The Road From 93 Annex A Controls to a Finished Statement of Applicability

ISO 27001 is not something that startups need to be thinking about for years. A few days later, an email is sent from a potential enterprise client: “Please provide your ISO 27001 certification as part of our vendor security audit.”

It’s not something you’re supposed to think about for the next year. It’s tied into a contract which the company plans to end.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. It’s not easy to identify the steps to take without turning an easily manageable project into an invasive compliance programme that is geared towards enterprises.

This week, focus on Scope, and not shopping

It’s natural to evaluate compliance platforms and consultants. A better starting point is to figure out what Information Security Management System, or ISMS must cover.

It is important to consider the scope of your project, as adding locations, systems, and processes that aren’t essential can result in the need for the need for additional documentation or evidence.

For example, a small SaaS company might have an environment that is largely concentrated on cloud infrastructure such as employee devices and customer information. It might also be dominated by handful of key vendors. Understanding the specific environment could assist you in determining the areas the certification process should cover.

Take a look at the security you Already Possess

A few companies who are studying ISO 27001 as a startup suppose that they have to establish an entirely new security program.

This might not be correct.

Modern startups might already be using cloud providers, and may require multi-factor authentication and limit employee access. They could also manage records of system activity and maintain backups. It’s important to evaluate current practices against ISO 27001, but if you start with what is working now, it can save unnecessary duplicate work.

The remaining work involves preparing policies, conducting risk assessments in determining Annex A controls applicable, completing Statements of Applicability (SOA), and obtaining evidence.

Be aware of which invoices pay for What

The ISO 27001 cost becomes much easier to understand when expenses aren’t all lumped together into a single number.

Initial expenses for a small-sized business could range from $10,000-$30,000 if the independent certification audit, compliance software and staff time at the internal level are taken into account. Consulting can add another expense but it’s not mandatory rather than a mandatory requirement.

The ISO 27001 certification cost charged by an accredited certification agency is particularly important to differentiate from software fees. The compliance platform functions as a device that organizes work but it is not able to issue the certification. The certification process is an independent audit procedure.

Then Comes the Evidence

It’s not enough simply to draft a policy that says employees are denied access after they have left. Auditors will have to see evidence that the system is implemented.

ISO 27001 is concerned with the difference between saying something and actually demonstrating it.

CertAssist manages this task without needing to directly connect to live systems. It contains all the 93 ISO 27001 Annex A controls in one board. It also provides customizable templates for policies and evidence, along with a Statement of Applicability.

In a small group template, you will eliminate the inefficient documenting of each policy on a blank page.

Certification Day isn’t the End Line

A business that is beginning from scratch can spend anywhere from three to six months working towards certification, depending on its existing security practices and available resources. The certification body conducts Stage 1 and Stage 2 audits.

Once you’ve passed the audits you shouldn’t simply forget about your ISMS. The ISMS should continue to ensure that it has adequate controls and proof. After certification, surveillance audits are performed.

It’s essential to take this into consideration when developing the program. Small companies don’t just need to possess an ISMS they can afford. It needs an ISMS that its team will be able to use once the project has been completed.

It’s not often that the biggest organization has the top ISO 27001 program. It’s one that is in line with the requirements of the standard, incorporates the true security standards, is able to withstand independent scrutiny, and is manageable when everyone returns to their normal jobs.

Scroll to Top