Ask HN: Is the ISO 27001 certification worth it?
21–30 of 104 posts
Re: Ask HN: Is the ISO 27001 certification worth it?
#22> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
Each potential client has a unique generally quite substantial list of security/tech questions in several spreadsheets. You answer each one as well as possible, and give details. This is definitely not an intern gig: at my fintech startup we had the CEO or Dir Eng or myself (DevOps) do it. Generally all of us took turns. They're pretty onerous.
Having done the work for the ISO-27001 helped. For that cert we'd already had to think about and document a ton of security related things. Potential clients were happy to take our internal docs (written for ISO) as details to their questions. If they actually read our docs or if it was just a checkbox requirement, that's a good question :)
Re: Ask HN: Is the ISO 27001 certification worth it?
#23Second: in North America, SOC2 is much more common than ISO 27001. 27001 is more common with gigantic companies than with startups. By way of example: Datadog just announced its 27001 last year, a few months after they went public. That they were able to scale their business to that point without 27001 certification --- and look closely at what Datadog's business is, and who their customers are! --- should tell you something about which certification you're likely to want first.
So for the rest of this comment I'm going to assume your company has no certification, and that you can get away with SOC2.
Third: while you will run into NA customers that want SOC2, there's a loose norm of purchases contingent on achieving a Type 1. That is to say: you can probably plan on deferring SOC2 until you have a contingent P.O. in hand, and do it then without losing that deal. You know your customers better than I do, but I spent a bunch of years doing this work for startups and don't think I ever told anyone to SOC2 preemptively.
Fourth: a real risk with rushing certification is that it can warp your security engineering and business processes. SOC2 is particularly amorphous, and SOC2 auditors are a weird bunch (people with strong opinions about which security tools you should be running that don't know the difference between an IP address and a domain name are people whose influence on your IT and engineering you should limit). You want a security team in place before you start chugging away at SOC2, so that your security team can be the primary influence on what engineering you do to support SOC2 (a competent security team will win any shootout with any major-label auditor).
Fifth: For most companies, you'll be 25-35 engineers before you contemplate a full-time security person, which gives you an idea of the normal lifecycle point at which you might start seriously consider certifying.
I wrote a blog post for my last company about some things to know about SOC2 and early-stage companies:
https://latacora.micro.blog/2020/03/12/the-soc-starting.html
Re: Ask HN: Is the ISO 27001 certification worth it?
#24> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
If you're in a line of business where your customers have questionnaires, just plan on having someone whose job is to fill these things out.
Re: Ask HN: Is the ISO 27001 certification worth it?
#25> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
It's probably easier to start w/ a SOC2 TypeII though. Once you get that down, you're at least 50% done with the 27001.
Re: Ask HN: Is the ISO 27001 certification worth it?
#26ISO 27001 and SOC2 are both very valuable ways to communicate your security posture to external partners and customers. Like others have mentioned this will allow you to close deals quicker and prevent a more costly outcome by navigating security reviews more quickly. Source of info: friends at https://pentestiq.com and https://vanta.com that handle security/compliance for many startups.
Re: Ask HN: Is the ISO 27001 certification worth it?
#27It's better to start early than anything, a lot of these certs are easier to get when you have nothing to audit. I've worked for 2 successful B2B fintechs, I wouldn't wait until a customer asks, I would be proactive if you have the time and money to go through it.
It doesn't help that SOC2 auditors are basically wrong about a lot of stuff, so that if you're getting certified before you have a sane security practice in place, your security engineering will get dragged into weird, unproductive places.
Re: Ask HN: Is the ISO 27001 certification worth it?
#28Re: Ask HN: Is the ISO 27001 certification worth it?
#29> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
However, having passed the certification process still save time.
Re: Ask HN: Is the ISO 27001 certification worth it?
#30> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…
So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?