The Road From 93 Annex A Controls to a Finished Statement of Applicability

A startup can go years without thinking about ISO 27001. When an email arrives from an enterprise client who is promising: “Please provide your ISO 27001 certification as part of our security review for vendors.”

The issue of certification is no longer a topic that will be discussed next year. The company would like to close the specific contract.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. It’s an uphill task to decide what’s required in order to turn a simple project into a compliance plan for enterprises.

The first week of the week should be focused on Scope, not Shopping

The initial reaction is to begin comparing compliance platforms and consultants. It is more beneficial to know the requirements that ISMS (Information Security Management System) will need to cover.

The scope of the project is vital, as adding unnecessary procedures, processes, or locations to the documentation may result in additional evidence and the need for documentation.

Small SaaS companies, for instance they may have an environment which is centered around cloud infrastructures and employee devices, as well as client data, and only one or two key vendors. Knowing the context will help determine what certification project is required.

Review the Security You Already Possess

Many companies researching ISO 27001 to start ups think they’ll have to establish a new security operation.

That may not be true.

Modern startups may already have established cloud providers, and may require multi-factor identification, restricted employee permissions as well as system logs to track the onboarding process and documentation for offboarding. It’s still important to test current practices against ISO 27001, but if you begin with the best practices now, it can save unnecessary duplicates.

Documenting policies, performing a risk assessment, determining the relevant Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.

How to Know which invoice pays for what

The ISO 27001 cost becomes much simpler to understand if expenses aren’t lumped into a single number.

A small-sized business could range from $10,000 to $30,000 once the independent certification audit, compliance software, as well as internal staff time are considered. A consulting fee can be included, but it isn’t a major expense.

The ISO 27001 certification cost charged by a certified certification body is important to distinguish from software fees. A compliance platform may help organize the work, but it’s not able award the certificate. The independent auditing process is the process that validates the certificate.

Following the proof follows the accusations

An employee policy that states that the employee’s access to company resources is terminated upon the employee’s departure is not enough. Auditors require proof that the process is actually working.

This difference between proving and saying is the most important aspect of ISO 27001.

CertAssist manages this task without the need to directly connect to an actual system. It shows all the 93 ISO 27001-2022 Annex A control templates on a single board. An editable policy as well as an templates for evidence are also available.

Templates can be employed by small groups of people to reduce the laborious process of drafting every policy from scratch.

The Final Line isn’t Certification Day

A business that is beginning from scratch may have to invest between three to six months getting ready for certification. This is contingent upon their existing security practices, as well as the resources they have available. The certification body will then conduct Stage 1 and Stage 2 audits.

Achieving these audits doesn’t mean you have the right to completely forget about the ISMS. The ISMS has to continue to ensure that it has adequate controls and proof. Following the certification, surveillance audits are performed.

This is a crucial aspect to think about when designing the program. It’s not enough for a small-sized business to just have an ISMS that it can afford. It should have an ISMS that its team will be able to use once the project is over.

It’s rare to find the ISO 27001 programme for smaller organisations the most intelligent. It’s the one that meets the requirements, is based on genuine security practices, survives independent scrutiny and is feasible when employees return to their normal jobs.

Scroll to Top