How we approached ISO 27001 across a four country platform
I directed the ISO 27001 implementation for a school meals platform that processes children's personal data in four countries. Each country has its own privacy law. We did the work alongside regular product delivery with a 10 person engineering team.
Start from risk, not from templates
ISO 27001 starts with risk. You identify what the company holds, what could threaten it, and what the company will do about it. The policies, controls, and audit evidence should follow from those decisions.
We started with an asset register covering every system, database, laptop, and outside service that touches data. Each asset had an owner. The risk register then recorded what could go wrong, how likely it was, the impact, and the chosen treatment. Auditors and customers both ask for this material.
Write policies people can follow on a Tuesday
We kept each policy short, named the people it applied to, and connected it to tools already used by the team. A long policy that nobody follows does not improve security.
Access control is a good example. The policy states who can reach each system and how access is granted or removed. The RBAC configuration, offboarding checklist, and access review log show whether the policy is being followed.
Evidence is the actual deliverable
Auditors ask for records, not promises. We collected evidence from the beginning:
- ·Access reviews with dates and sign off.
- ·Incident records with the cause and follow up action.
- ·Training records showing who completed each session.
- ·Change tickets and reviews linked to deployments.
- ·Assessments for suppliers that handle company data.
If you only take one thing from this post: start the evidence habit now. It cannot be backfilled honestly.
Mapping one standard onto four privacy laws
ISO 27001 provides one management system, while each country adds its own privacy requirements. Definitions, retention rules, and breach notification deadlines can differ.
We kept one core management system and recorded each national requirement as a control or register entry, with local annexes where needed. Four separate compliance systems would have duplicated work and drifted apart.
Because the platform handles children's data, each feature release includes a short privacy review. Putting that check into the release process is more reliable than expecting someone to remember it each time.
Keep the team on your side
The person writing the policies also reads the code, which kept the controls close to the way the team actually works. We introduced controls with the necessary tooling. Training stayed short and used examples from our own systems.
What changed
The work gives enterprise and government customers clearer answers to security questionnaires. Incidents follow a defined process, and the company has a current record of where its data lives. That matters for any platform holding children's data.
Case file 001 covers more of the engineering work. If your team is preparing for ISO 27001 and needs a realistic view of the scope, get in touch.
// frequently asked
How long does ISO 27001 take for a startup?
Allow six to twelve months from kickoff to audit readiness for a focused small team. Auditors need evidence that the controls have operated over time, not policies written the week before the audit.
Do startups need a consultant for ISO 27001?
Not necessarily. A technical owner who understands the standard can run the implementation internally. Consultants can help with templates, but the company still has to operate the controls and collect the evidence.
What is the hardest part of ISO 27001?
The hardest part is making the ISMS match how the company works. Policies that nobody follows will not survive an audit or improve security.