What a Cloud-Native Startup May Already Have in Place for ISO 27001

An entrepreneur can spend years without considering ISO 27001. A few days later, an email is sent from a promising enterprise customer: “Please provide your ISO 27001 certificate as part of our vendor security review.”

The certification issue has been resolved and will be discussed this year. It’s connected to a contract the company wants to close.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. The trick is figuring out the actual requirements without making a small security project into an enterprise-sized compliance program.

Week One should be all about Scope, not Shopping

The initial reaction is to start comparing compliance platforms and consultants. It is better to determine what ISMS (Information Security Management System) needs to protect.

It is essential to take into consideration the scope, since adding systems, locations, and processes that aren’t required can lead to further documentation or requirements for evidence.

A small SaaS company may have an environment largely focused on cloud infrastructure, employee devices and customer information. It could also be dominated by a few key suppliers. Understanding the context helps determine what the certification project actually needs to address.

Make a list of security you Already Have

Many businesses that are researching ISO 27001 to start ups think they’ll have to create a brand new security system.

This may not be accurate.

Modern startups might already have established cloud providers and require multi-factor identification, restricted employee permissions and system logs that can be used to manage documents for onboarding and offboarding. It’s still important to evaluate current practices against ISO 27001, but if you start with the practices that work currently, it could save unnecessary duplicates.

The remaining work involves preparing policies, conducting risk assessments, the determination of Annex A controls applicable, complete Statements of Applicability (SOA) and obtaining evidence.

Be aware of which invoices are paid for What

It’s easier to understand ISO 27001 costs when they aren’t summarized in a single figure.

When you look at the cost of an audit by an independent certifier, tools for compliance, and time spent by staff the first-year expenses could range from $10,000 and $30,000. Consulting fees can be added, but this isn’t a major expense.

The ISO 27001 certification cost charged by an accredited certification organization is important to distinguish from software fees. While a compliance platform may help in the process of organizing process, it is not able to issue a certificate. The certification process is an independent audit procedure.

Then, the evidence

It’s not enough simply to draft an policy that states employees can’t access the system upon their departure. Auditors require proof that the procedure is effective.

ISO 27001 is based on the distinction between showing and saying.

CertAssist facilitates this process without having to directly connect to an actual system. It offers all 93 ISO 27001 Annex A controls on one screen. It also includes customizable templates for policies and evidence, and a statement of Applicability.

A template for a small team can help eliminate the unorganized formulating of every policy in the blank page.

Certification Day isn’t the End Line

Depending on the company’s existing security procedures and capabilities, it may take a new company between three and six months to prepare for certification. The certification body will then conduct the Stage 1 and Stage 2 audits.

The fact that these audits are passed isn’t a reason to forget about the ISMS. Following certification, controls and proof must be maintained. Surveillance audits are to follow.

This is an important element to be considered when creating the program. It’s not enough for small businesses to have an ISMS which it can afford. It should have an ISMS that the team can access after the project is completed.

Rarely is the ISO 27001 programme for smaller organisations the most intelligent. It’s the one that conforms to the standard, reflects the true security standards, is able to withstand independent scrutiny and is in control when people return back to their work.