Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

1–10 of 104 posts

Ask HN: Is the ISO 27001 certification worth it?

#1
ISO 27001 (https://en.wikipedia.org/wiki/ISO/IEC_27001) certifies that information security is properly managed at a company or organisation. But the process of obtaining it is costly and time-consuming so I wanted to ask people who have experience with it: is it worth it?

If you're a company doing B2B sales, how often do prospective customers ask about the certificate? Does it ever make or break a deal? When did you decide that it's time to get it done?

Thanks!

Re: Ask HN: Is the ISO 27001 certification worth it?

#2
You will know when you need it. Half of the companies I’ve worked for required an ISO 2700x audit in order to do business with larger b2b customers. It was part of the customer’s due diligence process when selecting vendors.

It can take a long time to complete an audit, especially that first one. You’re going to need to show a lengthy paper trail of policies and documented compliance.

I think it can bring good discipline to an organization when embraced, but that is often not how it gets done. And in some organizations the discipline is stifling. You’ll want to pay attention to how it is impacting teams.

A previous company I worked for used Process Street for procedure completion and tracking, but I always wondered if all auditors would be OK with such a flexible system.

Re: Ask HN: Is the ISO 27001 certification worth it?

#3
I worked for a telecomms/webcasting company for about 5 years as a product manager. I can tell you from personal experience that a significant portion of the Fortune 500 (if not all of them) required ISO 2700X certification to even be considered.

The certification burden increases in proportion to the level of PII you are storing. The burden was much higher for government or med/bio contracts (FedRAMP/HIPPA, etc.). It's also worth it to mention that we had whole teams dedicated to working through RFPs/RFCs as they can get VERY time consuming.

Bottom line is that if you are going to work with the big fish, you will probably need this level of certification to show them you are serious.

Re: Ask HN: Is the ISO 27001 certification worth it?

#4
If you are a b2b company your customers will start to ask you at a certain point. Not having it can break a deal for sure although having it won't make the deal.

My advice to you is gradually improve your infosec posture and policies etc but rather than kicking off the certification, wait until a customer asks you for it during vendor due dilligence, then say "we're working towards it" and immediately after the meeting commission one of the outside firms who do the evaluation for you.

The evaluation process takes a while and in my experience customers are understanding about that especially given b2b sales aren't exactly quick normally.

Re: Ask HN: Is the ISO 27001 certification worth it?

#5
It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers.

A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it.

Your real problem as a small vendor is deciding when this is necessary, because you might be getting customers just fine when you're small and dealing with people who care about actual security, not paper security. At some point you are gonna have to pull a few people out to get all this paperwork done. I spent last summer doing a whole pile of "Information Security" policies for a friend I was helping. Luckily there are consultants who can get you most of the way there.

Re: Ask HN: Is the ISO 27001 certification worth it?

#6
It's a line-item in many of your clients' checklists. If they don't tick it off then you will have to answer a bunch of questions. It's a one time pain to get out of the way.

You could also start the process and ask your certifying consultant to give you a certificate saying it's in progress which is also good in many cases but follow through to complete it.

Re: Ask HN: Is the ISO 27001 certification worth it?

#7
For some companies it is enough to say "The data center is ISO certified". Which I always found strange, because almost every data center is ISO certified. But you will notice over time how relevant that will be for your customers. Simply ask with every lost offer what the reason was. Then you can still take care of your own certification.
Post reply on HN