ISMS Easy-Adoption Toolkit for Small Business

  • Who it's for

    Enterprises of eight or fewer people that need to adopt an ISMS to meet the Cyber Security Management Act or client requirements.

  • Problems we solve

    High consultancy costs and complex documentation that burden small organizations.

  • Benefits

    A cost-effective toolkit and guided support to build and run an ISMS and meet third-party certification requirements.

Background

Security incidents are increasingly frequent and no enterprise is immune. As public agencies and large enterprises tighten security requirements on suppliers, many require ISO 27001 third-party certification. For small enterprises, adopting an ISMS and getting certified is a necessary condition to win IT-service contracts — yet high consultancy costs are a heavy burden. IngSafe, a professional information-security consultancy staffed by senior auditors and consultants, has developed the "ISMS Easy-Adoption Toolkit for Small Business" to help small enterprises adopt and operate an ISMS in the most cost-effective way, meeting the Cyber Security Management Act and client/third-party requirements.

About the package

For small enterprises of eight or fewer people, with limited resources and relatively simple operations, self-adoption of an ISMS is highly feasible. Built on context analysis and risk assessment, the toolkit considers the ISO 27001 requirements, designs reasonable and practical controls, and streamlines the once-cumbersome procedures and forms to reduce staff burden. Key features:

  • Complete ISMS implementation templates
  • Online consultation with senior ISMS consultants
  • On-site guidance for key activities
  • Highly flexible value-added services for different needs

Who it's for & package contents

For enterprises of eight or fewer people adopting an ISMS to meet the Cyber Security Management Act or client requirements. The package includes: complete ISMS document templates; twelve hours of online service and customized templates; and a two-person-day on-site internal audit with discussion.

Price

NT$96,000 (tax included).

Ordering steps

  1. Contact us to arrange an adoption and assessment briefing.
  2. Confirm the service, sign the order and pay the first installment (NT$60,000).
  3. Delivery of document templates (electronic).
  4. Online discussion and revision of documents — 12 hours, up to four sessions (3 hours each), to be completed within four months of delivery.
  5. Within seven months, arrange a two-person-day internal audit and issue an audit report.
  6. After the internal audit and report, pay the balance (NT$36,000).
  7. Follow-up questions can be raised by email.

Value-added services

  • Professional certification training (ISO 27001 Lead Auditor): NT$36,000/person.
  • General/specialist courses: NT$10,000 / 3 hours (context analysis, asset inventory, risk assessment, supplier management, internal auditor, SSDLC, incident & BC drills, etc.).
  • Technical services (vulnerability scan, penetration test, host/network review): quoted separately.
  • Consulting (NT$16,000/person-day): e.g. ISMS gap analysis, BC drills, vendor audits.

Interested in adoption and consulting? Contact us and a specialist will assist you.