In the case of any strategically important decision for the company, employees go through a basic protective mechanism, well known as the 5 stages of response to change (author E. Kübler-Ross). The eminent psychologist once described emotional reactions, highlighting 5 key stages of emotional response: denial, anger, bargaining, depression and finally, acceptance. We have prepared a series of articles dedicated to ISO 27001 certification, where we will discuss each of the stages. Today, we will talk about the first one – denial.

Obtaining an ISO 27001 certificate "just for show" is a rather dubious pleasure, as it requires long and costly preparation. Moreover, as the show, this standard is extremely unpopular in Russia: to date, only 70 companies have been certified for compliance. In contrast, abroad, it is one of the most sought-after standards that meets the growing demands of businesses in the field of information security.
Our company provides a full range of accounting outsourcing services: bookkeeping and tax accounting, payroll processing, and personnel administration. We hold one of the leading positions in the market, particularly because foreign companies with divisions in Russia trust us with their confidential information. This concerns not only the financial processes of our clients but also the personal data we work with daily. Therefore, the issue of information security is one of our top priorities.
Often, all business processes of Russian branches are controlled and declared by the head offices of foreign companies, which means they must comply with internal group-wide standards. Recently, some of our key clients have begun to reconsider their security policies towards stricter measures. This is undoubtedly related to global trends concerning the increase in cyberattacks and losses associated with information security breach incidents. If it's necessary to implement protective measures, policies, and procedures aimed at enhancing the company's information security, ISO/IEC 27001 certification can be avoided, thus saving a lot of money, time, and nerves.

Today, foreign clients' tenders have begun to include requirements for existing information security within the company. Some, in order to simplify their checks and standardize their approach, are setting the mandatory evaluation criterion as the presence of ISO/IEC 27001 certification.
We experienced a situation where one of our key international clients, certified under this standard, seemingly significantly strengthened their global information security team. How did we find out about this? They decided to conduct an audit of our information security management system, considering we provide them with accounting services and personnel administration—therefore, the security of our information systems is critically important to them. The previous audit took place three years ago, and it went quite smoothly.
This time we were tackled by a united team of Indians, skillfully uncovering several dozen flaws in our security management system. The audit process felt like a wheel of Dharma – it seemed they had no intention of reaching a conclusive point in their review. It was an endless stream of questions, comments, our replies and evidence of their validity, conference calls, and long philosophical discussions trying to recognize the accent of the client's IT security team. By the way, the audit continues to this day with varying levels of intensity – over time, we have come to terms with it. Thus, the necessity for certification arose organically.
Can we manage with ISO 9001?
Anyone with a reasonable understanding of certification under any ISO standards knows that the foundation for each of them is the ISO 9001 "Quality Management System" certificate. This is perhaps the most popular certificate in the entire range of ISO standards at the moment. We didn’t have it – and we decided not to obtain it. Several reasons influenced this decision:
- doubtful economic efficiency of having this certificate for the company;
- most of our internal processes were already aligned with this standard;
- obtaining this certificate would require additional time and money.
Accordingly, we decided to implement ISO 27001 directly, without starting with the "easier" 9001.
Or maybe we shouldn’t?
Looking ahead, we returned to the question of whether obtaining it was appropriate many times. We began to study the issue from all sides, because we had absolutely no expertise. And here are the misconceptions that made us rethink this question.
Misconception #1.
We hoped that the standard would provide us with a detailed checklist, a list of policies and other statutory documents. In reality, it turned out that ISO/IEC 27001 is a set of requirements for the information security management system itself and the process being established. Based on these, it was necessary to independently decide what to write / implement in our company to comply with the standard's requirements.
Misconception #2.
We genuinely believed that it would be sufficient to study just one document and implement it independently within a relatively short time. In reality, as we read the document, we realized how many adjacent standards our standard is connected to, and how many standards we need to familiarize ourselves with, at least superficially. The "cherry on top" was the lack of up-to-date texts of the standards available to the public — they had to be purchased from the official ISO website.
Myth #3.
We were confident that we would find everything necessary for preparation for certification in open sources. There were indeed a lot of materials on ISO 27001 available online, but they lacked specificity. There were almost no accessible step-by-step instructions for preparing for certification or real cases from companies that had implemented this standard.
Myth #4.
We will write policies, but they won’t work! Seriously, we already have too many rules in our company; no one will follow 30 new policies. In reality, fortunately, our employees took the task of mastering the new rules seriously and successfully passed the test on understanding the information security management system documents.
Myth #5.
At that time, we couldn't clearly assess what benefits we would gain from our labor efforts. Back then, the number of requests for this certificate was not that high, and our key and most demanding client appeared long before certification. Experience showed that we managed without the standard.
At some point, we realized that we were chaotically closing gaps as they arose due to client requirements. Each time we would come up with new policies or solutions. Eventually, we came to understand that it would be much easier to systematize the process, which would ultimately save us significant labor efforts. The standard was meant to simplify this task.
Now, two years later, we see a trend of increasing requests and interest in this matter from major international clients.
Final decision.
In conclusion, we want to say that the leaders in our industry have obtained the ISO/IEC 27001 certification, prompting all other major providers (including us) to reconsider this issue. Undoubtedly, having a beautiful line in the company's marketing materials – on the website, in social media, in advertising brochures, etc. – can be considered a nice bonus, but is it worth spending so many resources for it? We have determined that for us, this is more than just a pretty line, and we have committed to this project.
Source: habr.com
