ISO 27001 for businesses in Devon, Cornwall and Somerset – what’s the point and how do I get it?

 

ISO 270001 devon, cornwall, somerset image

The profile of ISO 27001 – the international benchmark for effective information security – is growing rapidly in the Devon, Cornwall and Somerset business communities. In this article we look at why, explain what ISO 27001 is and isn’t and consider how businesses in the South West can most easily and effectively achieve and maintain the ISO 27001 standard.

What is ISO 27001?

ISO 27001 is the international standard for Information Security. It provides a framework for an information security management system, which enables organisations to manage the security of assets like finance information, intellectual property, employee details or information entrusted by third parties.

What are the key ISO 27001 benefits?

ISO 27001 has a number of significant benefits, both in terms of the end certification and the process and practices it helps instil within an organisation.

These include:

  • Enables you to bid for contracts with larger organisations who require the certification
  • Simplifies supply chain due diligence by minimising the evidence required by suppliers
  • Provides a system and tool to manage your GDPR compliance
  • Proves you have a system in place to continually review and improve your information security
  • Improves your credibility with customers, business partners and staff
  • Identifies your information assets and their value, enabling you to make informed decisions to mitigate risks 

Why are so many Devon, Cornwall & Somerset businesses looking at ISO 27001?

In our experience, there are three key drivers behind the desire for more businesses in the South West to consider or seek an ISO 27001 certification:

  1. ISO 27001 is explicitly required to bid for (or retain) a contract
  2. ISO 27001 is seen as a significant differentiator that gives competitive advantage
  3. ISO 27001 will provide a framework to better manage the information and security

In reality, we find a combination of these factors behind most organisations’ decisions to move forward with the certification process.

What does it take to get (and maintain) ISO 27001?

ISO 27001 is a demanding standard and is not one to be taken lightly. There are several steps involved:

  • Firstly, it’s important to understand what ISO 27001 is and the importance of managing your assets, risks and incidents. 
  • This includes determining your scope and understanding the Plan, Do, Check, Act approach.
  • Leadership is crucial and the next step covers the importance of leadership and identifying your Information Security Management System (ISMS) team, allocation of resources, competence, and communication.
  • In the planning stage you’ll be creating objectives and deciding how to achieve them
  • The planning stage also includes identifying information assets and building an asset register so that you can move on to identifying the risks to these assets.
  • Risk assessment is another part of the planning stage, including risk methodology, risk assessments and building the risk register
  • The final part of the planning involves determining risk treatment to mitigate the risks to an acceptable level.
  • At this stage you will also create the Statement of Applicability. This takes all the controls in Annexe A of ISO 27001 and determines whether they are applicable
  • Once you understand what you are protecting and the controls you have identified, you can implement the plans to mitigate risks that your information assets may be exposed to.
  • Performance Evaluation and improvement helps you to check that what you have put in place is working and then feed this back into opportunity for improvement.

For reference, We have managed to implement ISO 27001 within a 12 week process for some clients. However generally an implementation takes around 3-6 months (sometimes longer depending on resource availability and scope of the organisation)

How much does ISO 27001 cost?

Getting the ISO 27001 certification will involve, for most organisations, three different kinds of expense:

  1. Ultimately, the cost to the certification body (eg BSI) for the certification process. This will depend on the amount and type of information stored or processed, size of company that must audited after implementing controls and the total locations in scope.
  2. The internal resource costs of any changes to your systems and processes required to achieve the certification
  3. The cost of any expert support you require to implement the required systems and processes ahead of ISO 27001 certifications, and then to help you maintain it subsequently.

These costs will vary considerably from organisation to organisation, depending on their size and prior readiness as much as anything. However, at Securious we have pioneered an approach to delivering outstanding expert support to get you ready for ISO 27001 that can minimise the cost – see below.

What are the best options for getting ISO 27001 in Devon, Cornwall and Somerset?

We may be biased, but we believe our pioneering ISO 27001 Academy is an outstanding option for most organisations who are considering ISO 27001 in Devon, Cornwall and Somerset. 

In the ISO 27001 Academy – which can be either online or in-person at The Exeter Science Park – we work with businesses in a collaborative, interactive online workshop for a more effective (and cost-effective) implementation.

Here’s how it works:

Over 6 sessions, each business will gain an understanding of the standard, its application and implementation, while building an information security management system manual – a central document for the management of ISO 27001. The following will be covered in the six two-hour workshops.

  • What is ISO 27001 and how can this assist with GDPR compliance
  • Leadership requirements and support for ISO 27001
  • Planning and asset management
  • Introduction to risk assessment
  • Introduction to risk treatment
  • Introduction to performance evaluation

The cost is from just £995 + VAT and we offer an additional 5% discount to businesses based in Cornwall, Devon and Somerset.

cyber security devon discount for Devon, Cornwall, Somerset, South West image

Whilst the academy is designed to have participants from a small number of like-minded organisations on it together, we do also offer the option for a company-specific Academy – contact us for more details.

Summary – ISO 27001 for businesses in Devon, Cornwall and Somerset

ISO 27001 is the international benchmark for effective information security and more and more organisations in Devon, Cornwall and Somerset are signing up for it. 

Why? The reasons are varied, but building credibility and competitive advantage seem to be as important as the underlying improvements it delivers to the management of the security of assets like finance information, intellectual property, employee details or information entrusted by third parties.

It’s not an easy certification to achieve and shouldn’t be embarked on lightly, but we at Securious have helped dozens of businesses achieve and maintain ISO 27001 certifications. We see it as an important part of future-proofing the region’s businesses.

If you would like any further information, please fill in the contact form below, call on 01392 247 110 or email info@securious.co.uk

 

Read more:

Our Ultimate UK Guide to ISO 27001

Our ISO 27001 offer

The Securious ISO 27001 Academy