A Customer Wants ISO 27001: What Should a Small Company Do First?

An entrepreneur can spend years without considering ISO 27001. A potential enterprise client sends an email “Please supply ISO 27001 as part of our vendor review.”

Certification is no longer something you should be thinking about for the next year. It has to do with a contract the company is trying to close.

ISO 27001 is a good base for small businesses. It’s a challenge to determine the steps to take in order to turn a simple project into a strict compliance program for enterprises.

Week One is about Scope, Not Shopping

The initial reaction is to begin comparing compliance systems and consultants. It is more beneficial to know what ISMS (Information Security Management System) needs to protect.

Scope is crucial because trying to add unnecessary locations, systems or procedures can result in more documentation and require additional evidence.

Small SaaS companies, for instance could have an environment that is focused on cloud infrastructures employees’ devices, customer information, and few key vendors. Understanding the specific environment could help you determine what the certification process should cover.

Make a list of the security features you already have

Companies researching ISO 27001 for startups sometimes assume they need to build an entirely new security program.

This may not be the case.

A modern business may require multi-factor authentication, restrict the access of employees, keep records of system activity, control backups in the document onboarding process and offboarding procedures, and make use of existing cloud services. The current procedures must be evaluated against ISO 27001 requirements. However, starting with the things which are working already will help avoid unnecessary duplicates.

The remainder of the task is preparing policies, completing risk assessments and the determination of Annex A controls applicable, creating Statements of Applicability (SOA), and collecting evidence.

It is now possible to identify which invoices pay for what.

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

The initial costs for a small business could be between $10,000 and $30,000 according to the amount of time spent by employees, using software to monitor compliance, and an independent certification audit. Consulting fees can be added, however it isn’t an essential expense.

The ISO 27001 Certification Cost charged by a certification agency that is accredited is particularly significant to distinguish from software charges. The compliance platform functions as a device that allows for the organization of work but is unable to issue a certification. Certification is awarded by an audit conducted by an independent company.

Then comes the proof

It’s not enough simply to draft an policy that states employees cannot access information upon their departure. An auditor needs evidence that the process is actually working.

ISO 27001 is based on the distinction between showing and saying.

CertAssist helps to manage this work without the need to connect directly to the live system. It presents all 93 ISO 27001:2022 Annex A controls on one screen allows for editing of policy and evidence templates as well as the Statement of Applicability and permits auditors to access the system in a read-only mode.

In a small team template can eliminate the inefficient documenting of each policy on a blank page.

Certification Day is Not the End Line

A company starting from scratch can spend anywhere from three to six months getting certified based on its current security practices and available resources. The certification body conducts its audits at both Stage 1 and Stage 2.

After passing the audits you can’t just go away from your ISMS. Following certification, controls and proofs must be maintained. Surveillance audits are to follow.

This is a crucial aspect to consider when making the program. It’s not enough for a small business to have an ISMS that is affordable. It must have an ISMS that its team can utilize after the project is over.

It is rare that the biggest company has the most effective ISO 27001 program. It must meet ISO 27001 standards, reflects authentic security practices, passes independent inspection and is manageable after everyone is back to their regular jobs.