How Templates Can Save Weeks of Policy Writing for a Small Security Team

ISO 27001 is not something that a startup should think about for many years. A promising enterprise customer is contacted via email “Please provide ISO 27001 as part of our review of the vendor.”

Certification is no longer something you’re supposed to think about the year ahead. The company is looking to complete the specific contract.

ISO 27001 can be a ideal starting point for businesses that are growing. It’s a challenge to determine what’s required without turning a manageable compliance program into a massive security initiative.

This Week, affixed to Scope and Not Shopping

It’s commonplace to assess compliance platforms as well as consultants. An alternative is to identify what Information Security Management System, or ISMS must cover.

It is crucial to think about the extent of the project, since the addition of systems, locations and procedures that aren’t required can lead to further documentation or requirements for evidence.

Small SaaS companies, for instance they may have an environment that’s focused around cloud infrastructures employees’ devices, client information, and some key vendors. Understanding the environment can help determine what the certification project actually needs to address.

Look over the Security You Already Possess

A few companies who are studying ISO 27001 as a startup suppose that they have to establish an entirely new security program.

It could be that it isn’t.

Modern startups may already use cloud providers, which require multi-factor authentication and restrict access for employees. They might also maintain systems logs and handle backups. Existing practices still need to be assessed against ISO 27001 requirements, but beginning with what is working can prevent unnecessary duplication.

The remainder of the work involves establishing policies, conducting the risk assessment, determining applicable Annex A controls, completing the Statement of Applicability, and gathering evidence.

Find out which invoice pays for What

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

A small company could be between $10,000 to $30,000 once the independent certification audit, compliance software and time spent by internal staff are taken into consideration. The consulting fee could be included, but it isn’t considered a necessary expense.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software-related fees. The compliance platform is a device that allows for the organization of work but is unable to issue a certification. The certification process is an independent audit process.

Following the evidence, follows the accusations

The mere fact of a policy that says employee access is removed after departure isn’t enough. The auditor will need to verify that the procedure is in place.

ISO 27001 is concerned with the difference between stating something and then demonstrating it.

CertAssist is designed to organize this task without connecting directly to live systems in a company. It offers all 93 ISO 27001 Annex A controls on one screen. It also includes editable templates for policy and proof, as well as a Declaration of Applicability.

Templates are a great tool for small groups to avoid the laborious process of drafting each policy from scratch.

The Line to the Finish Line isn’t Certification Day.

A business that is beginning from scratch may require between three to six months getting ready to be certified. This will depend on the security procedures they have in place, as well as available resources. The certification body conducts Stage 1 and Stage 2 audits.

The ISMS isn’t forgotten because you passed the audits. Following certification, controls and evidence must be maintained. Audits for surveillance will follow.

This is an important factor to take into consideration when developing the program. Smaller companies do not just have to possess an ISMS they can afford. It needs an ISMS that its team can utilize after the project has been completed.

Rarely is the ISO 27001 programme for smaller businesses the most efficient. It’s one that complies with ISO 27001 standards and reflects true security practices, endures independent audits and is manageable after everyone gets back to their normal jobs.

Scroll to Top