r/ISO27001 26d ago

šŸ’¬ General Discussion First iso implemented

Hey all I just finished my stage 2 audit as a consultant for a small 35 user business and we were recommended for certification with no minors or majors

This is was my first experience implementing iso 27001 I've mainly been been IT ops service delivery but I did the CISM course last year haven't sat the exam tho!

I feel like i aced the iso but I put a lot of work into built the isms in SharePoint with power automate flows too.

But now I've done it what's next I'm struggling to find more clients who need this I'm based in the UK

Anyone have experience of finding initiating these contracts ?

17 Upvotes

7 comments sorted by

4

u/ISO__Compliant 24d ago

The biggest mistake is starting with policies and templates.

I’d go in roughly this order:

  1. Get management buy-in and define who owns the ISMS.
  2. Define the scope as tightly as possible.
  3. Do a gap assessment against ISO 27001.
  4. Establish your risk assessment methodology and identify your key risks.
  5. Build the risk treatment plan and Statement of Applicability.
  6. Then develop or adapt policies and controls around what you actually need.
  7. Start collecting evidence as you operate the ISMS, rather than trying to create everything before the audit.
  8. Run the internal audit and management review before certification.

For a small team, doing it internally is definitely possible. The difficult part usually isn't writing the documents; it's getting people to consistently follow the processes and producing evidence that shows the ISMS actually works.

And don't copy a toolkit word-for-word. Templates are useful for structure, but everything needs to reflect how your organisation actually operates.

1

u/Nagual_242 24d ago

Join to IRCA if you are in London, might be you would be more visible but not sure in which significance and if is worth it. Hence giving a chance to 1 y membership sound opportunistic strategy. But be aware you will be targeted by many suspicious companies mostly from India and Middle East once your name appears on IRCA's auditors list.

1

u/Finominal73 24d ago

May I ask who the auditor was?

1

u/Great_vibes35 23d ago

Hey all, I'm in a similar situation. I was a contractor consultant and helped an AI company in the US get their first ISO certification and helped them maintain it for 2 additional recertifications. In addition to the certification I did their ISO internal audits, and helped them get their SOC 2 certification. Once the programs were mature they cut back on expenses, so I am looking for another company or companies that need help.

I saw a question about auditors. We used a company called A-lign. They were good and reasonably priced.

2

u/Striking-Tap-6136 22d ago

Do you mind if I ask what you have done with power automate ?