A Customer Wants ISO 27001: What Should a Small Company Do First?

A Customer Wants ISO 27001: What Should a Small Company Do First?

An entrepreneur can spend years without thinking seriously about ISO 27001. A few days later, an email is sent from a prospective enterprise customer: “Please provide your ISO 27001 certification as part of our security review for vendors.”

The certification process isn’t something you need to be thinking about for the next year. It’s because of a contract that the company is trying to close.

In the case of many companies that are growing this is the ideal starting point for ISO 27001 for small business. It’s a challenge to determine what’s needed without turning a manageable compliance program into a massive security initiative.

This Week, affixed to Scope and Not Shopping

The first reaction could be to begin comparing compliance platforms and consultants. The ideal place to begin is to define the requirements that an ISMS or Information Security Management System needs to incorporate.

It is essential to take into consideration the scope, because adding systems, locations, and processes that are not required can lead to the need for additional documentation or evidence.

A small SaaS firm may have an environment mostly focused on cloud infrastructure including employee devices, the information of customers. It might also be dominated by couple of key vendors. Knowing the specifics of the environment will aid in determining what your certification plan should be addressing.

Check out the Security You Already Have

Some companies looking into ISO 27001 as a startup believe that they need to create an entirely new security system.

It may not be the case.

Modern startups may already be using established cloud providers and need multi-factor authentication, restricted employee access and system logs that can be used to manage the process of onboarding and offboarding. It’s important to review current practices in relation to ISO 27001, but if you begin with the best practices currently, it could save unnecessary duplicates.

The documentation of policies, the risk analysis, determining which Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.

Be aware of which invoices are paid for What?

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

The initial costs for a small business may be between $10,000 and $30,000 based on the amount of time spent by staff, software to make sure compliance is maintained, and independent certification audit. A consulting fee can be added, however it isn’t a major expense.

The ISO 27001 Certification Cost charged by a certified certification body is essential to distinguish from software charges. The compliance platform is a tool that allows for the organization of work however it cannot issue the certificate. The independent auditing process is the one that certifies the certificate.

Then, the evidence

It’s not enough to write the policy that states that employees are not allowed access when they leave. The auditor needs to see evidence that the system is working.

This distinction between demonstrating and saying is the most important aspect of ISO 27001.

CertAssist is designed to facilitate this process without connecting directly to live systems in a company. It displays all ISO 27001:2022 Annex A controls on one page, provides editable policy and evidence templates, supports the Statement of Applicability, and allows auditor access that is read-only.

A small-sized team template will help you eliminate the inefficient formulating of every policy in the blank page.

Certification Day isn’t the Day to Cross the Finish Line

A business that is beginning from scratch could take anywhere from three to six months in preparation for certification, depending on its existing security procedures and resources. The certification body will then conduct the Stage 1 and Stage 2 audits.

Achieving these audits doesn’t mean you have the right to completely forget about the ISMS. After certification, the controls and evidence must be maintained. Surveillance audits will follow.

This is an important aspect to consider when creating the program. Smaller businesses do not only have to have an ISMS they can afford. It requires one that its team can realistically operate after the initial project has ended.

It is rare that the biggest company has the most effective ISO 27001 program. The best ISO 27001 system is one that complies with the requirements, has the best practices in security, and can stand up to scrutiny from an outsider and be able to be managed after everyone has returned to work.

Scroll to Top