What a Cloud-Native Startup May Already Have in Place for ISO 27001

It’s possible for startups to continue for years without having a serious look at ISO 27001. An email from an enterprise client solicits your ISO 27001 certification as part our security review of vendors.

The issue of certification is no longer something that will be debated next year. It’s tied to a deal that the company would like to terminate.

For a lot of growing businesses, that’s the practical base for ISO 27001 for small business. It’s a challenge to determine what’s required without turning an easily managed project into a strict compliance program for large corporations.

This week, concentrate on Scope, not Shopping

It’s natural to look at compliance platforms and consultants. It is more beneficial to know the requirements that ISMS (Information Security Management System) needs to cover.

The scope of the project is important since adding unneeded procedures, processes, or locations to the documentation can result in additional evidence and requirements for documentation.

For example, a small SaaS company may have an environment heavily focused on cloud infrastructure, employee devices and customer data. It may be also dominated by a few key suppliers. Understanding this environment will help establish what the certification project actually must address.

Review the Security You Already Have

A few companies who are studying ISO 27001 as a startup think that they will need to build an entirely new security system.

It could be that it is not the instance.

Modern startups might already be using cloud providers, and may require multi-factor authentication and limit access to employees. They could also manage system logs and manage backups. It is still necessary to evaluate current practices against ISO 27001, but if you start with what works now, it can save unnecessary duplicate work.

The rest of the work involves the preparation of policies, completing risk assessments as well as finding Annex A controls applicable, complete Statements of Applicability (SOA), and obtaining evidence.

Know Which Invoice Pays for What

It’s simpler to comprehend ISO 27001 costs when they aren’t summarized in a single figure.

The initial costs for a small business may be between $10,000 and $30,000, depending on the amount of time required by employees, using software to make sure compliance is maintained, and independent certification audit. Consulting is an additional expense, but it’s not an obligation.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. A compliance platform may help with the task, but it cannot award the certificate. Certification is awarded by an audit conducted by an independent company.

Then comes the proof

Writing a policy stating that access to employees is restricted after departure isn’t enough. Auditors need proof that the process actually operating.

The distinction between saying and demonstrating is central to ISO 27001.

CertAssist was created to assist organize this process without connecting to the live systems of the company. It includes all 93 ISO 27001 Annex A controls in one board. It also includes editable templates for policy and evidence as well as a Statement of Applicability.

A small team can benefit from templates. templates can also reduce the time-consuming process of writing each policy from a blank sheet.

Certification Day isn’t the Finish Line

A company starting from scratch could take anywhere from three to six months working towards certification based on its current security practices and resources. The certification body conducts the Stage 1 and Stage 2 audits.

The fact that these audits are passed isn’t a reason to forget about the ISMS. After certification, control and evidence must be maintained. Surveillance audits are to follow.

It’s important to consider this when developing the program. Small businesses don’t only need to possess an ISMS they can afford. It needs an ISMS that its team will be able to use once the project has ended.

It is rare that the biggest company has the top ISO 27001 program. It’s one that complies with ISO 27001 standards and reflects real security practices, withstands independent scrutiny, and is manageable once everyone gets back to their normal jobs.

Recent Post

Table of Contents