Echo Forums

Preparing Evidence for an Auditor Without Connecting Another Tool to Your Systems

A start-up can be a long time without considering ISO 27001. An enterprise customer who is a good fit will send an email saying “Please provide ISO 27001 as part of our vendor review.”

The issue of certification has been resolved and will be discussed this year. It’s due to a contract that the company is attempting to end.

For a majority of companies growing it’s the most practical beginning point for ISO 27001 for small business. The trick is figuring out what exactly needs to happen without changing a simple security program into an enterprise-sized compliance plan.

This week, focus on Scope and Not Shopping

Initial instincts might cause you to compare the platforms and consultants for compliance. The ideal place to begin is to define the requirements that an ISMS or Information Security Management System needs to incorporate.

It is important to consider the extent of the project, since the addition of systems, locations and procedures that aren’t needed can create further documentation or requirements for evidence.

Small SaaS companies, for instance, may have an environment that’s centered around cloud infrastructures and employee devices, as well as customer information, and some key vendors. Understanding the current environment can help you determine which certification is required.

Take a look at the security you Already Have

Companies that are researching ISO 27001 for startups sometimes assume they need to build an entirely new security process.

It’s possible that this is not accurate.

A modern business may require multi-factor authentication, deter employees’ rights, manage the system logs, handle backups, document onboarding as well as offboarding, and also use the most well-known cloud providers. Current practices need to be evaluated against ISO 27001 requirements, but beginning with what is working can prevent unnecessary duplication.

The remaining task is to document guidelines, conducting the risk assessment, finding the applicable Annex A controls, completing the Statement of Applicability and obtaining proof.

Be aware of which invoices pay for What?

The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.

The initial cost for a small business could be between $10,000 and $30,000 based on the time spent by staff, the software used to monitor compliance, and an independent audits of certification. Consulting is a different expense, but it is optional rather than an automatic obligation.

It is crucial to distinguish between the ISO 27001 certification costs charged by a certified certification body and software fees. Although a compliance platform can help in the process of organizing task, it’s not capable of granting a certificate. The certification is granted through an independent audit.

Then, the proof

It’s not enough to write an policy that states employees are not allowed access after they have left. A auditor must be able to demonstrate that the process is actually working.

ISO 27001 is based on the distinction between showing and saying.

CertAssist is designed to organize this process without connecting directly to a company’s live systems. It displays all 93 ISO 27001:2022 Annex A controls on a single board It also provides editable policy and evidence templates and supports the Statement of Applicability, and allows auditor access that is read-only.

Templates can be employed by an enclave of people to cut out the time-consuming process of creating each policy from scratch.

Certification Day Isn’t a Finish Line

Based on the company’s current security procedures and capabilities depending on their security policies and resources, it can take a new company between 3 and 6 month to get certified. The certification body conducts audits in Stage 1 and 2.

The ISMS is not forgotten just because you pass the audits. The controls and evidence should be maintained and surveillance audits must be conducted after certification.

This is an important element to think about when designing the program. A small business doesn’t only require an ISMS it can afford to build. It requires an ISMS its team will be able to operate realistically following the initial project ended.

It is rare that the biggest company has the best ISO 27001 program. The best ISO 27001 system is the one that meets the standard, incorporates the best practices in security, and can stand up to scrutiny from an outsider and be manageable when everyone returns to work.