< Back to case studies

Customer stories
SupplierGATEWAY

SupplierGATEWAY is a SaaS supplier management and procurement platform based in California, USA. The company helps buyers and suppliers manage their relationships through integrated tools and powerful cloud-based services. Forina Vong, Network Infrastructure and Security Manager explains how the ongoing support from CertiKit assists with the timely development of their Information Security Management System (ISMS).

Reason for certification

SupplierGATEWAY chose to certify to ISO27001 to streamline their ISMS and stay competitive within their industry. It was increasingly important as a cloud service provider to ensure all requirements were complied with, including the relevant parts of the ISO27017 (controls for cloud service providers) and ISO27018 (controls for protection of personally identifiable information) codes of practice.

Finding the right solution

The biggest challenge SupplierGATEWAY faced from the beginning was the lack of ISO27001 knowledge internally. The standard itself is substantial and includes the Annex A controls. The requirements within ISO27001 are in-depth and implementation can be difficult with no prior knowledge.

Forina found that, with colleagues available to take on the project, a toolkit was the best solution for their business. “The great reviews from the website made us choose a CertiKit toolkit. The comprehensive documentation and great support helped make achieving certification easier.”  The fact that the toolkit documents contain additional content relevant to cloud service providers was particularly helpful, including in documents such as ISMS-DOC-A05-3: Cloud Computing Policy and ISMS-DOC-A05-4: Cloud Service Specifications."

The process

The SupplierGATEWAY team took just over a year to certify to the standard, whilst dedicating 10-15 hours per week to the project. The team chose to use the toolkit solely as guidance and didn’t need to call on external consultants for help. Instead, the team made excellent use of the unlimited email support available from CertiKit, describing this assistance as the most useful aspect of the package.

Taking on the implementation of the standard internally proved beneficial to the business, Forina explains, “We discovered opportunities for improvement in the way we are running our ISMS. We now find it much easier to provide our prospective clients with our security documentation during the sales process.”

Success!

With an increased internal knowledge, an ISO27001 certification and a continually improving ISMS, the team couldn’t be happier with the outcome. “We would definitely recommend the CertiKit toolkit to another company” said Forina. For now, the SupplierGATEWAY team are currently working through the new documents released in the latest update of the ISO27001 toolkit to continually improve their ISMS ready for their next annual audit.

“The great reviews from the website made us choose a CertiKit toolkit. The comprehensive documentation and great support helped make achieving certification easier.”

SupplierGATEWAY, USA

Reviewing ISO 27001 Toolkit

resources

Browse more customer stories

  • Saphetor SA shares how they benefited from an ISO27001 Document Toolkit and a Pre-certification Internal Audit from CertiKit.

    Read more
  • MindCraft shares how the CertiKit ISO 27001 Toolkit helped them successfully implement the ISO 27001 standard.

    Read more
  • Blue Phoenix Systems, an IT and cyber security services organisation based in Australia, use CertiKit toolkits with clients to help implement the ISO27001 standard.

    Read more
  • “The consistent formatting and style of the documents makes consolidation of various ISMS and Annex A documents very easy to achieve, reducing the overall size and complexity of the ISMS.”

    Blue Phoenix Systems, Australia

  • “It makes a big difference, for the better, when the implementer does not need to second guess and double check every template and guidance document.”

    DotSec, Australia

  • “The CertiKit toolkit was chosen because of the clear, informative writing style, ease-of-use customisable templates and unlimited email support.”

    Epiphany Healthcare, USA

  • “Using the toolkit we were able to systematically pick through and deliver all of the documentation and process areas we needed, picking up the toolkit updates as we continued through the year. We have no doubt that using the toolkit decreased the time we spent during this initial phase and still supports part of the compliance work we do every year.”

    Fishawack Health, Worldwide

  • “Our auditor said our documentation was very thorough and the CertiKit toolkit was key to passing our certification audit. Thank you for your support whenever we had questions. It was greatly appreciated as we tried to figure out this process.”

    Focused Fitness, USA