Group of doctors checking x-rays in a hospital

Preparing Evidence for an Auditor Without Connecting Another Tool to Your Systems

A start-up can be a long time without thinking seriously about ISO 27001. An email from an enterprise customer wants to know your ISO 27001 certification as part our security inspection of the vendor.

The certification issue is no longer a subject that is going to be discussed in the coming year. It’s related to an agreement that the company is trying to terminate.

ISO 27001 is a good start for many small firms. The trick is to understand what’s needed without turning a manageable compliance program into a massive security program.

Week One should be all about Scope, not Shopping

Your first instincts could lead you to start comparing compliance consultants and platforms. It is preferable to identify the requirements that ISMS (Information Security Management System) needs to be able to cover.

It is crucial to think about the scope, because adding locations, systems, and procedures that aren’t necessary can result in more documentation or proof requirements.

For instance, a smaller SaaS firm may have an environment mostly focused on cloud infrastructure including employee devices, the information of customers. It may also be dominated by few key vendors. Knowing the context will help determine what certification project is required.

List the security you already have

Companies who are looking at ISO 27001 for startups sometimes believe they must build an entirely new security process.

That may not be true.

Modern startups are likely to use cloud providers, which require multi-factor authentication, and limit employee access. They could also manage records of system activity and maintain backups. These practices should be assessed against ISO 27001 requirements. However, starting with the things that are already working will help avoid unnecessary duplicates.

The rest of the work includes preparing policies, performing risk assessments as well as finding Annex A controls applicable, complete Statements of Applicability (SOA), and gathering evidence.

You can now identify which invoices are paid for by what.

The ISO 27001 cost becomes much more understandable when expenses aren’t all lumped together into a single number.

The initial costs for a small business may range from $10,000 to $30,000 based on the time spent by staff, the software used to make sure compliance is maintained, and independent certification audit. A consulting fee can be included, but it isn’t a major expense.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. A compliance platform can assist manage the process, but it cannot award the certificate. The certification is awarded through an independent audit procedure.

Then comes the evidence

It’s not enough simply to draft a policy that says employees are denied access after they leave. Auditors require proof that the procedure is functioning.

ISO 27001 is based on the distinction between saying and showing.

CertAssist helps to manage this work without the need to connect directly to an actual system. It displays all the 93 ISO 27001-2022 Annex A control templates on one single board. An editable policy as well as an evidence templates are also included.

For a small team, templates can also remove the tedious task of writing every policy on an unfinished document.

The End Line isn’t Certification Day.

A business that is beginning from scratch may spend approximately three to six months in preparation for certification based on its current security policies and the resources available. The certification body then conducts Stage 1 and Stage 2 audits.

The ISMS will not be lost just because you pass the audits. The ISMS should continue to monitor controls and provide evidence. After certification, surveillance audits must be conducted.

That’s an important consideration when making the program. It’s not enough for small businesses to have an ISMS that they can afford. It should have an ISMS its staff can use after the project has been completed.

It’s rare to find that the largest organization has the best ISO 27001 program. The most reliable ISO 27001 programme is one that complies with the standard, reflects the best practices in security, and can withstand independent scrutiny and still be able to be managed after everyone has returned to work.

Scroll to Top