ISO 27001 Certification Partner Needed
Budget: ₹37,500 – ₹75,000 INR
We are a very small SaaS company, looking to obtain ISO27001.
We are looking for someone who has already got ISO27001 certification for small SaaS companies in the past AND WHO HAS A SET OF POLICY DOCUMENTS THAT WE CAN USE AS A BASELINE WITHOUT HAVING TO WRITE EVERYTHING FROM SCRATCH.
We had planned to start ISO27001 in the 2nd half of 2026, however a customer is insisting we start this sooner (or lose their business) and they are a larger business with a dedicated security/compliance team and all policies written as part of this project need to be approved by them (this will form sign off/completion for this project).
They have given us a priority order for the policies that they want us to have in place initially...
The high priority items below need to be completed in the next 4-5 weeks.
HIGH PRIORITY ITEMS
These items represent the most critical security concerns to ensure Terracon’s data security, availability, and resilience.
Incident Response & Continuity Management
Development of a documented Cybersecurity Incident Response Plan and Incident Management Program.
Development of a formal Business Continuity Program, IT Disaster Recovery Plan, and Data Recovery Plan.
Access & Network Security
Implementation of a defined Access Control Program, Password Policy, and documenting your DMZ environment for public-facing systems.
Implementation of Network Device Hardening Standards and a Vulnerability Management Program.
Governance & Risk Management
Implement a Risk Governance Plan
Implement a Third-Party Risk Management and Cyber Supply Chain Risk Management program.
Change & Configuration Management
Document your Change Management Program and Security Configuration Standards for servers, network devices, and applications.
MEDIUM PRIORITY ITEMS
These items are requested to further strengthen your security foundation and improve overall alignment with recognized best practices.
Policy Development & Review
Implement Information Security Policies and review them at least annually.
o These policies should address Regulatory and Contractual Compliance or Third-Party Privacy Obligations, as well as a Privacy Program governing the collection, use, and protection of client data.
Secure Development & Data Governance
Define and implement a Secure Software Development Lifecycle (SDLC) policy that includes an API Security Review Process, Data Flow Documentation, and Data Inventory for scoped data.
After the above has been copleted we then need to...
2. Complete all other policies and implement controls across the business.
3. Achieve certification
4. We will need ongoing support and someone to pick up responsibility for adherance to ISO27001, continual improvement and re-certification annually.
Deliverables
Develop ISO27001 policies (working through the details as we go)
Create procedures for information security
Ensure compliance with ISO27001 standards
We are looking for someone who has already got ISO27001 certification for small SaaS companies in the past AND WHO HAS A SET OF POLICY DOCUMENTS THAT WE CAN USE AS A BASELINE WITHOUT HAVING TO WRITE EVERYTHING FROM SCRATCH.
We had planned to start ISO27001 in the 2nd half of 2026, however a customer is insisting we start this sooner (or lose their business) and they are a larger business with a dedicated security/compliance team and all policies written as part of this project need to be approved by them (this will form sign off/completion for this project).
They have given us a priority order for the policies that they want us to have in place initially...
The high priority items below need to be completed in the next 4-5 weeks.
HIGH PRIORITY ITEMS
These items represent the most critical security concerns to ensure Terracon’s data security, availability, and resilience.
Incident Response & Continuity Management
Development of a documented Cybersecurity Incident Response Plan and Incident Management Program.
Development of a formal Business Continuity Program, IT Disaster Recovery Plan, and Data Recovery Plan.
Access & Network Security
Implementation of a defined Access Control Program, Password Policy, and documenting your DMZ environment for public-facing systems.
Implementation of Network Device Hardening Standards and a Vulnerability Management Program.
Governance & Risk Management
Implement a Risk Governance Plan
Implement a Third-Party Risk Management and Cyber Supply Chain Risk Management program.
Change & Configuration Management
Document your Change Management Program and Security Configuration Standards for servers, network devices, and applications.
MEDIUM PRIORITY ITEMS
These items are requested to further strengthen your security foundation and improve overall alignment with recognized best practices.
Policy Development & Review
Implement Information Security Policies and review them at least annually.
o These policies should address Regulatory and Contractual Compliance or Third-Party Privacy Obligations, as well as a Privacy Program governing the collection, use, and protection of client data.
Secure Development & Data Governance
Define and implement a Secure Software Development Lifecycle (SDLC) policy that includes an API Security Review Process, Data Flow Documentation, and Data Inventory for scoped data.
After the above has been copleted we then need to...
2. Complete all other policies and implement controls across the business.
3. Achieve certification
4. We will need ongoing support and someone to pick up responsibility for adherance to ISO27001, continual improvement and re-certification annually.
Deliverables
Develop ISO27001 policies (working through the details as we go)
Create procedures for information security
Ensure compliance with ISO27001 standards