Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

41–50 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#41
post #30
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

Do you actually run a soc or iso certified data center? Because 99.9% of companies, even those who don’t use cloud services, use other people’s racks, cages, power, network etc for certified systems.

I do t think I know a single serious security professional that would raise an eye at using cloud resources. Quite the opposite, there is a fairly straightforward & repeatable process for securing cloud resources. Unlike on prem.

Re: Ask HN: Is the ISO 27001 certification worth it?

#42
Depends on your industry and what your customers expect. Also worth noting that your customers might not be ISO27001 compliant, but expect their suppliers to be compliant.

Many customers will send you a huge questionnaire to understand your security posture, policies and procedures. You’ll quickly realise that these questionnaire are pretty much what an ISO27001 auditor will ask. So if you have ISO27001, then you can just copy and paste.

It’s much easier to become ISO27001 compliant early, before you have much built. It allows you to take cookie cutter policies and procedures from companies like Laika and apply them wholesale with only minor tweaks, and without the need to make technical changes, because there’s nothing to change. However the process is both expensive and time consuming, so make sure it’s something your customers will expect.

Finally, pay someone else to walk you through the process. I’ve used the company heylaika.com, it removes so much overhead and the need to read the standard in detail. Trying to go it alone will just be a huge waste of time and money, you’ll end up paying for expensive audits that you’ll fail. Getting external help in makes sure you’ll actual pass the audit before you pay an auditor.

Re: Ask HN: Is the ISO 27001 certification worth it?

#43
post #30
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

Yeah, exactly, its always possible to fail someone if ANYTHING is outsourced. Keep on digging digging digging. For example Amazon is PCIDSS level 1 and more than willing to provide docs to prove it, so if you need pcidss 1 or less, that "should" be OK. OK fine, keep digging. In more detail you can see AWS brags about having linked their HR system to their security system so when someone is terminated their security access is immediately automatically revokes. OK fine, keep digging. I demand to see the python script or whatever that they wrote and I'd like to examine the system logs on both sides to verify operation of that security system. Ah got them now. OK now I demand to read the source code for the BIOS of the computer that connects those two systems. Can't do it? You're now officially insecure, cancel the deal.

You can shut down deals that aren't outsourced by demanding more difficult stuff like viewing the manufacturing masks for the microcontrollers in the badge scanners. No not a generic mask for the CPU family or similar model of slightly different capacity, I mean the mask that was specifically used to make the specific chips in the individual badge scanners. You do audit that, don't you? Why can't I have the firmware to the chip in your usb keyboard, are you guys hiding something in there like a password grabber? Can you provide the source code of your on premises Cisco routers for our security review? Does Cisco know you can do that (LOL?)

Security is not a checkmark, its always been a spectrum, and if you want to torpedo a deal its always possible to crank up the demands until the other side quits. It may not be useful or provide a business advantage, but nothing is ever truly secure. Probably the AWS stuff is better than average, LOL.

Re: Ask HN: Is the ISO 27001 certification worth it?

#44
The objective of most companies is to make money (let us be honest), thus the objective of the information security team is to make sure that the organization can achieve its objectives.

Thus, a lot of times, to sign customers, you need to be secured, as an IT/Security department can easily shut down any SaaS project if it is not secure enough. Having a certification like ISO 27001 or a report like SOC2 can really be helpful, and is sometimes a necessity. So ask yourself "does our company needs a SOC2/ISO 27001 to sign customers? Is it a blocker for our business?". You never want to achieve compliance "just because", you need a business reason to do it.

We started building our security program (ISMS) based on ISO 27001 (which is a really good basis in my opinion), but decided to get a SOC2 report instead. We started with a SOC2 type I report, then a type II. I personally find that a SOC2 is much more flexible than an ISO 27001 certification.

We mainly deal with big European customers, and SOC2 and ISO 27001 are seen as equal; never had a problem there. Most customers don't even read the report to be honest; it's a check in a box.

Having a SOC2 report or ISO 27001 certification shows that you care about security, and it sets the tone from the start.

Re: Ask HN: Is the ISO 27001 certification worth it?

#46
post #24
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

My experience doing this for several large companies at a time is that the questionnaires don't really go away with certification. There are probably some shops where audit reports will substitute for the Excel spreadsheet Q&A's, but there are plenty of others where the Q&A is a dealbreaker part of procurements no matter what. If you're in a line of business where your customers have questionnaires, just plan on havi…

We have a SOC2 report type II, and security questionnaires/meetings are still there. Once we had a security questionnaire from a potential customer, took a glance at it, told the customer "hey you can find all of the answers in our SOC2 report and in our CAIQ (CSA)", they told us to still fill the questionnaire...

Re: Ask HN: Is the ISO 27001 certification worth it?

#47
I would wonder if there is a heuristic where you don't need a specialized and mature security governance program until you are close to or have established PMF. Security is tech governance, so you need something to govern before you drop in a bunch of security people.

If you have an enterprise product, either you get the ISO cert, or give up some of your sales margin and leverage to be a "partner," to another vendor who does. e.g. If you are selling to a bank and you don't have it, it's likely the bank may ask a consultant from one of the big firms to "recommend," your product as part of an engagement, and the compliance risk nominally shifts onto them, which is super not-cheap. I'd start discussions with VaRs and consulting firms about partnering now in case you get a demand for it, just to be hedged.

However, as a security pro, I would almost never suggest it to a startup until they are much later stage, like B and C rounds, or above say, $20m ARR, and perhaps not even then. The reason for this is if you are still establishing PMF, ISO is an expensive distraction, same with FedRAMP. Pay for it out of profits only, or tack on the expense to a customer contract, as imo, it's a waste of precious runway.

Strategically, I think it's worth considering taking the revenue hit of partnering with a VaR or a big-N consulting firm early to grow your channel first, and who specializes in managing these dead weight regulatory burdens while you focus on building a product that grows fast enough that you can choose solve ISO yourself as an optimization problem later on when you are rolling in cash, and not as a strategic barrier. I'd venture that the lack of an ISO cert is not going to get in the way of an exit or early stage growth. It's an expense that I would punt to whoever acquires you. If you are acquiring companies, then maybe you're big enough to consider it.

Re: Ask HN: Is the ISO 27001 certification worth it?

#48
It’s a racket essentially, they make up a certification sell it to people buying software. Those buyers force it on their suppliers and they can charge for auditing and compliance. Not much you can do though, just have to grit your teeth and get on with it and try and avoid the most bureaucratic parts that slow down you ability to execute.

Re: Ask HN: Is the ISO 27001 certification worth it?

#49
post #23

First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them. You should be able to weigh the costs of certification against hard, certain revenue. Depending on your customer base, you may get pushed into certification soon, or you might be able to push it off surprisingly far. If you can do that, you should. Second: in North America, SOC2 is much more c…

This ^ is my favourite writeup on the question of how you implement SOC2. I wish I had read that before we started - after going through the Type 1 and Type 2 process, we've ended up with the same conclusions. I've lost count of the number of times I've recommended that. Our experience (global b2b customers, heavily skewed to NA) is that SOC2 Type 2 is the most frequently requested/expected standard, and if you have that, not having ISO is very rarely a dealbreaker. Neither makes the security questionnaires go away; they continue to be mandatory, require expert input, and are a significant drain on time. However, having SOC2 and/or ISO does mean that you've already thought of the answers to the questions and you'll have a defensible position, backed up by a track record of independent audits, when your particular approach doesn't meet the "gold" standard implied by the questionnaire. (Edit: typo)

Re: Ask HN: Is the ISO 27001 certification worth it?

#50
post #26

ISO 27001 and SOC2 are both very valuable ways to communicate your security posture to external partners and customers. Like others have mentioned this will allow you to close deals quicker and prevent a more costly outcome by navigating security reviews more quickly. Source of info: friends at https://pentestiq.com and https://vanta.com that handle security/compliance for many startups.

I think for a lot of startups this is mostly not true at all, and that you can get a pretty long way without doing SOC2. I think for most startups there's basically no sales value to 27001 at all, and I would be wary of anyone giving advice suggesting anyone should do a 27001 preemptively, rather than to close a 7 figure pilot or something where the deal will pay for the cert drama.

You are correct, in many ways even SOC2 is not a desirable investment for young companies. You can do 5 figure deals with fortune 500 companies without it but the process of closing that deal will require a lot more work. Maybe a good time to start investing in SOC2 or ISO certification is when you have multiple large deals with enterprises in your sales pipe. Before that, running a small security program (annual pentest, security awareness training) and communicating that via security questionnaires will get you first deals.
Post reply on HN