ISO 27001 Certification Partner Needed

Job ID: 40025530

Budget: ₹37,500 – ₹75,000 INR

We are a very small SaaS company, looking to obtain ISO27001.

We are looking for someone who has already got ISO27001 certification for small SaaS companies in the past AND WHO HAS A SET OF POLICY DOCUMENTS THAT WE CAN USE AS A BASELINE WITHOUT HAVING TO WRITE EVERYTHING FROM SCRATCH.

We had planned to start ISO27001 in the 2nd half of 2026, however a customer is insisting we start this sooner (or lose their business) and they are a larger business with a dedicated security/compliance team and all policies written as part of this project need to be approved by them (this will form sign off/completion for this project).

They have given us a priority order for the policies that they want us to have in place initially...

The high priority items below need to be completed in the next 4-5 weeks.

HIGH PRIORITY ITEMS
These items represent the most critical security concerns to ensure Terracon’s data security, availability, and resilience.

Incident Response & Continuity Management
 Development of a documented Cybersecurity Incident Response Plan and Incident Management Program.
 Development of a formal Business Continuity Program, IT Disaster Recovery Plan, and Data Recovery Plan.

Access & Network Security
 Implementation of a defined Access Control Program, Password Policy, and documenting your DMZ environment for public-facing systems.
 Implementation of Network Device Hardening Standards and a Vulnerability Management Program.

Governance & Risk Management
 Implement a Risk Governance Plan
 Implement a Third-Party Risk Management and Cyber Supply Chain Risk Management program.

Change & Configuration Management
 Document your Change Management Program and Security Configuration Standards for servers, network devices, and applications.

MEDIUM PRIORITY ITEMS

These items are requested to further strengthen your security foundation and improve overall alignment with recognized best practices.

Policy Development & Review

 Implement Information Security Policies and review them at least annually.
o These policies should address Regulatory and Contractual Compliance or Third-Party Privacy Obligations, as well as a Privacy Program governing the collection, use, and protection of client data.

Secure Development & Data Governance
 Define and implement a Secure Software Development Lifecycle (SDLC) policy that includes an API Security Review Process, Data Flow Documentation, and Data Inventory for scoped data.

After the above has been copleted we then need to...

2. Complete all other policies and implement controls across the business.
3. Achieve certification
4. We will need ongoing support and someone to pick up responsibility for adherance to ISO27001, continual improvement and re-certification annually.

Deliverables
Develop ISO27001 policies (working through the details as we go)
Create procedures for information security
Ensure compliance with ISO27001 standards