What a Cloud-Native Startup May Already Have in Place for ISO 27001

It is possible for a startup to last for years with no even thinking about ISO 27001. A potential enterprise client is contacted via email “Please supply ISO 27001 as part of our vendor evaluation.”

The certification process isn’t something to think about next year. The company needs to conclude a particular contract.

ISO 27001 is a good start for many small businesses. The trick is to identify what’s necessary without transforming a simple compliance program into an enterprise-sized security program.

Week One Should Be About Scope, not Shopping

The initial reaction is to begin comparing compliance systems and consultants. The best place to start is to determine what Information Security Management System, or ISMS is required to cover.

It is important to consider the scope, since the addition of locations, systems, and processes that are not necessary can result in more documentation or proof requirements.

Small SaaS businesses, for example they may have an environment that is focused on cloud infrastructures employees’ devices, client information, and just some key vendors. Knowing the specifics of the environment will help you decide what your certification plan should be addressing.

Take Inventory of Security You Already Have

Companies researching ISO 27001 for startups sometimes assume they need to build an entirely new security operation.

This could not be true.

Modern startups may already have established cloud providers that require multi-factor identification, restricted employee permissions and system logs that can be used to manage the process of onboarding and offboarding. It’s important to review current practices in relation to ISO 27001, but if you begin with the best practices today, you can avoid unnecessary duplication.

The remaining tasks include establishing policies, conducting the risk assessment, determining the applicable Annex A controls, completing the Statement of Applicability and obtaining evidence.

How do you know which invoice pays for what?

It’s simpler to comprehend ISO 27001 costs when they aren’t summated in a single figure.

The initial cost for a small business could be as low as $10,000-$30,000 depending on the amount of time spent by employees, using software to monitor compliance, and an independent audits of certification. Consulting is a different expense however, it’s optional rather than an automatic requirement.

It is important to differentiate between ISO 27001 certification costs charged by a certified certification agency and software fees. A compliance platform can help manage the process, but it’s not able to issue the certificate. The process of independent auditing is what validates the certificate.

Then comes the evidence

It’s not enough to write an policy that states employees are denied access when they leave. Auditors need proof that the process is actually operating.

ISO 27001 is concerned with the distinction between stating something and demonstrating it.

CertAssist was created to assist in coordinating this process, but without connecting to live systems of the company. It lists all ISO 27001:2022 Annex A controls on a single board allows for editing of policy and evidence templates and supports the Statement of Applicability and permits auditing access only for read-only.

A small-sized team template can help eliminate the unorganized formulating of every policy in a blank page.

The End Line isn’t Certification Day

Based on the company’s current security policies and resources depending on the company’s security practices and resources, it could take between 3 and 6 month to prepare for certification. The certification body will conduct the Stage 1 and Stage 2 auditories.

The fact that these audits are passed isn’t a reason to completely forget about the ISMS. Controls and evidence have to be maintained as well as surveillance audits that follow after certification.

It is important to think about this while designing the program. Small companies don’t just need to have an ISMS they can afford. It should have an ISMS its staff can use after the project has ended.

It’s rare to find that the biggest company is the one with the best ISO 27001 program. It’s the one that meets the standards, has the true security standards, is able to withstand independent scrutiny, and is manageable when everyone returns back to their work.

Recent Post

Subscribe