Medium and large corporations are increasingly having to deal with information security breaches. According a study, 70% of these incidents have their root cause in the supply chain. Corporate leaders and investors are driving a greater level of compliance in order to address this systemic issue. Hence, organizations are implementing their own ISMS which is then audited by certification companies. In order to be compliant with the ISO IEC 27001 standard, supplier management policies are requiring new suppliers to become ISO 27001 certified.
At first most service oriented companies might think, they are excluded as they do not supply physical good to such corporations. Any company that does websites, coding, software development or even marketing for a mid sized client is already in the scope of this trend. Hence, web agencies and marketing agencies have to implement their own information security management system (ISMS).
From here, the web agencies then apply for an audit in order to achieve an iso 27001 certification. As AI is becoming a super helpful took for marketers and developers, the risks are also leading to new governance requirements. This where companies have to pick an ISO standard to be accepted as a trustworthy supplier. Those heavy aI users will have to also make an effort to show case their sustainable and ethical use of AI by also getting their AI Management System (AIMS) certified according to ISO 42001 by an accredited certification body.
You might ask about the ROI of getting a management system documented and certified. It will consume several work days or weeks to get it all ready. The audit will also cost you a lot of cash. Nevertheless, think about your competition. some of your competitors will not bother and eventually go into oblivion. Other more growth orientated web agencies will invest the time and money into becoming ISO 27001 certified. They will start contacting your clients, to let them know there is an alternative web agency which is fully compliant with thei supplier requirements. If yu do not invest in your competitive ness, you will eventually fall back in the market. Even small clients will eventually become ISO 27001 certified and expect your agency to also be compliant. Hence, ignoring information security is not a way to staying in business.
Now you might ask where to start. There are 11 steps towards achieving this certification. You can get help from information security implementation experts and save a lot of pain. Eventually you will need to get audited by an accredited certification body. That is where Stratlane can help you. Having access to audit teams in many parts of the world, makes it easier for you to get your management system audited. So you can get the lead auditor to inspect your documentation even if you are in Alaska, or Luxembourg or in Capetown. Every lad auditor has to undergo a training to deliver a compliant audit. In some cases, a remote audit is even a good way of becoming certified as your web agency might be predominantly home office based. An audit team can not realistically travel accross state or countries just for a 30 minute conversation. Remote audits save time and travel expenses. As you will see it is not impossible to achieve an iso 27001 certification.
















Leave a Reply