Cybersecurity in plain language (6 of 6)
From the decision to start through to the certificate, there are eight steps, and it usually takes six to twelve months. This page explains what happens at each step and what is expected of you as a business owner. At the bottom of the page you can download the overview as a PDF.
A certificate is not mandatory. You can stop after step 6: you then have the system, without the certificate.
That may seem long. But for most businesses cybersecurity comes second, because the core business has to keep running at full speed. If it is genuinely urgent for your organisation's survival, it can be done in four to six months. Be aware, though, that in most cases this is fairly unrealistic.
The road includes two roles that you are better off not giving to the same party.
The first is guidance: someone who helps you build the system. The second is the internal audit: a check that confirms, or refutes, that the system meets the standard and really protects you. The standard requires that check to be objective and impartial, and whoever helped build the system can hardly judge their own work impartially. So my advice is to have the internal audit done by someone from outside who was not involved in building it.
Before the certification audit starts, at least one internal audit and one management review must have been completed. I actually consider that internal audit more important than the certification audit. A good internal audit does not just tell you where you stand today. Drawing on the internal auditor's knowledge and experience, it also tells you where a limited effort will take you the furthest.
At any one organisation I take on one of the two roles: guidance during the implementation or the internal audit. If I take on the guidance, I can arrange for someone from my network with sufficient experience to do the internal audit, or you choose an internal auditor yourself. That keeps the two roles separate.
Guidance with an ISO 27001 implementation
Want to do something today, even without a full programme? List the three things that would bring your business to a halt if they failed: a system, a supplier, a file or a person. That is where ISO 27001 starts on a small scale, even if you never get certified.
The eight steps on four pages, with the diagrams.
No obligation. We look together at whether ISO 27001 makes sense for your business, and where best to start.
Book a short call