Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

81–90 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#81
post #71
post #40

Earlier quoted context omitted.

Because most CISOs / security reviews we go through ask for it.

But that's not the reason you gave for getting the Type 2! My experience has been that companies regularly close deals by committing to get a Type 1, for what it's worth.

This is a YMMV situation I think. In our case, when we only had our Type 1, we did deals _conditional_ on getting Type 2 within a year.

Re: Ask HN: Is the ISO 27001 certification worth it?

#82
post #71
post #40

Earlier quoted context omitted.

Because most CISOs / security reviews we go through ask for it.

But that's not the reason you gave for getting the Type 2! My experience has been that companies regularly close deals by committing to get a Type 1, for what it's worth.

Right, it's multiple benefits: the soc2 has a lot of overlap with 27001, a bunch of overlap with hitrust, it's a bit easier to do, and the CISOs we talk to want the Type 2. Internally, you can bump up your security practices, eg it forced us into a level of internal controls that was early for a startup. But beneficial, imo. I really can't think of many drawbacks if you work with customers that ask for these things.

In our case, the customer profile is from lower midmarket to Fortune 50.

You probably can close deals (depending customer, obviously) by committing to a Type 1. We did that at the beginning, but it exposes you to a lot more interactions with the security team. While you rarely see deals fail for security reasons, I've had it happen. So my experience is the less interaction you have with them, the better off you are. And a Type II plus the annual (or more than annual) pen tests make a lot of the questioning less intense.

btw (happy to disclose personally, but I keep my identity private on hn), you can get the audit done for a lot less than $70k if you use a smaller firm, and that never was a problem with our customers.

Re: Ask HN: Is the ISO 27001 certification worth it?

#83
post #82
post #71

Earlier quoted context omitted.

But that's not the reason you gave for getting the Type 2! My experience has been that companies regularly close deals by committing to get a Type 1, for what it's worth.

Right, it's multiple benefits: the soc2 has a lot of overlap with 27001, a bunch of overlap with hitrust, it's a bit easier to do, and the CISOs we talk to want the Type 2. Internally, you can bump up your security practices, eg it forced us into a level of internal controls that was early for a startup. But beneficial, imo. I really can't think of many drawbacks if you work with customers that ask for these things.…

I've seen deals contingent on named and/or Big 4 auditors, so I'm going to go ahead and disagree there too. With major buyers, I think there's pretty general awareness that there's a race-to-the-bottom market for cheap SOC2 assessments.

Anyways: the point I'm making is: a Type 2 probably doesn't do anything more to prepare you for 27001 (which you should not get) than a Type 1 does. The subject matter of the assessments are the same (in fact, the Type 1 essentially sets the playbook for the Type 2, which is something you should be careful about).

Pentest reports can definitely mitigate security objections. T What's funny is that none of these certifications meaningfully require them. All the more reason not to pay much attention to them until you have to.

You should think of SOC2 and ISO 27001 as exotic sales expenses, not as something your startup needs to engineer against.

Re: Ask HN: Is the ISO 27001 certification worth it?

#84
post #75

There's a lot of advice in this thread saying one shouldn't pursue a certification until you need it. Fine, that makes sense. I'm in the thick of our SOC-2 and it is indeed a pain in the ass. But that doesn't mean you shouldn't worry about compliance! Almost any B2B company should be acutely aware of what the substance of a SOC-2 (at least) entails and what changes will eventually be required to satisfy it. You can m…

SOC2 is an administrative process and rubber stamp whether or not you prepare for it. You should build a security practice to avoid costly security incidents, and let your sales process tell you when it's time to get a SOC2, which itself has zero to do with security.

Re: Ask HN: Is the ISO 27001 certification worth it?

#85

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

There are some portions which are theatrical, but for the most part it is beneficial. I'd say that my company already had a large majority of the important things in place before getting SOC2, the process helped us close some gaps and organize the ongoing maintenance.

Certainly if the organization is not interested in security, they could fake their way through the certification with meaningless compliance and not actually achieve security.

But if your company does take security seriously, the certifications do help you get organized.

Sometimes it is just helpful when enforcing a good procedure across an organization to be able to tell a sales manager that they can't just email passwords around because we are SOC2, instead of trying to convince them from principle. It can elevate it above the level of company policy from which some people feel exempt. Now you can just threaten them that if they cause an exception on next year's SOC2 report it might scare away the big sale.

Re: Ask HN: Is the ISO 27001 certification worth it?

#86
> If you're a company doing B2B sales, how often do prospective customers ask about the certificate?

We're an authorization API company, so we may not be representative, but it definitely comes up, even in the context of early-stage SaaS startups that are selling into larger accounts.

> When did you decide that it's time to get it done?

It's certainly a pain, but somewhat ironically, the smaller / younger your company is, the easier it is to institute some of the processes than if you wait until you're larger.

There are companies out there (hyperproof.io is one of them) that sell SaaS products that help you streamline the workflow for ISO, SOC2, et al.

Re: Ask HN: Is the ISO 27001 certification worth it?

#87
post #27

It's better to start early than anything, a lot of these certs are easier to get when you have nothing to audit. I've worked for 2 successful B2B fintechs, I wouldn't wait until a customer asks, I would be proactive if you have the time and money to go through it.

I think this is basically the opposite of the correct answer. If you do certification too early, you'll be pulled into pointless engineering projects that will likely have a TCO far larger than the certification itself. If you wait to do SOC2 until after you have a security team, you can avoid a lot of this work. It doesn't help that SOC2 auditors are basically wrong about a lot of stuff, so that if you're getting ce…

Starting too early might not be the best move (though parent has a point on better auditability), but doing it at the last minute or once the product is plenty mature also means a ton of needless changes that can be disrupting depending on how the product was built/managed.

Perhaps it would make sense to at least know and understand the certifications as early as possible, and grow with it in mind. It makes it a lot easier to get certified when times come, or even to explain clients why it wouldn't be required in some cases ("we can already guarantee you this and that, if that's the part you're worrying about")

Re: Ask HN: Is the ISO 27001 certification worth it?

#88
Hi, I'm one of the founders of Secureframe.com.

At Secureframe we help customers streamline their SOC 2, ISO 27001, HIPAA, and PCI compliance. And much more! If you are selling to customers in Europe or Asia, ISO 27001 is quite commonly requested. In the US, SOC 2 tends to be more common.

When it comes to the process, an ISO 27001 certification has two stages and includes an annual renewal.

- Stage 1: Evaluates the right documentation and controls in place in order to progress to Stage 2. - Stage 2: Evaluates the evidence to prove your controls and ISMS are effective, and that they meet the ISO 27001 requirements. Passing Stage 2 results in an ISO 27001 certification.

Stage 1 can be completed pretty quickly, but Stage 2 can take a bit more time to evaluate the evidence for. It can be done in a few weeks with a tool like Secureframe. It can cost Secureframe is the only security & compliance platform that has an ISO 27001 certification of its own. We save customers dozens of hours by automatically generating key documents like your Statement of Applicability. These can be incredibly time consuming and complex when you try to do it yourself.

Happy to chat more! shrav[at]secureframe.com

Re: Ask HN: Is the ISO 27001 certification worth it?

#89
Yes it is. If you do it right, it will not only improve your security but also your reliability as well as scalability. It forces you to think about you business processes and documentation. This helps by onboarding new employees as well as bringing structure to existing. In addition, you gain stability to you enterprise.

But, this does not come for free. You have to invest time and Money and most companies don't understand the importance of not copy and pasting existing SOP and other documents.

Re: Ask HN: Is the ISO 27001 certification worth it?

#90
post #55

Earlier quoted context omitted.

We are in the 'lucky' position that ISO 27001 is now simply a legal requirement because we offer a healthcare SaaS-product in the Netherlands (ISO 27001 is required via its Dutch NEN 7510/12/13 bastard child that is). For a small company (less than twenty employees) it really is a lot of work. It brings some benefits in that it forces you to have your documentation and certain processes in order, but man… getting aud…

We’re also certified for similar reasons. It did bring information security more in the focus of upper management, so that’s a plus. I for the time for backup encryption, getting rid of outdated servers (fuck Arch Linux, really), and everyone now has a monitored laptop, and got a info sec training.

You could have organized your processes around ArchLinux instead of battling it, really. A living, dynamically developed software will benefit a lot from ArchLinux rolling releases.

Once your software becomes an ossified cash cow, moving it to RedHat makes more sense.

Post reply on HN