< Back to case studies

Customer stories
Focused Fitness

Focused Fitness based in Washington, USA, are providers of physical education software and curriculum. Their bespoke software WELNET® is designed to provide physical educators with a tool to gather student fitness data and communicate results. They recently became certified to ISO27001 with the help of a CertiKit toolkit, and below Amy Lutz, VP of Software, talks us through the process.

Reason for certification

Like many organisations, Focused Fitness decided to become certified to ISO27001, due to client demand and contract requirements. Becoming certified to a standard is often a requirement when bidding for contracts, especially for government contracts. Certification was the next logical step for the business in order to develop and grow.

Where to start?

The main trial faced once deciding to become ISO27001 certified was one that is common amongst many organisations, Amy explains, “Our biggest challenge at first was understanding what the process involved, what the standard was and how to actually get certified.”

ISO27001 includes an Information Security Management System, and simply put is a set of processes that together help an organisation to manage their information security by assessing their risks and taking action to reduce them. The other part of ISO27001 involves the reference controls contained in Annex A. This is a set of good-practice ideas that you can use to make your organisation more secure, and they’re organised into 4 groups covering organisational, people, physical and technological controls."

Choosing the right solution

Amy and her team found the unlimited email support that comes with the ISO27001 toolkit package very useful. “The email support was key at the beginning, we could email a question and get a response back the next day, even with the time difference.” 

The toolkit package also comes with an expert review of up to three documents. CertiKit’s consultants provided detailed feedback on ISMS-FORM-06-3: Scenario Based Risk Assessment and Treatment and ISMS-DOC-04-1: Information Security Context, Requirements and Scope, as well as detailed information on Annex A and explained the importance of ISMS-DOC-A08-3: Information Labelling Procedure to the team. This ensured that Focused Fitness knew they were on the right track before their audit.

Success!

Focused Fitness became certified in just months with the help of our ISO27001 toolkit and the expert advice from our consultancy team.

Amy explains, “It took us eight months to get certified. We started researching auditors and the standard at the beginning of January, and we were certified at the end of August. We dedicated time to work on this on a weekly basis so we could move the process forward. Our auditor said our documentation was very thorough and the CertiKit toolkit was key to passing our audit. Thank you for your support whenever we had questions. It was greatly appreciated as we tried to figure out this process.”  

Congratulations to all involved.

“Our auditor said our documentation was very thorough and the CertiKit toolkit was key to passing our certification audit. Thank you for your support whenever we had questions. It was greatly appreciated as we tried to figure out this process.”

Focused Fitness, USA

Reviewing ISO 27001 Toolkit

resources

Browse more customer stories

  • Saphetor SA shares how they benefited from an ISO27001 Document Toolkit and a Pre-certification Internal Audit from CertiKit.

    Read more
  • MindCraft shares how the CertiKit ISO 27001 Toolkit helped them successfully implement the ISO 27001 standard.

    Read more
  • Blue Phoenix Systems, an IT and cyber security services organisation based in Australia, use CertiKit toolkits with clients to help implement the ISO27001 standard.

    Read more
  • “The consistent formatting and style of the documents makes consolidation of various ISMS and Annex A documents very easy to achieve, reducing the overall size and complexity of the ISMS.”

    Blue Phoenix Systems, Australia

  • “It makes a big difference, for the better, when the implementer does not need to second guess and double check every template and guidance document.”

    DotSec, Australia

  • “The CertiKit toolkit was chosen because of the clear, informative writing style, ease-of-use customisable templates and unlimited email support.”

    Epiphany Healthcare, USA

  • “Using the toolkit we were able to systematically pick through and deliver all of the documentation and process areas we needed, picking up the toolkit updates as we continued through the year. We have no doubt that using the toolkit decreased the time we spent during this initial phase and still supports part of the compliance work we do every year.”

    Fishawack Health, Worldwide

  • “Our auditor said our documentation was very thorough and the CertiKit toolkit was key to passing our certification audit. Thank you for your support whenever we had questions. It was greatly appreciated as we tried to figure out this process.”

    Focused Fitness, USA