SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Adoption of ISO 27001

  Quote
Guest
Guest user Created:   Mar 14, 2020 Last commented:   Mar 14, 2020

Adoption of ISO 27001

1. We have been told by a client (a bank) that we need to become ISO27001 accredited as a company to meet their security standards.
But we are only a small organisation and do not have in-house IT people.
Would you recommend we contract an IT consultant for some time and use your framework?

2. How do you work with clients like us? I’m not sure where to start.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 14, 2020

1. We have been told by a client (a bank) that we need to become ISO27001 accredited as a company to meet their security standards.
But we are only a small organisation and do not have in-house IT people.
Would you recommend we contract an IT consultant for some time and use your framework?

First is important to note that:

  • ISO 27001 was designed to be applicable to organizations of any size and industry, so even if you are a small organization ISO 27001 can help you
  •  Information security goes much beyond the IT environment (you have to handle information security risk related to suppliers, employees, physical documents, etc.)

Regarding the implementation approach, there are three major options:
a) using your own personnel
b) hiring a consultant
c) using a DIY approach with external support

All of them have their advantages and disadvantages, considering time, cost, effort, and preservation of knowledge, and you should consider these factors to decide which approach is best for you.

These articles will provide you further explanation about ISO 27001:

These materials will also help you regarding ISO 27001:

2. How do you work with clients like us? I’m not sure where to start?

Our ISO 27001 Toolkit follows the "DIY with external support" approach, and by which you stated about your business, it is the right solution for you. The templates in the toolkit are 90% completed and you only have to include the information about your organization and the specifics about the controls that will be used.

The templates have lots of comments that will help you including your information. And if you are stuck at any moment in the process, you can contact us through e-mail (there is no limit for how many emails you can send), or schedule online meetings with one of our experts.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 14, 2020

Mar 14, 2020

Suggested Topics