Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

71–80 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#71
post #40
post #25

Earlier quoted context omitted.

Why a Type 2? The documentation you'll generate for the Type 1 covers just as much questionnaire terrain as the Type 2 does.

Because most CISOs / security reviews we go through ask for it.

But that's not the reason you gave for getting the Type 2!

My experience has been that companies regularly close deals by committing to get a Type 1, for what it's worth.

Re: Ask HN: Is the ISO 27001 certification worth it?

#72
post #70
post #27

Earlier quoted context omitted.

I think this is basically the opposite of the correct answer. If you do certification too early, you'll be pulled into pointless engineering projects that will likely have a TCO far larger than the certification itself. If you wait to do SOC2 until after you have a security team, you can avoid a lot of this work. It doesn't help that SOC2 auditors are basically wrong about a lot of stuff, so that if you're getting ce…

I disagree. soc2 forced us to yubikeys everywhere; getting serious about knowing, auditing, and controlling access; etc. There def were useless bits (contingency plans? If an earthquake hits sfo bad we're screwed, you're screwed, etc)). But on the whole, I think it made us a more secure company. Lots of it is basically best practices. Have, test, and document db backups. Have, test, and document a network diagram. Au…

SOC2 did not force you to use Yubikeys everywhere. How I know that is: no mid-sized organization I've seen SOC2 has ever gotten everyone onto Yubikeys. The median SOC2 auditor hasn't the slightest clue what a Yubikey is (the median SOC2 auditor probably doesn't know the difference between a URL and a hostname).

I understand what you're trying to say: the threat of a SOC2 information gathering process scared your engineering team into taking 2FA seriously. Your team was able to use it as a forcing function. Not to put too fine a point on it: your team is dysfunctional and has a poorly-communicating and unpersuasive security practice.†

That's the problem you needed to fix. There will be things you very seriously need to get rolled out after Yubikeys, and you won't have another $70,000 Big5 audit to wave around to get it done. Meanwhile: people who don't want to endure that audit can get Yubikeys deployed without bothering with the SOC2 part.

An important thing not enough people understand about SOC2 is that the profile of controls that you use (where controls are things like "logs we monitor" and "onboarding processes" and "2FA mechanisms") are self-determined. Auditors have a set of very high-level goals --- much higher level than "services need 2FA SSO --- and you get to pick what controls you map to them. You get to pick what SOC2 makes you deploy, and the auditors ostensibly just keep you honest.

I would be surprised if anything close to 50% of reliably SOC2 -Type-2'd shops had any hardware 2FA at all.

Almost everyone does!

Re: Ask HN: Is the ISO 27001 certification worth it?

#73
post #23

First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them. You should be able to weigh the costs of certification against hard, certain revenue. Depending on your customer base, you may get pushed into certification soon, or you might be able to push it off surprisingly far. If you can do that, you should. Second: in North America, SOC2 is much more c…

> First: the rule with these kinds of certifications is simple: don't do them until you have customer deals contingent on them. Getting an ISO 27001 certification can take months of effort, and not all deals can be stretched this far without significant repercussions. Just a data point, I lead the certification project at my current company and it took us 8 months (~65 people in total, of which 3 full-time in IT): th…

Right. The short answer to the question this post asks is: "if you're a North America startup, do not get ISO 27001, and be wary of any advisor that says you should do so without a 7 figure purchase order closed and contingent on it."

SOC2 is a little bit trickier, but not much trickier: the strategy is the same: wait until you have to, and then get it to close the deal.

Re: Ask HN: Is the ISO 27001 certification worth it?

#74
post #32

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

> It's theatre, so it won't help actual security. I disagree with this sentiment. As a small firm who has undergone multiple security audits/certifications, I have found that the controls we added were generally practical and did improve our security.

I've seen the exact opposite thing happen: organizations that went into security engineering deficit because of stupid things they were led by an unguided audit process to believe they needed to do. Compliance is a byproduct of security, not the other way around. Never go into a compliance process without an already-clear idea of what your security practice goals are.

Re: Ask HN: Is the ISO 27001 certification worth it?

#75
There's a lot of advice in this thread saying one shouldn't pursue a certification until you need it. Fine, that makes sense. I'm in the thick of our SOC-2 and it is indeed a pain in the ass.

But that doesn't mean you shouldn't worry about compliance! Almost any B2B company should be acutely aware of what the substance of a SOC-2 (at least) entails and what changes will eventually be required to satisfy it. You can make things much easier or harder on yourself by adopting certain principles and architectural patterns from day 1.

The goal is, when it is time for your SOC-2, it's just an administrative process and a rubber stamp, rather than needing to make major changes to your architecture and business processes.

And hey, you just might end up avoiding a costly security incident along the way.

Re: Ask HN: Is the ISO 27001 certification worth it?

#76

Earlier quoted context omitted.

There's a very recently announced ( https://security.googleblog.com/2021/10/launching-collaborat... ) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.

I note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18". That looks larger than all the other requirements.

IME the human time cost and direct expense associated with obtaining HITRUST, even if you've already done SOC2, is roughly in line with buying a Lamborghini.

Re: Ask HN: Is the ISO 27001 certification worth it?

#77
Architect who works on a bunch of procurement - our approach is that a clean SOC2 Type 2 report is preferable, but not a deal-breaker (and reduces paperwork for me). But if you couldn't demonstrate that you could address the issues that SOC2 (etc) test, that would be a problem.

Re: Ask HN: Is the ISO 27001 certification worth it?

#78
post #72
post #70

Earlier quoted context omitted.

I disagree. soc2 forced us to yubikeys everywhere; getting serious about knowing, auditing, and controlling access; etc. There def were useless bits (contingency plans? If an earthquake hits sfo bad we're screwed, you're screwed, etc)). But on the whole, I think it made us a more secure company. Lots of it is basically best practices. Have, test, and document db backups. Have, test, and document a network diagram. Au…

SOC2 did not force you to use Yubikeys everywhere. How I know that is: no mid-sized organization I've seen SOC2 has ever gotten everyone onto Yubikeys. The median SOC2 auditor hasn't the slightest clue what a Yubikey is (the median SOC2 auditor probably doesn't know the difference between a URL and a hostname). I understand what you're trying to say: the threat of a SOC2 information gathering process scared your engi…

Agreed, SOC2 says nothing about yubikey/u2f/etc. Almost any MFA will do unless one lets opinionated auditors head deep into the weeds.

You can use spreadsheet-based recordkeeping to satisfy very much of SOC2 as long as the processes are followed consistently.

Re: Ask HN: Is the ISO 27001 certification worth it?

#79

(I work at/cofounded Vanta) We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must. From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of…

Check out secureframe.com as well (I like them the most, albeit just getting going)

Also in the space:

- Drata

- Laika

- Tugboat

- Kintent

Re: Ask HN: Is the ISO 27001 certification worth it?

#80

(I work at/cofounded Vanta) We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must. From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of…

My experience is that you only don’t get far with ISO 27001 in the USA but the rest of the world are fine.
Post reply on HN