Understanding where to start with ISO 27001 can feel somewhat overwhelming, but we are here to help!
By the time you’ve finished this guide you’ll understand what ISO 27001 is, what the benefits are, how it works and why it’s a great framework for blended security.
What is ISO 27001?
At its core, ISO 27001 is a globally recognised framework designed to help organisations establish, implement, maintain, and continually improve an information security management system.
ISO 27001 includes requirements for managing information assets by considering people, processes, technology, and physical controls. The wholistic nature of ISO 27001 makes it the perfect framework to approach blended security processes and controls across your organisation.
Before you start…
ISO 27001 should not be treated as a checklist exercise; it should be seen a continual improvement journey. Embrace it as such and you will improve your overall security posture.
Why might you need it?
ISO 27001 ultimately shows your clients that you are serious about security, and you follow best practices to keep their data secure.
Why is it an excellent choice as a framework?
How does it work?
What are the controls?
The ISO 27001 framework is broken down into 2 parts.
Firstly, there are the core requirements needed to run an ISMS (Information Security Management System), this is your governance and process piece. This looks at context, leadership, planning, support, operation, performance evaluation and improvement. These are broken down below.
The second part of ISO 27001 is the Annex A controls, which are broken down into 4 themes. There are 93 controls across the 4 security domains;
This blended approach across all the controls ensures that security is not restricted to one part of the business.
Where do I start?
The first thing you need to do is to get leadership support and buy in from the organisation. Once this is in place you need to:
Other important things to consider:
How long does it take?
There are lots of different factors that will determine how long it takes such as the size of your organisation, the number and complexity of processes, number of locations and number of employees. You also need to consider the current maturity of your information security capability and the knowledge that exists already within your organisation.
However, we’d typically say that you need to allocate at least 6 – 12 months.
We would recommend treating the certification as a project and managing it this way, whether it is done completely in-house or supported by an ISO 27001 consultant.
How often do you need to re-certify?
You need to complete a full audit every 3 years and surveillance audits need to be done annually.
How much involvement from senior management?
You need top management ‘buy-in’. A reputable auditor will need to be satisfied that the ISMS is integrated into the wider organisation and not just a siloed initiative being run in isolation.
How much does it cost?
It depends on your size, complexity, the scope, and the accreditation certification body chosen. The cost of the audit for small businesses starts at £6k whereas larger organisations should expect to pay more.
The cost of implementation, whether you are paying for consultancy support or just internal time and resources should also be factored in.
Altogether small businesses might need to budget £15-20k and larger organisations significantly more than this.
What are the alternatives?
IASME Cyber Assured is the Cyber Essentials equivalent of ISO 27001, looking for processes, policies and procedures that support a system of governance and information security.
Cyber Essentials is the cheapest technical controls framework, but it is far more prescriptive / black & white and can be challenging for some organisations to achieve if your IT is not proactively centrally managed or you do not have a robust and fast patching schedule, especially.
Achieving ISO27001 certification can seem daunting and overwhelming, lots of organisation prefer to partner with a third-party organisation.
If you are interested in implementing ISO 27001 in your organisation and would like to speak to Toro please get in touch. Toro have supported 100’s of organisations achieve ISO 27001 and have done this both as a stand along project or as part of a wider security improvement programme.
If you want to watch our latest webinar which demystifies ISO 27001, please view it here.