Published: September 27, 2025
9
16
72

Here’s a thread about how I approached getting ISO27001 certified at Pistachio, written for people who hate these things as much as I do. As @IceSolst says, ACAB includes auditors.

Caveats, as usual: First, I’m a total amateur. I did this once and hopefully never again. Some days I actively try to forget some of what I learned. ISO27001 made me dumber. This is just about what worked for me. Second, my org is 70 people, so YMMV. Anyway, here we go:

BASICS (1): ISO27001 is a standard for managing information security, and you can get an auditor to certify you followed the standard. That helps with sales processes to prove you’re not shit, and a lot of bigger companies require it from any vendor they buy from.

BASICS (2): If you read ISO27001 start to finish expecting to understand what to do, you’ll be disappointed. It’s extraordinarily vague and basically says “do security”.

BASICS (3): The body of the standard basically sets out a bunch of rules for creating and running an information security management system (ISMS), and then Annex A is a lot of controls that you want to prove you’ve satisfied if relevant. The controls are a little more concrete.

BASICS (4): What you’re effectively doing is creating a bunch of documents that say “this is how we manage information security” plus a bunch of specific policies, then documenting technical/human processes to prove you’ve done everything you said you’d do.

TOOLS (1): If you try to build everything from scratch you’re going to have a terrible time. Use some software. We used Vanta. I didn’t shop around, just jumped on a call with an AE and said I’d sign by end of month if they give me a big discount and quarterly billing. Done.

TOOLS (2): What you get with Vanta is basically: 1. A set of generic policies to modify, and 2. A ton of specific “tests” to prove you’ve passed. My advice is to start with the tests, then go back and fix up the policies. Otherwise the policy docs will all feel like gibberish.

ISMS/POLICIES (1): There are a TON of policy docs. For us, ~30 in total. People say you should keep the docs short and simple so they’re “effective”. Don’t do that. Your goal is coverage. You want to know there’s nothing your auditor can say that isn’t covered in a doc somewhere.

ISMS/POLICIES (2): So many controls say things like “processes shall be established” or “rules shall be defined” and 90% of the battle there is having a document to point to. Trust me, don’t cut Vanta’s sprawling legalese. Keep it, and use it as a weapon against your auditor.

ISMS/POLICIES (3): What I did is also made a policy summary doc with the most important stuff, but made it clear it doesn’t override the real policies. That way the auditor can’t say “well people don’t understand all of this” but also can’t find stuff you missed.

GETTING STARTED (1): Like I said, I started by just knocking out all of the “tests” Vanta made that were easy. For example, to prove you have rules for handling company data in your employment contracts, you just upload a recent example. Done.

GETTING STARTED (2): What Vanta is doing is linking these tests to controls, so when your auditor shows up and says “how did you satisfy A5.20 (vendor agreement stuff), you click the control and it shows all the tests with evidence that are relevant.

GETTING STARTED (3): You’ll not really understand why you’re doing things at first and that’s fine. Just keep doing it. Skip over the harder tests or stuff you’re uncertain about, and just crack out the stuff you know how to do.

GETTING STARTED (4): You might be tempted to say “well this test doesn’t really apply” and disregard it, but do so sparingly. Your auditor won’t understand your context. I don’t care that your network doesn’t provide any privileged access, pay for a good firewall anyway.

HUMAN PROCESSES (1): You’ll end up with some tests that you’ll look at and think, “what do I do with that”. The thing is that ISO27001 doesn’t really require tech at all. You can always brute force solutions with manual labor.

HUMAN PROCESSES (2): For example, you need to prove you’ve evaluated everyone’s cybersecurity knowledge? Cool, it’s now one person’s job to do an annual 1:1 with each person (and document it). Done.

HUMAN PROCESSES (3): If you don’t know where to start on a given test or control, go to ISO27002. It has concrete examples of how you can satisfy a control.

RISK REGISTER (1): Auditors love to say that ISO27001 is about evaluating risks, and this is your get out of jail free card. If there’s some area where you’re weak, just document that, make a plan to fix it or just say the business decided to accept the risk. Have the CEO sign.

RISK REGISTER (2): It’s worth spending a few hours on this part just adding anything you can think of. Have a few people join in because auditors love when “the business” is involved. You’ll never regret having a risk listed.

RISK REGISTER (3): Doing this is also good because when you then later do some of the things you said you’d do to address the risks, that shows improvement, and auditors love that too.

THE AUDIT (1): The initial audit is two parts. First they show up and complain about your documents and give some findings on that, and generally tell you if you’re missing obvious stuff. Then they leave so you can fix stuff.

THE AUDIT (2): They then come back maybe a few months later and look through all the evidence with you, and write down findings. As long as you don’t get any major nonconformities, you get certified.

THE AUDIT (3): I thought the auditor would try to see every little thing and dig in, but realistically there’s no time for that. This isn’t some forensic investigation. They mostly just look for evidence of compliance, not the opposite.

AUDIT ADVICE (1): Really learn all of your policy docs. I don’t care that it’s technical and boring. Your auditor will try to own you by saying, “yea and where does it say that?!” It’s great when you can be like, “It’s right here in the operational security policy, actually.”

AUDIT ADVICE (2): Auditors love to give advice, and I went along with that in the 1st stage. That was a mistake. Got a ton of minor non-conformities. In the 2nd stage, I argued everything I disagreed with, and the result was very few non-conformities.

CONCLUSION (1): And that’s it. Got the cert and had a terrible time. It made us a tiny bit safer, sure, but not relative to the effort involved. I could have made us a lot safer in other ways if I applied the effort elsewhere.

CONCLUSION (2): Ultimately, this is the unfortunate part of ISO27001. The standard wants you to care so much about business context, but the easiest path to certification is to not. And I do think that’s the standard’s fault.

The end. Not sure if it was helpful, but if you have any questions feel free to ask. Also my DMs are open. And sorry to spam the feed.

@ZackKorman @IceSolst I'm literally doing this now from scratch and just couldn't understand why I was struggling so much and SOC2 is in my future

@comms_sherlock I absolutely do not envy you. My condolences

@ZackKorman @IceSolst Just went through the SOC 2 process and will likely pickup ISO next year. I had much of the same experiences

@schwartzonsec Hah glad I’m not alone. It’s just one of those things it’s way easier to game than take seriously, because the auditor is… well, an auditor.

Share this thread

Read on Twitter

View original thread

Navigate thread

1/33