How Templates Can Save Weeks of Policy Writing for a Small Security Team

A startup can go years without thinking seriously about ISO 27001. An email from an enterprise client asks for your ISO 27001 certification as part our security audit of the vendor.

Certification is suddenly not something you should be thinking about in the coming year. It’s tied to a contract that the company would like to terminate.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. It’s an uphill task to decide what’s required without turning a manageable project into a compliance program for larger companies.

Week One should be about Scope, not shopping

The first instincts can cause you to compare the platforms and consultants for compliance. It is better to determine what ISMS (Information Security Management System) should be able to cover.

The scope of the project is essential because adding inefficient methods, locations or systems to the documentation can create additional evidence and documentation requirements.

Small SaaS businesses, for example could have an environment which is centered around cloud infrastructures and employee devices, as well as customer information, and one or two key vendors. Understanding the surroundings will aid in determining what certification is needed.

Create a list of all the security that you have already

Many companies who are looking into ISO 27001 to start ups are assuming that they must create a brand new security operation.

It could be that it is not the situation.

Modern startups may already have established cloud providers, and may require multi-factor identification, restricted employee access as well as system logs to track, documentation for onboarding and offboarding. Practices in place must be assessed against ISO 27001 requirements, but beginning with what is in place can help avoid unnecessary duplicates.

The remaining work is preparing policies, completing risk assessments and finding Annex A controls applicable, complete Statements of Applicability (SOA) and gathering evidence.

Know Which Invoice Pays for What?

If expenses aren’t bundled into a single figure It is much simpler to grasp the ISO 27001 cost.

The first year’s expenses for a small company could be between $10,000 to $30,000 once the independent certification audit, compliance software, and internal staff time are taken into account. Consulting can add another expense however it’s an option instead of an automatic requirement.

The ISO 27001 certification cost charged by an accredited certification body is particularly important to differentiate from the fees for software. A compliance platform may help manage the process, but it cannot award the certificate. Certification is granted through an independent audit procedure.

Following the proof comes the accusations

It’s not enough simply to draft a policy that stipulates that employees cannot access information when they leave. An auditor needs evidence that the system actually functions.

ISO 27001 is concerned with the distinction between saying something and then demonstrating it.

CertAssist is designed to manage this task without connecting directly to live systems of a company. It displays all the 93 ISO 27001-2022 Annex A control templates on a single board. An editable policy as well as an evidence templates are also offered.

Templates can be utilized by small groups of people to reduce the tedious task of creating each policy by hand.

Certification Day Isn’t a Finish Line

A company starting from scratch can spend anywhere from three to six months getting certified dependent on its current security practices and available resources. The certification body conducts the Stage 1 and Stage 2 audits.

Achieving these audits doesn’t mean you have the right to forget about the ISMS. Controls and evidence have to be maintained and surveillance audits are conducted following certification.

That’s an important consideration when creating the program. A small company doesn’t merely require an ISMS it is able to afford to develop. It needs an ISMS its staff can use after the project has ended.

It’s not often that even the biggest organization has the best ISO 27001 program. It’s the one that satisfies the requirements of the standard, incorporates real security practices, stands up to independent scrutiny and is easily manageable after everyone has returned back to their work.

Let’s fight with all injustice and corruption

Scroll to Top