Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

31–40 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#31
Typically this is your B2B infosec audit evolution:

1. No audits/certifications. Stay here until you're losing deals with big-ish companies to the point where it's worth investing $10-20k and ~200 hours into solving this.

2. SOC 2 Type 1. Takes about $10-20k/yr and 200 hours in my experience. If you use a platform like Drata it'll be a bit more money but less effort. This report satisfies a lot of security teams, and you have to get it once per year. The 2nd/3rd time is way less time investment than first. Stay here until you're losing deals over not having SOC 2 Type 2 / ISO27001.

3. SOC 2 Type 2. Takes about $15-30k/yr. If you've done SOC 2 Type 1 it should only take 80 hours or so to get. Again, platforms like Drata cost more but make this easier.

4. ISO27001. If SOC 2 Type 2 isn't enough for your big enterprise customers to buy, this is the next step. There's a lot of overlap between SOC 2 Type 2 and ISO27001, but ISO27001 definitely introduces some new controls. Drata can help with this as well, but pricing might go up to something more like $50k/yr for SOC 2 Type 2 + ISO27001.

If your company's very first sales will be enterprise deals, you may need to get SOC 2 Type 1/2 from the beginning. If you're starting out with SMB and eventually moving upstream, you could probably wait a few years before getting SOC 2 Type 1/2.

If a customer is asking "do you have ISO27001 certification?", saying "no" to that isn't (necessarily) damning. It might just mean they want you to fill out their security questionnaire. These can be time consuming, so you can even get around this by filling out a VSA Core once (standardized questionnaire) and trying to send them that instead of filling out each customer's custom questionnaire.

Re: Ask HN: Is the ISO 27001 certification worth it?

#32

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

> It's theatre, so it won't help actual security.

I disagree with this sentiment. As a small firm who has undergone multiple security audits/certifications, I have found that the controls we added were generally practical and did improve our security.

Re: Ask HN: Is the ISO 27001 certification worth it?

#34
(I work at/cofounded Vanta)

We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must.

From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of ways to get through that process: ISO cert, SOC 2, the promise to get either of those certs by your go-live/implementation date, security questionnaire hell, etc.

As mentioned previously, ISO is preferred by European companies; SOC 2 is more likely to be mandated by American companies, and you’re likely to get pretty far, even in Europe, on just a SOC 2. If I had to construct the situation that’s most likely to be deal-breaking, it’d be an old-school European company that’s operating off a rigid flow chart: “if no ISO 27001 cert, go back to start. Do not pass Go. Do not collect $200.”

A few folks have mentioned cost (dollar and organizational) — ymmv and/but the cost of obtaining ISO 27001 certification varies with the number of employees, say $10-20k for smaller companies. Implementing ISO 27001 and an ISMS can be blitzed by small teams in a few weeks but probably will take a couple of months to a year for larger organizations.

(And we’d love to help if you decide to pursue this at Vanta etc etc)

Re: Ask HN: Is the ISO 27001 certification worth it?

#35
post #25
post #13

Earlier quoted context omitted.

It's probably easier to start w/ a SOC2 TypeII though. Once you get that down, you're at least 50% done with the 27001.

Why a Type 2? The documentation you'll generate for the Type 1 covers just as much questionnaire terrain as the Type 2 does.

Type 1 is a point in time, and it expires. Type 2 maintains it.

Re: Ask HN: Is the ISO 27001 certification worth it?

#36
post #30
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

AWS is ISO and SOC certified so they get audited on physical security. I can m trust that they dis it right because they passed their audit. I don't have time to go bother AWS about their security cameras and key card procedures.

Re: Ask HN: Is the ISO 27001 certification worth it?

#37
post #30
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

Certification allows you to form a chain of trust via providers who have had auditors validate and verify their security. When my company gets SOC2 audited, we don't have to audit AWS because AWS is also SOC2 compliant, and their business critical vendors are likewise or have been independently validated, etc. all the way down the chain.

Re: Ask HN: Is the ISO 27001 certification worth it?

#38
post #23

First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them. You should be able to weigh the costs of certification against hard, certain revenue. Depending on your customer base, you may get pushed into certification soon, or you might be able to push it off surprisingly far. If you can do that, you should. Second: in North America, SOC2 is much more c…

> First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them.

Getting an ISO 27001 certification can take months of effort, and not all deals can be stretched this far without significant repercussions.

Just a data point, I lead the certification project at my current company and it took us 8 months (~65 people in total, of which 3 full-time in IT): the auditors were a little hesitant at first because the system wasn't "battle-tested" as much as they'd liked.

Re: Ask HN: Is the ISO 27001 certification worth it?

#39
post #30
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

AWS has ISO27001 certification and more. The whole point of these certifications is that it proves a competent auditor came in and checked all of these things, so your customers don’t have too.

Part of ISO27001 is proving that you’re supply chain is also ISO27001 compliant. So picking companies that are already certified makes that easy, because then the certification naturally recurses down your supply chain.

Re: Ask HN: Is the ISO 27001 certification worth it?

#40
post #25
post #13

Earlier quoted context omitted.

It's probably easier to start w/ a SOC2 TypeII though. Once you get that down, you're at least 50% done with the 27001.

Why a Type 2? The documentation you'll generate for the Type 1 covers just as much questionnaire terrain as the Type 2 does.

Because most CISOs / security reviews we go through ask for it.
Post reply on HN