ISO Academy: Darren on helping SMEs achieve ISO 27001

ISO_Academy

I have been involved with the Securious ISO academy since creation, and have helped it evolve with our team over the past 2 years. As an ISO 27001 Lead Implementer, I also assist presenting the academy and between presentations, project manage the evidence gathering of the implementation alongside the client’s completion of mandatory documents.

What is the Securious ISO Academy and how does it help?

The Securious ISO Academy originated from our onsite implementation of ISO 27001 for our clients. We noticed that the most beneficial component of our onsite implementation was the knowledge sharing element of how to build and manage an Information Security Management System (ISMS). This greatly helped management teams feel confident creating a system that fitted their culture and business as usual environment.

SMEs and new businesses often feel that ISO is out of reach, both in meeting the requirements of the standard, and financially justifying the process, which often means filling in evidence for due diligence in a bidding process where an equivalent would be to provide an ISO 27001 certificate itself. But, more importantly, more businesses are finding that not implementing the controls and processes of an ISMS leaves them much less competitive in the market without such certification to show.

How we deliver the ISO Academy

The ISO Academy comprises 6 2-hour ‘steps’ by BSI trained ISO 27001 Lead Implementers and Lead Auditors, who explain the ‘why and how’ in easily digested sessions. We also offer the option of using our templated documents, relevant to the specific step of understanding. This means we won’t leave you with a mountain of documents that just turn into a ‘tick box exercise’ – something we at Securious strongly discourage.

We project manage between the online sessions, including document or evidence reviews to ensure you don’t fall behind the steps, and each participant has full understanding before receiving the next session.

We can deliver the ISO Academy to multiple companies remotely (2 -3 key staff from each) and therefore reduce cost. Or, for a more concentrated effort, we can deliver it to an individual business with deadlines to meet or a more complex environment.

Why ISO 27001 and who attends the Academy?

Everyone is different when it comes to understanding how your business meets the standard… But the underlying question of ‘why’ you are implementing is the same for all. We help to take the pain away and assist designing an ISMS for your business as a ‘tool for continuous improvement’.

Using the Academy, we have helped companies of all sizes. Some smaller companies wanted to implement the best practice that ISO 27001 and ISMS provides as they expand from a handful of staff, ensuring a sound foundation to build from. Other multi-site companies with diverse trade have implemented from nothing. Some attendees have certified within 3 months using this approach. We have helped additional companies that, through personnel changes or not understanding the importance of incorporating their ISMS into business as usual, have let the ISO slip to a point where re-certification means training a new team entirely with what they already have in place.

Feedback from the multi-business cohorts has been that bringing together different approaches to problems and solutions from other industries is really beneficial, and often raises worthwhile discussion that attendees have not considered to their own implementation.

What can attendees expect from it?

From little or no knowledge, Securious provides 6 easy to understand building blocks of ISO 27001 implementation and management from the overview of the standard itself, through support and leadership involvement, asset management, risk assessment and treatment to monitoring, review and continuous improvement. We can provide all the mandatory (and non-mandatory) documentation along the way so by the completion of the Academy, the businesses’ key personnel who are involved in the implementation and are running the ISMS have what they need to fulfil the standard – and they also have the knowledge they need to improve Information Security in their business.

Our Academy is delivered by accredited BSI Lead implementers and Lead Auditors, and supported by in-house industry experts of additional compliance standards.

Securious supports you through stage 1 readiness to stage 2 certification, and the team can assist beyond your certification, into the management stages of running the ISMS.

I thoroughly enjoy helping SMEs on their journey to certification, and love seeing how the initial pain or worry of gaining a world-recognised international standard can be taken away.

P_darren_1_Securious_Exeter_Devon_Cyber_Security

Written by Darren

Darren is our Operations Director. He facilitates the smooth delivery of our client services, making sure everything is done right and on time. Darren is Prince 2 qualified and a BSI qualified ISO 27001 implementer.

Follow us on LinkedIn

See the latest from the Securious team on LinkedIn