ISMS Easy-Adoption Toolkit for Small Business
Who it's for
Enterprises of eight or fewer people that need to adopt an ISMS to meet the Cyber Security Management Act or client requirements.
Problems we solve
High consultancy costs and complex documentation that burden small organizations.
Benefits
A cost-effective toolkit and guided support to build and run an ISMS and meet third-party certification requirements.
Background
Security incidents are increasingly frequent and no enterprise is immune. As public agencies and large enterprises tighten security requirements on suppliers, many require ISO 27001 third-party certification. For small enterprises, adopting an ISMS and getting certified is a necessary condition to win IT-service contracts — yet high consultancy costs are a heavy burden. IngSafe, a professional information-security consultancy staffed by senior auditors and consultants, has developed the "ISMS Easy-Adoption Toolkit for Small Business" to help small enterprises adopt and operate an ISMS in the most cost-effective way, meeting the Cyber Security Management Act and client/third-party requirements.
About the package
For small enterprises of eight or fewer people, with limited resources and relatively simple operations, self-adoption of an ISMS is highly feasible. Built on context analysis and risk assessment, the toolkit considers the ISO 27001 requirements, designs reasonable and practical controls, and streamlines the once-cumbersome procedures and forms to reduce staff burden. Key features:
- Complete ISMS implementation templates
- Online consultation with senior ISMS consultants
- On-site guidance for key activities
- Highly flexible value-added services for different needs
Who it's for & package contents
For enterprises of eight or fewer people adopting an ISMS to meet the Cyber Security Management Act or client requirements. The package includes: complete ISMS document templates; twelve hours of online service and customized templates; and a two-person-day on-site internal audit with discussion.
Price
NT$96,000 (tax included).
Ordering steps
- Contact us to arrange an adoption and assessment briefing.
- Confirm the service, sign the order and pay the first installment (NT$60,000).
- Delivery of document templates (electronic).
- Online discussion and revision of documents — 12 hours, up to four sessions (3 hours each), to be completed within four months of delivery.
- Within seven months, arrange a two-person-day internal audit and issue an audit report.
- After the internal audit and report, pay the balance (NT$36,000).
- Follow-up questions can be raised by email.
Value-added services
- Professional certification training (ISO 27001 Lead Auditor): NT$36,000/person.
- General/specialist courses: NT$10,000 / 3 hours (context analysis, asset inventory, risk assessment, supplier management, internal auditor, SSDLC, incident & BC drills, etc.).
- Technical services (vulnerability scan, penetration test, host/network review): quoted separately.
- Consulting (NT$16,000/person-day): e.g. ISMS gap analysis, BC drills, vendor audits.
Interested in adoption and consulting? Contact us and a specialist will assist you.
IngSafe