Challenge
Zoundream wanted to demonstrate its commitment to security and privacy by obtaining the ISO 27001 certification, an internationally recognized information security management system (ISMS) standard. The company’s first commercial contract depended on the successful ISO 27001 certification, and it was paramount that it was done in the shortest time possible.
However, Zoundream faced several challenges in implementing an ISO 27001-based ISMS. The company had no internal expertise in the security and compliance domains and lacked the resources and time to hire and train new staff. The company also had a complex cloud environment that needed to be assessed and secured according to the standard’s requirements. Zoundream tried to implement an ISO 27001-based ISMS for more than six months before contacting the Security Consultants team, but the lack of internal experience prevented the company from succeeding.
Solution
The Security Consultants team conducted a compliance gap analysis and a cloud security posture assessment for Zoundream, identifying the areas that needed improvement and providing practical recommendations. The team also set up weekly project calls and a streamlined process to fulfill all requirements by the standard, including risk assessment, policies, procedures, user security awareness training, and hardening of the cloud environment of the company. The Security Consultants team also provided guidance and support for the internal and external audits, ensuring that Zoundream was well prepared and confident for the certification process.