How Templates Can Save Weeks of Policy Writing for a Small Security Team

Startups can go for years without even thinking about ISO 27001. An enterprise customer who is a good fit is contacted via email “Please provide ISO 27001 as part of our vendor evaluation.”

Now, certification isn’t a thing to look at next year. It’s due to an agreement the business is attempting to end.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. It’s a challenge to determine the steps to take without turning a manageable project into an invasive compliance programme for large corporations.

Week One should be about Scope, Not Shopping

The first reaction could be to compare compliance platforms and consultants. It is more beneficial to know the requirements that ISMS (Information Security Management System) should be able to cover.

The project’s scope is crucial since adding unneeded procedures, processes, or locations to the documentation can create additional evidence and the need for documentation.

For instance, a small SaaS firm may have an environment predominantly concentrated on cloud infrastructure such as employee devices and customer information. It might also be dominated by a small number of major vendors. Knowing the specifics of the environment will help you decide what your certification program should focus on.

Look over the Security You Already Have

Many companies researching ISO 27001 to start ups believe they’ll need to develop a completely new security system.

This might not be correct.

Modern startups might already be using cloud providers, and may require multi-factor authentication and limit access for employees. They might also maintain the system logs and backups. The existing practices need to be compared against ISO 27001 requirements. However beginning with the elements that work already will avoid duplicate work.

The remainder of the job involves preparing policies, conducting risk assessments in the determination of Annex A controls applicable, complete Statements of Applicability (SOA), and collecting evidence.

Know Which Invoice Pays for What?

The ISO 27001 cost becomes much more understandable when expenses aren’t lumped into a single number.

If you take into account the costs of an independent certification audit, compliance tools, and time spent by staff the first-year expenditure may be anywhere between $10,000 and $30,000. Consulting is an additional cost, but it is not a requirement.

The ISO 27001 certification cost charged by an accredited certification organization is crucial to distinguish from the software costs. The compliance platform is a device that allows for the organization of work but is unable to issue a certification. The certification process is an independent audit process.

Then, we will look at the evidence

The mere fact of a policy that says access to employees is restricted after departure isn’t enough. Auditors need evidence to prove that the process actually operates.

ISO 27001 is concerned with the difference between stating that something, and proving it.

CertAssist was created to assist to manage this process without having to connect to the live systems of the business. It contains all the 93 ISO 27001 Annex A controls all in one place. It also provides customizable templates for policies and documentation, and a statement of Applicability.

For small teams, templates can help eliminate the inefficient process of drafting every policy from a blank sheet.

Certification Day isn’t the End Line

A company starting from scratch can take between three and six months preparing for certification dependent on its current security practices and available resources. The certification body conducts its audits at Stage 1 and Stage 2.

The fact that these audits are passed isn’t a reason to ignore the ISMS. The ISMS must be able to maintain controls and evidence. After certification, surveillance audits must be performed.

This is an important aspect to take into consideration when designing the program. It’s not enough for a small-sized business to just have an ISMS which it can afford. It must have an ISMS that its team can access after the project has ended.

It’s rare to find that an organization with the most employees has the top ISO 27001 program. The most reliable ISO 27001 programme is one that complies with the standard, incorporates genuine security practices, and can stand up to scrutiny from an outsider and be manageable after everyone returns to work.

Get our best recipes & expert tips right into your inbox!

Join over 10k subscribers

By submitting above, you agree to our privacy policy.