Information Security Blog

ISO-27001 Cost Estimate: $48,000 Information Security Confidence: Priceless

ISO-27001 Cost Estimate: $48,000  Information Security Confidence: Priceless

5 Flares

5 Flares


×

iso-27001-consultingHow Much Does ISO-27001 cost?

 

I spend a good percentage of my time these days talking to organizations that process data on another party’s behalf regarding ISO 27001 and other forms of “attestation” (proof that they are handling their clients’ data in a reasonable and appropriate manner).   With ISO 27001 being such a hot topic and Pivot Point Security being such a strong advocate of ISO 27001, invariably the prospective client will ask; “What is estimated cost to obtain an ISO 27001 certificate?”

The challenge with providing a ballpark cost for a 27001 certificate is that there is so much potential variability. For example:

  • The size of the company and physical/logical scope of the ISO-27001 certificate
  • The current maturity level of the Information Security Management System (ISMS)
  • The gap between the current state and the desired state of the control environment
  • The in-house capability/capacity to develop the ISMS and close the identified gaps
  • How quickly the certificate is required

Nevertheless, we eventually end up with an estimate for how much ISO 27001 may cost in their particular environment.  While we spend a lot of time drilling down on the areas highlighted above, we also draw extensively on experiences over the last 3 or 4 years taking clients through the certification process.

Looking across these projects an “average” customer looks about like this:

  • 75 employees
  • Processes sensitive data subject to PII/PHI laws regulations
  • Co-locate their services at two disparate data centers
  • Provides software (SaaS) integral to their service offering
  • Has a control environment that, while previously subject to external review, would still be best referred to as immature and non-fully documented; i.e., a Capability Maturity Model (CMM) of 2
  • Has a “CSO” that is very technical but is not well versed in ISO 27001/ISO 27002 (i.e., a CISSP rather than a CISA or CISM)
  • Is experiencing pressure from clients for third party attestation – often specifically asking for ISO 27001 certification
  • Needs to achieve a certificate (without overly disrupting “business as usual”) in a 12-month time frame
  • Require a fair degree of ISO-27001 consulting to prep for the certification audit

Assuming the above more or less holds true, the “external” costs to become ISO 27001 certified may look as follows:

  • Precertification Phase I: $20,000 (e.g., Scope Definition, Risk Assessment, Risk Treatment Plan, Gap Assessment, Phase II Remediation Plan)
  • Precertification Phase II: $18,000 (e.g., Gap closure (collaboratively), registrar selection, ISMS Artifact development, Risk Management Committee, Incident Response, Internal ISMS Audit, On-site Certification Audit Support)
  • Certification Audit: $10,000
  • Total cost for ISO 27001 certificate: $48,000

Once you have your certificate you will require a “surveillance” audit in years 2 and 3 to maintain your certificate.  You will also need to conduct an Internal ISMS Audit each year – which the “average” company usually outsources to a third party. So figure your year 2 and year 3 costs are likely to be as follows:

  • Surveillance Audit: $7,500
  • Internal ISMS Audit: $7,000

A word of caution – your costs may vary notably.  We have clients that have spent as little as $5,000 and as much as $70,000 on pre-certification consulting.  As an FYI, I used $1,500 per man-day in my estimates, as I have seen rates anywhere between $1,400 and $1,800 for a “true” ISO-27001 consultant.

 

0


Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

About the Author:

John Verry (CISA, 27001 Certified Lead Auditor, CCSE, CRISC) is Pivot Point's resident "Security Sherpa". He is lucky enough to spend most of his day helping clients develop a road map to address security, compliance, and attestation requirements.

Add a Comment

5 Flares Twitter 3 Facebook 0 Google+ 0 Pin It Share 0 LinkedIn 1 Reddit 0 StumbleUpon 0 Email -- Email to a friend 5 Flares ×