Bolstering the recommendation is the fact that the proliferation of supply chain attacks recently is adding pressure for companies to perform more thorough diligence on their vendors. The certification helps check all the boxes.
Ask HN: Is the ISO 27001 certification worth it?
11–20 of 104 posts
Re: Ask HN: Is the ISO 27001 certification worth it?
#12There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybersecurity about your answers.
Once you're in the loop with a number of large deals, this becomes a huge time sink.
And no, you can't give this to an intern, or just search-and-answer most questions, because every company formulates their questions and requirements differently and it takes some knowledge to figure out what they mean and want.
And at times the discussions afterwards are even worse. I've had InfoSec-guys tell me they're concerned because I cannot give them the specific details on the physical security of an AWS datacenter because these are not available.
As much work as getting and maintaining an ISO27001 certification is, there is a point after which it'll save you time and nerves.
Re: Ask HN: Is the ISO 27001 certification worth it?
#13> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
Re: Ask HN: Is the ISO 27001 certification worth it?
#14If you are a b2b company your customers will start to ask you at a certain point. Not having it can break a deal for sure although having it won't make the deal. My advice to you is gradually improve your infosec posture and policies etc but rather than kicking off the certification, wait until a customer asks you for it during vendor due dilligence, then say "we're working towards it" and immediately after the meeti…
Oftentimes, companies from the USA will prefer SOC2 Type2 instead of ISO. So in my experience it is best to check with the market.
Regarding B2C companies, in my experience you'd like to get an ISO certification to reduce pressure from some governing body. For example, I was in a company were we did ISO-37001 because in our country that is a HUGE risk, and our market was attracting a lot of attention from government and regulators. Having an ISO gave us a "checkmark" in their eyes.
Re: Ask HN: Is the ISO 27001 certification worth it?
#15It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…
For a small company (less than twenty employees) it really is a lot of work. It brings some benefits in that it forces you to have your documentation and certain processes in order, but man… getting audited drains you. It depends a lot on the auditor you get, but from all the stuff I do for my job, this yearly event feels like the biggest waste of time. It's just that without it we would be out of business.
Re: Ask HN: Is the ISO 27001 certification worth it?
#16It's a line-item in many of your clients' checklists. If they don't tick it off then you will have to answer a bunch of questions. It's a one time pain to get out of the way. You could also start the process and ask your certifying consultant to give you a certificate saying it's in progress which is also good in many cases but follow through to complete it.
It's also a yearly audit and a continuous process to maintain it though.
Re: Ask HN: Is the ISO 27001 certification worth it?
#17But I'm sure it also depends what you're selling. We mostly sell marketing services and the risk is inherently low (we generally don't have access to any sensitive client data or systems).
Re: Ask HN: Is the ISO 27001 certification worth it?
#18It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…
We are in the 'lucky' position that ISO 27001 is now simply a legal requirement because we offer a healthcare SaaS-product in the Netherlands (ISO 27001 is required via its Dutch NEN 7510/12/13 bastard child that is). For a small company (less than twenty employees) it really is a lot of work. It brings some benefits in that it forces you to have your documentation and certain processes in order, but man… getting aud…
Re: Ask HN: Is the ISO 27001 certification worth it?
#19Re: Ask HN: Is the ISO 27001 certification worth it?
#20Personally however I think that ISO and management systems solves a lot of the problems that most companies deals with, and it gives a structured way of setting goals and reaching them.
Secondly the certification is not the most important part. The certification proves that your management system works and that you are reaching your goals, but if your goals are shit then the certification rather proves that you are a shity company. In other words the certification in itself is not a quality badge.