We are ISO 27001 certified: here's how we did it

· Þórður

This week we got the good news that we made it through ISO certification!

The ISO/IEC 27001:2022 certification badge from Prescient Security

This is a process that has taught us a lot. Here I want to go through what we did and what we have learned along the way. My hope is that this can be of use to you and your certification journey.

Further down the post I note what the certification cost in total and which vendors we used.

Background: when — and whether — we should do this

The first question was when and whether we needed to go through this certification.

Atlas Cloud is a cloud service and hosting solution for critical infrastructure. After more than a few conversations with security specialists, regulators and prospective customers, we concluded that despite being only a year-old company we could no longer wait for this certification.

What is ISO 27001 about?

In short, the standard revolves around one question: how are you securing your information?

The answer can lie in technical defences or in processes, and in fact usually in both. The standard is written in the blood of the mistakes made in information security over the past decades, and it gives a clear map of what needs to be done to follow security best practices.

For us, the certification is an absolute prerequisite for trust and success in hosting. There is no clear certification for hosting providers or their methods. SOC 2 Type 1 comes closest, but ISO 27001:2022 is the gold standard for security in Iceland and in Europe.

We heard warnings that it could take a very long time to obtain this certification, and that many companies grow and mature for years before taking the project on.

In our case it took considerably less time. More on that below.

The vendors

Management system: Vanta

After some searching and comparison of tools, we decided to use Vanta to lead us through the process.

As software solutions go, Vanta is unquestionably on the pricier end. We compared several other solutions against it, including Drata, Verjumst and Eramba. But in the end we were convinced the process would be comfortable and simple with this software — which turned out to be the case.

For a team with limited experience implementing an ISO information security management system (ISMS), the point-and-click interface proved very helpful. After a few weeks of work, the structure of the standard also became fairly clear: how specific evidence ties into specific clauses and forms a closed, provable loop.

The internal audit

For the internal audit we brought in a computer science student with knowledge of certification processes and audits.

The certification body

Based on Syndis's recommendation we engaged Prescient Security for the audit. They proved pleasant and professional. The certification process itself took no more than four hours of video calls.

Vendors for the certification

  • Vanta — GRC and evidence storage - $8000
  • Prescient Security — certification body - $4750
  • fencer.dev - vulnerability scanning - $1200
  • Semgrep — static analysis - $0
  • Socket.dev — supply chain and package risk - $0
  • Wazuh — HIDS/XDR - Custom (self-hosted)
  • Restic — backups - Custom (self-hosted)
  • Defend Iceland — security and compliance report - Custom

Our approach

Start with the template

When we first opened Vanta, we were met with many pages of documents that needed to be "written". You can then accept the template the software proposes for almost every company policy and document, and that is how I recommend starting. Get everything on paper first, fix it later.

We ran on the mantra "Done is better than perfect" and iterated from there.

Some policies we had to iterate on ten times until they matched reality. In other cases the first drafts proved perfectly usable and did not change at all during the process.

Eyvör

We combined this with the security project we had received a grant for from Eyvör's cybersecurity fund.

There we implemented comprehensive backups of all systems, both data plane and control plane. On top of that, we set up systematic responses to supply chain risks and to the issues and vulnerabilities (CVEs) that have been flowing in faster than ever since the arrival of Mythos and project Glasswing.

The audit

It was remarkably simple and comfortable. The auditor spoke with the team for around four hours to go over the questions that the system and the evidence we had submitted could not prove on their own.

That is really the heart of the matter: the better the evidence speaks for itself, the shorter the conversation.

The numbers

  • Work effort: roughly 6 to 7 weeks of full-time work
  • Total time: 3.5 months from start to finish
  • The audit itself: 4 hours of video calls

You can read more about our security posture on our trust page, as well as Atlas's future certification plans.