ISO 27001 is a specification for an information security management system (ISMS) published by the International Organization for Standardization (ISO). An ISMS is a framework of policies, procedures, processes, and various technical controls that set the information security rules for an organization.
It's hard to imagine a 'good time' to receive customer requests for an independent certification of your organization's controls. However, with the right mindset, it can be a power for good. If a customer never asked for a review, you may not have found that glowing, flashing, red, problem hiding in the corner of the environment that, had it gone unnoticed, may have been the reason your organization's name ended up on the news.
As a security professional, I’d like to see all organization leverage frameworks like ISO 27001 to ensure that they have a properly implemented ISMS. But, like most things, frameworks and certifications vary from one to the other.
Certain audits, like a SOC Audit, are often easier to obtain, can be less expensive, and the timeline is often shorter. These can be compelling reasons for many organizations – especially those who view an audit as “checking the box”. However, I think it’s important to note that SOC Auditing standards are not a security framework and may not help your organization prevent or respond to data breaches.
I have worked with organizations that implemented an ISMS based on ISO 27001 without going through the certification process, but simply because they recognized the need for better security and cyber resilience. However if you want to be certified, you’ll need to be able to show that you have defined security processes in place. You need to show who is responsible for what. You also need to demonstrate what you are doing to manage risk and how you would handle a breach if one is detected. Frankly, ISO 27001 requires that you’ve given data protection the attention it deserves, and you continue to do so on an ongoing basis.
To be certified you must follow the certification process that includes an assessment by an organization approved to perform ISO 27001 certification and also have an audit of your ISO 27001 ISMS performed independently.
The ISO 27001 standard has a good deal of flexibility however there are some hard and fast requirements:
To summarize, is ISO 27001 perfect? No framework is, or anything else for that matter. But, ISO 27001 makes organizations more resilient to attack and more likely to be able to detect / respond sooner. If you're curious if ISO 27001 is right for you, reach out. Always happy to chat.