The ISO 27001 Scope Decision That Can Change Your Budget and Timeline

It’s possible for a new company to continue for years without taking seriously the idea of ISO 27001. A few days later, an email is sent from an enterprise client who is promising: “Please provide your ISO 27001 certificate as part of our vendor security audit.”

Certification is suddenly not something you’re supposed to think about in the coming year. It’s related to an agreement that the company is attempting to end.

ISO 27001 is a good base for small-scale firms. The trick is figuring out what needs to be done without becoming a manageable security initiative into an enterprise-sized compliance program.

Week One is supposed to be about Scope, not about shopping.

It is common to compare compliance platforms and consultants. The most effective place to start is by defining what ISMS or Information Security Management System needs to include.

Scope is crucial because trying to include unneeded systems, locations or processes could result in further documentation requirements and proof requirements.

For example, a small SaaS company might have an environment that is largely concentrated on cloud infrastructure including employee devices, information about customers. It could also be dominated by a couple of key suppliers. Understanding the environment will help you determine which certification is needed.

Review the Security You Already Have

Some companies looking into ISO 27001 as a startup believe that they need to create an entirely new security system.

However, this may not be the case.

A modern startup might already require multi-factor authentication, deter employees’ access, keep systems logs, maintain backups documents onboarding and offboarding, and utilize well-established cloud providers. The existing practices need to be compared against ISO 27001 requirements. However beginning with the elements that are already working will avoid duplicate work.

The documentation of policies, the risk assessment, determining the applicable Annex A Controls, completing the Statement for Applicability and gathering evidence are the remaining tasks.

Be aware of which invoices pay for What?

The ISO 27001 cost becomes much simpler to understand if expenses aren’t bundled into one number.

When you look at the cost of an audit by an independent certifier, tools for compliance, and time for staff the first-year expenses could range from $10,000 to $30,000. Consulting fees can be a part of the equation, but it isn’t an essential expense.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. The compliance platform is a device that organizes work but it is not able to issue the certification. Certification is granted through an independent audit process.

Then comes the proof

An employee policy that states that employees’ access to company resources will be revoked following the employee’s departure is not enough. Auditors will have to verify that the system is working.

ISO 27001 is concerned with the distinction between saying something and demonstrating it.

CertAssist manages this task without the need to connect directly to live systems. It contains all the 93 ISO 27001 Annex A controls all in one place. It also includes editable templates for policy and evidence and a statement of Applicability.

A template for a small team can help eliminate the unorganized documenting of each policy on one blank page.

The Line to the Finish Line isn’t Certification Day.

Based on the current security practices and resources depending on the company’s security practices and resources, it could take between 3 and 6 month to be ready for certification. The certification body conducts Stage 1 and Stage 2 audits.

Once you’ve passed the audits you can’t just ignore your ISMS. The ISMS should continue to maintain controls and evidence. After certification, surveillance audits must be carried out.

This is an important element to be considered when creating the program. Smaller businesses do not only have to have an ISMS they can afford. It requires an ISMS that ensures its team will be able to work effectively following the initial project ended.

It is rare that the biggest company has the top ISO 27001 program. It’s one that meets the ISO 27001 requirements, is based on real security practices, withstands independent audits and is manageable after everyone is back to normal duties.

Scroll to Top