Louis Proud

Preparing Evidence for an Auditor Without Connecting Another Tool to Your Systems

A startup can go years without thinking about ISO 27001. When an email arrives from a prospective enterprise customer: “Please provide your ISO 27001 certification as part of our security review for vendors.”

Certification is no longer something you need to be thinking about for the next year. The company needs to conclude an agreement.

ISO 27001 can be a ideal starting point for businesses that are growing. It’s an uphill task to decide the steps to take without turning a manageable project into an invasive compliance programme that is geared towards enterprises.

Week One is supposed to be about Scope, not about shopping.

It’s natural to look at compliance platforms and consultants. An alternative is to determine what the Information Security Management System, or ISMS should cover.

It is essential to take into consideration the scope, because the addition of systems, locations and processes that aren’t required can lead to further documentation or requirements for evidence.

A small SaaS business, for instance could have a specific environment that is built around cloud infrastructure as well as employee devices, customers details, and even a handful of important vendors. Understanding the specific environment can help you determine what your certification project should address.

Review the Security You Already Have

Some companies looking into ISO 27001 as a startup believe that they need to create an entirely new security system.

It could be that it is not the scenario.

Modern startups may already use cloud providers, and may require multi-factor authentication as well as restrict access for employees. They may also keep system logs and manage backups. Practices in place must be assessed against ISO 27001 requirements, but by starting with what’s in place can help avoid unnecessary duplicates.

The documentation of policies, the risk analysis, determining which Annex A Controls, completing the Statement for Applicability and gathering evidence are all the remaining tasks.

Be aware of which invoices pay for What?

The ISO 27001 cost becomes much simpler to understand if expenses aren’t all lumped together into a single number.

The initial cost for a small company could range from $10,000 to $30,000 depending on the amount of time required by staff, the software used to ensure compliance, and independent certification audit. The cost of consulting can be added, but this is not an essential expense.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. A compliance platform may help in the organization of work, however it’s not able to issue the certificate. The independent auditing process is what validates the certificate.

Then follows the accusations

An employee policy that states that employees’ access to company resources is suspended after the employee’s departure is not enough. Auditor needs proof that the system is effective.

ISO 27001 is based on the distinction between showing and saying.

CertAssist is designed to facilitate the work of CertAssist without directly connecting to a company’s live systems. It displays all 93 ISO 27001-2022 Annex A control templates on one screen. An editable policy as well as an evidence templates are also offered.

For small teams, templates could also help to eliminate the inefficient process of writing each policy from a blank sheet.

The Final Line isn’t Certification Day.

A new company could take anywhere from three to six months preparing for certification according to its current security policies and the resources available. The body that certifies conducts its audits at the stages 1 and Stage 2.

Passing those audits isn’t permission to forget about the ISMS. Controls and evidence must be maintained and surveillance audits must be conducted following the certification.

This is an important aspect to take into consideration when designing the program. It’s not enough for a small company to just have an ISMS which it can afford. It requires an ISMS its team will be able to function realistically after the initial project has ended.

The most effective ISO 27001 program for a smaller company is not always the most powerful. The best ISO 27001 program is one that conforms to the standard, incorporates real security practices, can be able to withstand scrutiny by an independent third party and be manageable after everyone returns to work.