When a Security Certificate Becomes Part of the Sales Process

It’s possible for a new company to continue for years without seriously considering ISO 27001. A few days later, an email is sent from a prospective enterprise customer: “Please provide your ISO 27001 certification as part of our vendor security audit.”

It’s not something you need to be thinking about for the next year. The company would like to close the specific contract.

ISO 27001 is a good base for small firms. The problem is to understand what’s required, without turning a scalable compliance program into an enterprise-sized security program.

Week One Should Be About Scope, Not Shopping

It may be instinctive to compare compliance platforms and consultants. It is preferable to identify the requirements that ISMS (Information Security Management System) should cover.

It is important to know the scope because trying include ineffective systems, locations or processes may result in additional documentation and requirements for evidence.

A small SaaS company, like might have a specific environment that is built around cloud infrastructure including employee devices, customer information, and a few of essential vendors. Understanding the specific environment can aid in determining what the certification process should cover.

Take Inventory of Security You Already Have

Some companies researching ISO 27001 as a startup assume that they must build an entirely new security program.

This could not be true.

Modern startups could already utilize cloud providers, require multi-factor authentication as well as restrict access to employees. They might also maintain the system logs and backups. These practices should be assessed against ISO 27001 requirements. However, starting with the things that work already will prevent unnecessary duplication.

Documenting policies, performing a risk assessment, determining the applicable Annex A Controls, completing the Statement for Applicability and collecting evidence are the remaining tasks.

How do you know which invoice is credited for what?

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

A small business can range from $10,000 to $30,000. This is when the independent certification audit, compliance software, as well as internal staff time are taken into consideration. The consulting fee could be added, however it is not an essential expense.

It is crucial to distinguish between the ISO 27001 certification costs charged by a certified certification organization as well as software-related fees. A compliance platform can help organize the work, but it’s not able award the certificate. The certification process is an independent audit process.

Then is presented, the accusation

A policy that stipulates that employees’ access to corporate resources is terminated upon their departure is not sufficient. The auditor needs to be able to verify that the procedure is working.

That distinction between saying and demonstrating is central to ISO 27001.

CertAssist was created to assist organize this process without connecting to the live systems of the company. It shows all 93 ISO 27001-2022 Annex A control templates on a single board. The ability to edit the policy and evidence template are also provided.

In a small team template will eliminate the inefficient writing of every policy on a blank page.

The Finish Line isn’t Certification Day.

A business that is beginning at the beginning may need to take between three and six months to get prepared for certification. This will depend on their security policies and procedures, and also the resources available. The certification body conducts the Stage 1 and Stage 2 audits.

It isn’t enough to ignore the ISMS. After certification, the controls and proofs must be maintained. Audits for surveillance will follow.

This is an important aspect to take into consideration when developing the program. Small businesses don’t just require an ISMS it can afford to build. It’s in need of one that can realistically operate after the initial project ends.

The most efficient ISO 27001 program for a smaller organization is rarely the most comprehensive. It’s one that is in line with the requirements of the standard, incorporates real security practices, stands up to independent scrutiny, and is in control when people return back to their work.

Recent Post