Preparing Evidence for an Auditor Without Connecting Another Tool to Your Systems

A start-up can be a long time without thinking seriously about ISO 27001. An enterprise customer who is a good fit sends an email to “Please supply ISO 27001 as part of our vendor review.”

Then, it’s not something to look at the next time. The company is looking to complete the specific contract.

In the case of many companies that are growing it’s the most practical starting point for ISO 27001 for small business. The challenge is figuring out what exactly needs to happen without making a small security project into an enterprise-sized compliance program.

This week, concentrate on Scope and not on Shopping

The first instincts can lead you to start comparing platforms and compliance experts. It is better to determine the requirements that ISMS (Information Security Management System) must provide.

The project’s scope is crucial, as adding unnecessary systems, locations or processes to the documentation could cause additional evidence or the need for documentation.

A small SaaS business, for instance it may have a concentrated environment based around cloud infrastructure including employee devices, customer information, and a handful of essential vendors. Understanding that environment helps establish the issues that the certification program requires to tackle.

Make a list of the security features you already have

Many companies that are researching ISO 27001 to start ups think they’ll have to develop a completely new security company.

It’s possible that this is not accurate.

Modern startups may already require multi-factor authentication. It could also restrict employees’ access, keep systems logs, maintain backups as well as document onboarding and offboarding procedures, and make use of the most well-known cloud providers. Practices in place must be assessed against ISO 27001 requirements, but beginning with what is effective can avoid unnecessary duplicates.

Documenting policies, performing a risk assessment, determining the applicable Annex A Controls, completing the Statement for Applicability and gathering evidence are all the remaining tasks.

Be aware of which invoices pay for What?

It’s easier to understand ISO 27001 costs when they don’t have to be summed into a single figure.

The first-year costs for a small company could be anywhere between $10,000 and $30,000 depending on the time devoted by staff, software to make sure compliance is maintained, and independent audits of certification. Consulting fees can be added, but this isn’t an essential expense.

The ISO 27001 certification cost charged by an accredited certification body is especially important to distinguish from software fees. Although a compliance system can aid in the organization of process, it is not able to issue an official certificate. The certification is granted through an independent audit.

Next, the evidence

An employee policy that states that employees’ access to corporate resources is suspended after their departure does not suffice. A auditor must be able to demonstrate that the process actually operates.

This difference between proving and saying is the most important aspect of ISO 27001.

CertAssist was designed to help in coordinating this process, but without connecting to the live systems of an organization. It presents all ISO 27001:2022 Annex A controls on a single board allows for editing of policy and evidence templates as well as the Statement of Applicability and provides auditors to access the system in a read-only mode.

A small-sized team template will eliminate the inefficient writing of every policy on one blank page.

The End Line isn’t Certification Day

Depending on the company’s existing security procedures and capabilities depending on their security policies and resources, it can take a new company between three and six months to prepare for certification. The certification body then conducts Stage 1 and Stage 2 audits.

The ISMS will not be lost just because you have passed the audits. After certification, controls and proofs must be maintained. Audits of surveillance will follow.

It is important to take this into consideration when developing the program. It’s not enough for a small business to just have an ISMS that they can afford. It should have an ISMS its staff will be able to use once the project is over.

The most intelligent ISO 27001 program for a smaller company is not always the largest. It must meet the ISO 27001 requirements, is based on authentic security practices, passes independent audits and is able to be maintained once everyone is back to normal duties.