for instance could have an environment that is focused on cloud infrastructures and employee devices, as well as client information, and just some key vendors. Knowing the specifics of the environment will assist you in determining the areas your certification program should focus on.

Take a look at the security you Already Have

Some companies looking into ISO 27001 as a startup suppose that they have to establish a new security operation.

It may not be the situation.

A modern startup might already require multi-factor authentication, limit employees’ access, keep systems logs, maintain backups documents onboarding and offboarding, and use the most well-known cloud providers. The current practices must be evaluated in relation to ISO 27001 requirements. However by starting with the practices which are working already can avoid unnecessary duplicates.

The remaining work includes preparing policies, performing risk assessments as well as the determination of Annex A controls applicable, creating Statements of Applicability (SOA), and gathering evidence.

How do you know which invoice pays for what

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

Initial expenses for a small organization may total roughly $10,000-$30,000 if the independent certification audit, compliance software as well as internal staff time are taken into consideration. The consulting fee could be added, however it isn’t a major expense.

It is important to differentiate between the ISO 27001 certification costs charged by a certified certification organization and the software costs. A compliance platform is a great tool to with the task, but it’s not able award the certificate. Certification is awarded through an audit conducted by an independent company.

Next, the evidence

It’s not enough to create an policy that states employees are not allowed access when they leave. An auditor requires evidence that the process actually operates.

That distinction between demonstrating and saying is the main point of ISO 27001.

CertAssist was created to assist facilitate this process, without connecting to the live systems of the business. It includes all 93 ISO 27001 Annex A controls all in one place. It also provides editable templates for policy and evidence as well as a Declaration of Applicability.

If you have a small group, templates can help remove the tedious task of drafting every policy from a blank sheet.

Certification Day isn’t the Finish Line

A company that is starting from scratch may have to invest between three and six months to get ready for certification. This will depend on the security procedures they have in place, and also the resources available. The body that certifies will perform Stage 1 and Stage 2 auditories.

Achieving these audits doesn’t mean you have the right to completely forget about the ISMS. The controls and evidence should be maintained as well as surveillance audits that follow following certification.

This is an important factor to think about when designing the program. Small-sized businesses don’t need an ISMS it can afford to build. It must have an ISMS that its team can utilize after the project has been completed.

The smartest ISO 27001 program for a smaller organization is rarely the most comprehensive. It’s one that is in line with the requirements of the standard, incorporates real security practices, stands up to independent scrutiny, and is in control when people return to their jobs.

Subscribe

Recent Post