What a Cloud-Native Startup May Already Have in Place for ISO 27001

ISO 27001 is not something startups should think about for many years. An enterprise customer who is a good fit sends an email to “Please give us ISO 27001 as part of our vendor evaluation.”

Suddenly, certification isn’t something to be considered the next time. It’s tied to a contract that the company would like to terminate.

ISO 27001 can be a great starting point, especially for growing businesses. It’s a challenge to understand what’s required, without turning a scalable compliance program into an enterprise-sized security project.

Week One should be about Scope, not about shopping.

It may be instinctive to look at compliance platforms and consultants. The ideal place to begin is by defining the requirements that an ISMS or Information Security Management System needs to include.

The scope of the project is important, as adding unnecessary systems, locations or processes to the documentation could create additional evidence and the need for documentation.

A small SaaS company, like it may have a concentrated environment based around cloud infrastructure including employee devices, customer information, and a few of key vendors. Understanding the current environment can help you determine which certification is required.

Review the Security You Already Have

Companies researching ISO 27001 for startups sometimes think they will need to create an entirely new security program.

It could be that it isn’t.

Modern startups may already require multi-factor authentication. It could also restrict employees’ rights, manage system logs, manage backups, document onboarding and offboarding, and use the most well-known cloud providers. Current practices need to be assessed against ISO 27001 requirements, but beginning with what is in place can help avoid unnecessary duplicates.

The remaining task is to document policies, performing the risk assessment, determining the applicable Annex A controls, completing the Statement of Applicability and obtaining evidence.

Find out which invoice pays for What?

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

The initial cost for a small business may range from $10,000 to $30,000 depending on the time spent by employees, using software to make sure compliance is maintained, and independent certification audit. Consulting can be a cost in addition however it’s an option instead of an automatic requirement.

The ISO 27001 Certification Cost charged by a certification organization that is accredited is essential to distinguish from the software fees. The compliance platform is a tool that organizes work however it cannot issue the certificate. The certification is granted through an independent audit.

Following the proof is presented, the accusation

It’s not enough simply to draft an policy that states employees can’t access the system after they leave. Auditors need proof that the process actually functioning.

ISO 27001 is concerned with the difference between saying that something, and proving it.

CertAssist is designed to manage this process without connecting directly to live systems in a company. It provides all the 93 ISO 27001 Annex A controls all in one place. It also includes customizable templates for policies and evidence as well as a Statement of Applicability.

Templates can be utilized by small groups of people to reduce the laborious process of drafting every policy from scratch.

Certification Day is Not the Day to Cross the Finish Line

A company that is starting from scratch might need to spend between three and six month getting prepared for certification. It will be contingent on their existing security practices, and the available resources. The certification body then conducts the Stage 1 and Stage 2 audits.

After passing the audits, it isn’t enough to put aside your ISMS. Controls and evidence must be maintained as well as surveillance audits that follow after the certification.

It’s a key consideration when developing the program. It’s not enough for a small-sized business to have an ISMS that is affordable. It’s in need of one that will be able to run after the initial project is completed.

The most effective ISO 27001 program for a smaller company is not always the largest. It’s one that meets the ISO 27001 requirements, is based on true security practices, endures independent scrutiny and is able to be maintained once everyone returns to their normal jobs.

Scroll to Top