Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

61–70 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#61
If you are doing business internationally, you are more likely to be asked about this. SOC2 is not all that requested internationally. For some deals with mature European customers, ISO 27001 is a hard requirement. For B2B US, SOC2 is most often requested.

Most organizations take a calendar year or more to get their ISO 27001 certification. One difference between that and a SOC2 is that you need to show that you are running it continuously. At the end of the first year, you get to have another audit. And you really need to show improvement over that year. And the following year. In the fourth year, you start over again with a full audit. Keep in mind that ISO 27001 will require staffing involvement.

Some deals can work if you show convincingly that you are on the road to getting it.

And no, having both won't make the questionnaires go away (contrary to my hope of obtaining it). They may be slightly reduced, but if you have a lot of large customers, you will find quite often hundreds of questions that don't exactly overlap with the last one you filled out. This make it hard to scale the questionnaire effort. There can be some luck if you prepare a standard one, like starting with the CIS controls.

We decided to get it done before it was a hard requirement, as we wanted to show a better security posture, and pursue international (not just EU) business.

One thought I share with teams building security practice is to obtain a copy of the ISO 27001/27002 standards and read through it. It may give you some ideas of how to measure your own security program. One thing that I like about that standard is documenting the executive commitment to funding and staffing the security effort. If you can wrangle that, you are ahead of the game.

The new (2017) SOC2 standard has new language that goes a bit in that direction, with controls like executive commitment to ethics, and division of responsibilities between the board and management.

With respect to security, in your own enlightened company self interest, don't let the idea of SOC2 or ISO 27001 lead you to think that you have security solved. Didn't SolarWinds have a SOC2? (Don't get me started on Third Party Risk Management.)

Re: Ask HN: Is the ISO 27001 certification worth it?

#62
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

We had one that was over 500 questions.

And this is certainly the truth:

> And no, you can't give this to an intern, or just search-and-answer most questions,

Ah, but the answer for major suppliers such as AWS and Azure, etc, is their own ISO 27001, SOC2, etc, certifications that you can defer that risk to.

Re: Ask HN: Is the ISO 27001 certification worth it?

#63
post #59

(I work at/cofounded Vanta) We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must. From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of…

How can one reach you at Vanta?

christina@vanta.com

Re: Ask HN: Is the ISO 27001 certification worth it?

#64

Earlier quoted context omitted.

There's a very recently announced ( https://security.googleblog.com/2021/10/launching-collaborat... ) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.

I note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18". That looks larger than all the other requirements.

I think the intent here is to note that there may be business requirements about these that affect the security of your business.

For example, if anyone pays you through credit cards, PCI DSS is non-optional. Certain transactions of health information will require Hitrust. Without them, you won't be able to do business, and while they seem large (PCI DSS if you have another company handle the cards, is a very simple self-assessment.)

Re: Ask HN: Is the ISO 27001 certification worth it?

#65
post #24

Earlier quoted context omitted.

My experience doing this for several large companies at a time is that the questionnaires don't really go away with certification. There are probably some shops where audit reports will substitute for the Excel spreadsheet Q&A's, but there are plenty of others where the Q&A is a dealbreaker part of procurements no matter what. If you're in a line of business where your customers have questionnaires, just plan on havi…

We got a SOC2... and still get questionnaires. It's the worst. Companies are just outsourcing their security reviews to the vendor. Rather than rely on a 3rd party audited document companies want their custom questions answered. BUT - they aren't custom questions - it's the same questions for every vendor and they are very often poorly worded. Then when we turn them in - there's no follow up questions which to me imp…

I would argue it is "Compliance Theater."

Re: Ask HN: Is the ISO 27001 certification worth it?

#66
post #30

Earlier quoted context omitted.

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

AWS is ISO and SOC certified so they get audited on physical security. I can m trust that they dis it right because they passed their audit. I don't have time to go bother AWS about their security cameras and key card procedures.

And no auditor is going to ding you for noting that you have deferred the risk to them.

Re: Ask HN: Is the ISO 27001 certification worth it?

#67

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

> It's theatre, so it won't help actual security.

I would disagree, as we had a very good security program and when we went through ISO 27001, I would have to say that it ended up measurably better.

But if you don't have a security culture, then it will be theater. Dangerously so.

Re: Ask HN: Is the ISO 27001 certification worth it?

#68
post #13
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

It's probably easier to start w/ a SOC2 TypeII though. Once you get that down, you're at least 50% done with the 27001.

I wouldn't agree with that. It seemed like it was more like 20% of 27001.

Re: Ask HN: Is the ISO 27001 certification worth it?

#69
post #3

I worked for a telecomms/webcasting company for about 5 years as a product manager. I can tell you from personal experience that a significant portion of the Fortune 500 (if not all of them) required ISO 2700X certification to even be considered. The certification burden increases in proportion to the level of PII you are storing. The burden was much higher for government or med/bio contracts (FedRAMP/HIPPA, etc.). I…

PII is not as toxic as many types of data that I have dealt with. Consider legal discovery processes involving many terabytes of documents. These contain e.g., ingestion of laptop, mail folders, document repositories that themselves contain all the kinds of toxic material that you have ever heard of.

Re: Ask HN: Is the ISO 27001 certification worth it?

#70
post #27

It's better to start early than anything, a lot of these certs are easier to get when you have nothing to audit. I've worked for 2 successful B2B fintechs, I wouldn't wait until a customer asks, I would be proactive if you have the time and money to go through it.

I think this is basically the opposite of the correct answer. If you do certification too early, you'll be pulled into pointless engineering projects that will likely have a TCO far larger than the certification itself. If you wait to do SOC2 until after you have a security team, you can avoid a lot of this work. It doesn't help that SOC2 auditors are basically wrong about a lot of stuff, so that if you're getting ce…

I disagree.

soc2 forced us to yubikeys everywhere; getting serious about knowing, auditing, and controlling access; etc. There def were useless bits (contingency plans? If an earthquake hits sfo bad we're screwed, you're screwed, etc)). But on the whole, I think it made us a more secure company.

Lots of it is basically best practices. Have, test, and document db backups. Have, test, and document a network diagram. Audit employee offboarding. Don't let all employees trivially touch prod. Put admin tools behind a vpn. Automate approvals and deploys (we did it all with aws tooling) so that you can audit deploy -> git sha -> [PR approval in github, ticket in jira]

Lots of this is probably dependent on your auditor though.

Also, it's a slow lead time to get, and the upper midmarket / lower enterprise demand it.

edit: bluntly, it also gave me some justification to slide things through when junior eng complained they couldn't touch the prod db.

Post reply on HN