The Road From 93 Annex A Controls to a Finished Statement of Applicability

ISO 27001 is not something startups should be thinking about for a number of years. An email from a business customer wants to know your ISO 27001 certification as part our security review of vendors.

Suddenly, certification isn’t something to be considered next year. It’s connected to a contract that the company would like to terminate.

ISO 27001 can be a ideal starting point for companies that are growing. The trick is figuring out what needs to be done without becoming a manageable security initiative into a massive compliance program.

Week One should be about Scope, not shopping

It’s commonplace to compare compliance platforms and consultants. The ideal place to begin is by defining what ISMS or Information Security Management System needs to incorporate.

It is essential to take into consideration the scope, because the addition of systems, locations or processes that aren’t needed can create more documentation or proof requirements.

A small SaaS business, for instance, may have a relatively concentrated environment based around cloud infrastructure employees’ devices, customer information, and a few of essential vendors. Knowing the specifics of your environment will aid in determining what your certification plan should be addressing.

Make a list of the security features you already have

Companies looking into ISO 27001 for startups sometimes assume they need to build an entirely new security process.

It may not be the instance.

Modern startups may already have established cloud providers and need multi-factor identification, restricted employee access and system logs for managing documents for onboarding and offboarding. The current practices must be compared against ISO 27001 requirements. However by starting with the practices which are working already will prevent unnecessary duplication.

The remainder of the job involves preparing policies, conducting risk assessments in the determination of Annex A controls applicable, making Statements of Applicability (SOA) and collecting evidence.

Be aware of which invoices pay for What?

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

The first-year costs for a small business could be between $10,000 and $30,000 according to the time devoted by staff, software to monitor compliance, and an independent audits of certification. Consulting fees can be added, but this isn’t a major expense.

It is important to distinguish between ISO 27001 certification costs charged by a certified certification body and the software costs. Although a compliance system can help in the process of organizing work, it cannot issue the certificate. Certification is awarded through an independent audit.

Following the proof follows the accusations

A policy that stipulates that employees’ access rights to company resources will be revoked following their departure is not sufficient. A auditor must be able to demonstrate that the procedure actually works.

ISO 27001 is based on the distinction between saying and showing.

CertAssist was designed to help to manage this process without having to connect to live systems of the company. It shows all the 93 ISO 27001-2022 Annex A control templates on a single board. An editable policy as well as an templates for evidence are also available.

Templates can be utilized by small groups of people to reduce the laborious process of drafting every policy from scratch.

The Final Line isn’t Certification Day.

An organization that is just starting from scratch may have to invest between three and six month getting prepared to be certified. This is contingent upon their current security practices as well as available resources. The body that certifies will conduct the Stage 1 and Stage 2 auditories.

After passing the audits, you shouldn’t simply ignore your ISMS. The ISMS should continue to keep track of controls and records. Following the certification, surveillance audits are performed.

This is a crucial aspect to think about when designing the program. Smaller businesses do not only have to possess an ISMS they can afford. It must have an ISMS that the team can use after the project has been completed.

It’s not often that even an organization with the most employees has the most effective ISO 27001 program. It’s one that meets the ISO 27001 requirements, is based on the best practices in security, is subject to independent audits and can be managed once everyone gets back to their normal jobs.

Newsletter

Recent Post

Scroll to Top