{"id":38596,"date":"2020-02-25T05:14:59","date_gmt":"2020-02-25T09:14:59","guid":{"rendered":"https:\/\/www.mrisoftware.com\/sg\/blog\/were-iso-27001-certified-heres-why-it-was-worth-it\/"},"modified":"2022-05-08T22:40:42","modified_gmt":"2022-05-09T02:40:42","slug":"were-iso-27001-certified-heres-why-it-was-worth-it","status":"publish","type":"post","link":"https:\/\/www.mrisoftware.com\/sg\/blog\/were-iso-27001-certified-heres-why-it-was-worth-it\/","title":{"rendered":"We\u2019re ISO-27001 certified. Here\u2019s why it was worth it"},"content":{"rendered":"<p>Are you a cloud-based service looking into getting ISO-27001 certification? Are you wondering about the process, the benefits, and whether it\u2019s worth it?<\/p>\n<p>There are a lot of articles about ISO-27001 written by security and compliance consultancy firms, but there\u2019s not much out there about what it\u2019s actually like from the perspective of an organisation going through the process.<\/p>\n<p>This was something we thought was lacking when we were doing our research, so we thought \u2013 why don\u2019t we share our first-hand account?<\/p>\n<p>This blog post addresses some of the big questions we had before making a decision.<\/p>\n<h2>Why become ISO-27001 certified?<\/h2>\n<p>After completing our GDPR compliance requirements prior to its implementation in May 2018 we decided to pursue ISO-27001 certification.<\/p>\n<p>We realised that in an ever-evolving security landscape, our customers were becoming more and more stringent in their procurement process. With major security breaches such as the Dropbox incident in 2016 (which led to the leaking of 68 million user passwords) and the iCloud leak of more than 500 private celebrity photos in 2014, organisations are much more aware of the security risks of using cloud-based services.<\/p>\n<p>Prospective customers were beginning to ask us detailed and specific questions about our security management processes. One question that kept coming up was \u201cAre you ISO 27001-certified?\u201d We knew many of our competitors were attaining SOC 2, but direct customer feedback was telling us that ISO-27001 was more important for our particular service and market niche: we serve many international enterprises, and ISO is more globally applicable than SOC 2. This, of course, is something that your organisation needs to weigh up.<\/p>\n<h2>How long does it take to get ISO-27001 certified?<i>\u00a0<\/i><\/h2>\n<p>We found it really difficult to find an answer to this online \u2013 and now it\u2019s very clear why. It really does completely depend on your organisation. We had read everything from a couple of months to more than a year. It took us 18 months.<\/p>\n<p><b>There were a few factors that stretched the process out for us:<\/b><\/p>\n<ul>\n<li>We are a relatively small team, and we did not have a dedicated person working on this full-time, so our IT and Security departments were working on ISO over and above BAU.<\/li>\n<li>We also decided to address and meet every control as outlined in Annex A of the standard, including things that were not necessarily risks for us. This was a decision to be completely thorough and follow best practice. Some organisations might not choose to do this.<\/li>\n<\/ul>\n<blockquote><p>ISO 27001 is very resource hungry on your teams, and when you are trying to focus on growth, ISO can seem like a distraction. But it is not. It is an essential part of our DNA and creates opportunities for growth in your people, your culture, and your customer footprint.<b><br \/>\n<\/b><b><\/b><\/p><\/blockquote>\n<p><b>\u2013 Darren Whitaker-Barnett,<\/b> CEO<\/p>\n<h2>Is ISO-27001 certification worth the time, energy and cost?<\/h2>\n<p>For us, becoming ISO 27001-certified was absolutely worth it. Even despite the fact that we had contracts that were contingent upon our eventual certification, this was a sound business decision for so many reasons.<\/p>\n<blockquote><p>This process has been great for building customer confidence. And it lowers the barriers to sale when we are interacting with potential customers. For many of them, it\u2019s a must. And for the others, it\u2019s a huge bonus.<\/p><\/blockquote>\n<p><b>\u2013 Andrew Thompson,<\/b> Chief Security Officer<\/p>\n<p><b>Business benefits for us include\u2026<\/b><\/p>\n<ul>\n<li>Having a solid foundation to pursue other security certifications or attestations, such as SOC 2<\/li>\n<li>Establishing a strong security culture throughout our organisation<\/li>\n<li>Living and breathing our vision to become the most trusted people presence management system in the market<\/li>\n<li>Further establishing our brand as the top choice for enterprise-level organisations<\/li>\n<li>Potential cost savings in the long run that come from having a sound information security management system<\/li>\n<\/ul>\n<blockquote><p>Being ISO 27001-certified allows us to speak confidently about our security practices because we know we\u2019re following international best practice. That\u2019s the best value you can possibly offer from a security perspective.<\/p><\/blockquote>\n<p><b>\u2013 Tom Peck,<\/b> Chief Technology Officer<\/p>\n<h2>What is the ISO-27001 certification process like?<\/h2>\n<p>We engaged Axenic, a security consultancy agency, to assess our current state of security, conduct internal audits and assist us on the path to certification (getting us ready for external audit and assessment \u2013 which was ultimately conducted by a third party auditor from\u00a0<a href=\"https:\/\/www.bsigroup.com\/en-NZ\/\">BSI)<\/a>.<\/p>\n<blockquote><p>It was the right decision to engage a security and compliance consultant. We couldn\u2019t have done this without Lisa [from Axenic].<\/p><\/blockquote>\n<p><b>\u2013 Tom Peck,<\/b> Chief Technology Officer<\/p>\n<p>Firstly,\u00a0<a href=\"https:\/\/www.axenic.co.nz\/\">Axenic\u00a0<\/a>conducted a gap analysis using the Framework in conjunction with Annex A of ISO\/IEC 27001 to create a Current Profile. As we mentioned earlier, we decided to implement everything in Annex A \u2013 even things that were not risks to our business\/security processes \u2013 this was a business decision to follow best practice.<\/p>\n<p>After this, we conducted a risk assessment. This report identified which controls were there and did not need improvement, which controls were already there but did need improvement, and which controls needed to be implemented from scratch. These are \u201crisks\u201d and are categorised as either low, moderate or critical.<\/p>\n<p>Originally, we identified 35 risks. We achieved certification with only 7 areas of concern (though none enough to be a nonconformity).<\/p>\n<blockquote><p>The process was not complicated, but we certainly had no idea how extensive or time-consuming it would be.<b><br \/>\n<\/b><b><\/b><\/p><\/blockquote>\n<p><b>\u2013 Andrew Thompson,<\/b> Chief Security Officer<\/p>\n<h2>What kind of ongoing maintenance does it require to keep ISO-27001 certification?<\/h2>\n<p>ISO-27001 requires consistent management and maintenance. We\u2019ve seen it said that ISO is a lifestyle, and that\u2019s definitely true!<\/p>\n<p><b>Retention of ISO 27001 certification includes\u2026<\/b><\/p>\n<ul>\n<li>An annual surveillance audit makes sure you\u2019re on track to managing all outstanding areas of concern<\/li>\n<li>A 3-yearly major re-audit will determine your eligibility to retain certification<\/li>\n<li>There will be other reports and documentation that requires even more regular review, bi-monthly etc.<\/li>\n<\/ul>\n<h2>Should you get ISO-27001 certified?<i>\u00a0<\/i><\/h2>\n<p><b>Consider ISO-27001\u2026<\/b><\/p>\n<ul>\n<li>If you want to serve customers in countries like Japan and India, it\u2019s a legal requirement.<\/li>\n<li>If your customer base includes international organisations, ISO-27001 is more widely applicable globally than SOC 2.<\/li>\n<li>If your customers include large enterprises, it is good practice, and it removes a barrier when trying to get new customers over the line.<\/li>\n<\/ul>\n<p><b>However\u2026<\/b><\/p>\n<ul>\n<li>If you\u2019re a small company (say, smaller than 20 people), consider that there are many roles that are required of staff over and above BAU, so a small team may not feasibly be able to complete or maintain ISO-27001.<\/li>\n<li>If you only service small businesses (who generally are less discerning than larger organisations) ISO-27001 certification is possibly not necessary.<\/li>\n<\/ul>\n<blockquote><p>ISO certification has created a \u2018security first\u2019 mentality in our office culture; this is an absolute must-have when dealing with customer information.<\/p><\/blockquote>\n<p><b>\u2013 Darren Whitaker-Barnett,<\/b> CEO<\/p>\n<h2>Our advice to any organisation going through the certification process:<\/h2>\n<p>Make sure you\u2019ve got the resources to get through it because it\u2019s not something you can go into half-heartedly. For example, sometimes it will make sense to bring in external experts.<\/p>\n<p>Make sure you\u2019ve brought everyone in the company along on the journey. This requires a big culture shift, so make sure everyone understands why this is important and what the process is like.<\/p>\n<p>Make sure you have enough people to fill the roles required by the standard. We have a relatively small leadership team so with all the roles necessary it might not have been possible to do it if the team were any smaller.<\/p>\n<p>You need someone to really own and drive this process internally. For us, this was our CEO \u2013 he was committed to this and really gave it everything. It had his full attention over and above everything else.<\/p>\n<h3><strong><i>Disclaimer:<\/i><\/strong><\/h3>\n<p>We are not security or compliance consultancy. Everything outlined in this article is purely our own experience or opinion. Every organisation considering ISO-27001 should undertake their own research and gain professional advice before making a decision.<\/p>\n<h2>About MRI OnLocation<\/h2>\n<p>MRI OnLocation provides people presence management software that monitors the safe and secure movement of people through buildings and work sites. Our powerful, cloud-based solution unites visitor, contractor, employee, and emergency management, enabling organisations to secure their facilities and ensure the safety of every person on-site. Armed with a rich, unified source of people presence information, our users are empowered to make more strategic, data-driven decisions that mitigate risk, reduce overhead costs, and streamline operations. Compliant with ISO:27001 2013 for Information Security Management. MRI OnLocation serves organisations in 42 countries around the world and manages over 60 million secure movements through thousands of locations each year. For more information, visit <a href=\"\/products\/onlocation\/\">MRI OnLocation.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Are you a cloud-based service looking into getting ISO-27001 certification? Are you wondering about the process, the benefits, and whether it\u2019s worth it?<br \/>\nThere are a lot of articles about ISO-27001 written by security and compliance consultancy firms&hellip;<\/p>\n","protected":false},"author":37,"featured_media":38070,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9405],"tags":[],"class_list":["post-38596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-onlocation"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/posts\/38596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/comments?post=38596"}],"version-history":[{"count":0,"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/posts\/38596\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/media\/38070"}],"wp:attachment":[{"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/media?parent=38596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/categories?post=38596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mrisoftware.com\/sg\/wp-json\/wp\/v2\/tags?post=38596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}