Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

11–20 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#11
I'm in Information Security at a large enterprise. We look for this kind certification, but it isn't required. Not having it though will lead to further scrutiny (lots more questions to answer). I would recommend getting it if you can, particularly if you are offering a service that is hosting the customer's data and/or is managing some part of their IT operations.

Bolstering the recommendation is the fact that the proliferation of supply chain attacks recently is adding pressure for companies to perform more thorough diligence on their vendors. The certification helps check all the boxes.

Re: Ask HN: Is the ISO 27001 certification worth it?

#12
> When did you decide that it's time to get it done?

There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybersecurity about your answers.

Once you're in the loop with a number of large deals, this becomes a huge time sink.

And no, you can't give this to an intern, or just search-and-answer most questions, because every company formulates their questions and requirements differently and it takes some knowledge to figure out what they mean and want.

And at times the discussions afterwards are even worse. I've had InfoSec-guys tell me they're concerned because I cannot give them the specific details on the physical security of an AWS datacenter because these are not available.

As much work as getting and maintaining an ISO27001 certification is, there is a point after which it'll save you time and nerves.

Re: Ask HN: Is the ISO 27001 certification worth it?

#13
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

It's probably easier to start w/ a SOC2 TypeII though. Once you get that down, you're at least 50% done with the 27001.

Re: Ask HN: Is the ISO 27001 certification worth it?

#14

If you are a b2b company your customers will start to ask you at a certain point. Not having it can break a deal for sure although having it won't make the deal. My advice to you is gradually improve your infosec posture and policies etc but rather than kicking off the certification, wait until a customer asks you for it during vendor due dilligence, then say "we're working towards it" and immediately after the meeti…

This has been the best answer in my opinion, the cost of achieving the certification is only worth it if you have prospect customers demanding for it (so that their business will "pay" for the cost).

Oftentimes, companies from the USA will prefer SOC2 Type2 instead of ISO. So in my experience it is best to check with the market.

Regarding B2C companies, in my experience you'd like to get an ISO certification to reduce pressure from some governing body. For example, I was in a company were we did ISO-37001 because in our country that is a HUGE risk, and our market was attracting a lot of attention from government and regulators. Having an ISO gave us a "checkmark" in their eyes.

Re: Ask HN: Is the ISO 27001 certification worth it?

#15

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

We are in the 'lucky' position that ISO 27001 is now simply a legal requirement because we offer a healthcare SaaS-product in the Netherlands (ISO 27001 is required via its Dutch NEN 7510/12/13 bastard child that is).

For a small company (less than twenty employees) it really is a lot of work. It brings some benefits in that it forces you to have your documentation and certain processes in order, but man… getting audited drains you. It depends a lot on the auditor you get, but from all the stuff I do for my job, this yearly event feels like the biggest waste of time. It's just that without it we would be out of business.

Re: Ask HN: Is the ISO 27001 certification worth it?

#16

It's a line-item in many of your clients' checklists. If they don't tick it off then you will have to answer a bunch of questions. It's a one time pain to get out of the way. You could also start the process and ask your certifying consultant to give you a certificate saying it's in progress which is also good in many cases but follow through to complete it.

> It's a one time pain to get out of the way.

It's also a yearly audit and a continuous process to maintain it though.

Re: Ask HN: Is the ISO 27001 certification worth it?

#17
We do B2B sales, we don't have an ISO certificate, and to my knowledge it has never cost us a deal (though some companies have asked).

But I'm sure it also depends what you're selling. We mostly sell marketing services and the risk is inherently low (we generally don't have access to any sensitive client data or systems).

Re: Ask HN: Is the ISO 27001 certification worth it?

#18

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

We are in the 'lucky' position that ISO 27001 is now simply a legal requirement because we offer a healthcare SaaS-product in the Netherlands (ISO 27001 is required via its Dutch NEN 7510/12/13 bastard child that is). For a small company (less than twenty employees) it really is a lot of work. It brings some benefits in that it forces you to have your documentation and certain processes in order, but man… getting aud…

Same story here. Health tech in the UK. It's a pretty arduous process, but given our engineering team was already hot on security (and probably haven't been unlucky with auditors) we haven't had problems in practice.

Re: Ask HN: Is the ISO 27001 certification worth it?

#19
ISO 27001 and SOC2 are both very valuable ways to communicate your security posture to external partners and customers. Like others have mentioned this will allow you to close deals quicker and prevent a more costly outcome by navigating security reviews more quickly. Source of info: friends at https://pentestiq.com and https://vanta.com that handle security/compliance for many startups.

Re: Ask HN: Is the ISO 27001 certification worth it?

#20
First of all management systems and ISO is a way of working, a method or a framework. Just like scrum and agile are methods for project management within a team, management systems within the context of ISO is a method or framework set up by the management to lead the company. If you don't believe in ISO as a method, then you should not do it. Simple as that.

Personally however I think that ISO and management systems solves a lot of the problems that most companies deals with, and it gives a structured way of setting goals and reaching them.

Secondly the certification is not the most important part. The certification proves that your management system works and that you are reaching your goals, but if your goals are shit then the certification rather proves that you are a shity company. In other words the certification in itself is not a quality badge.

Post reply on HN