ISO/IEC 27001:2022 הוא תקן למערכת ניהול אבטחת מידע, לא אוסף מסמכים ולא בדיקת חדירה. הוא דורש מהארגון להגדיר היקף, לנהל סיכונים, לבחור בקרות, להפעיל אותן ולהציג ראיות שהמערכת עובדת.
Art of Cyber מלווה חברות בישראל מהבדיקה הראשונה ועד מוכנות לביקורת ההסמכה. בוריס פוסטילניק ליווה מעל 30 הסמכות ISO 27001. העבודה ישירה ומעשית: בונים רק מה שנדרש לארגון, מחברים כל מסמך לפעילות אמיתית ולא משאירים את הצוות לבד מול המבקר.
למי הליווי מתאים?
- חברת SaaS שנדרשת להסמכה על ידי לקוח או משקיע
- פינטק, מדטק או חברה שמטפלת במידע רגיש
- ארגון שניגש למכרז או לעסקה עם דרישות אבטחה
- חברה שגדלה וצריכה מערכת ניהול מסודרת
- ארגון שכבר התחיל לבד אבל המסמכים, הראיות והבקרות לא מתחברים
- חברה מוסמכת שמתכוננת לביקורת מעקב או למעבר לגרסת 2022
מה כולל תהליך ISO/IEC 27001?
1. הגדרת היקף ה-ISMS
מחליטים אילו שירותים, צוותים, מיקומים ומערכות נכללים. היקף רחב מדי מייצר עבודה מיותרת; היקף צר מדי לא עומד בצורך העסקי.
2. סקר פערים
בודקים את המצב מול דרישות התקן ומול Annex A. התוצר הוא תוכנית עבודה, לא רק רשימת אי-התאמות.
3. הערכת סיכונים
מזהים נכסים, איומים, חולשות והשפעה עסקית. קובעים טיפול, בעלים ולוחות זמנים. הסיכון מנהל את הבקרות, לא להפך.
4. Statement of Applicability
מתעדים אילו בקרות חלות, למה הן נבחרו, מה לא חל ומה מצב ההטמעה. זה מסמך מרכזי שהמבקר בוחן מול המציאות.
5. מדיניות ותהליכים
בונים או מתקנים את מה שהארגון באמת צריך: ניהול גישה, ספקים, אירועים, המשכיות, גיבוי, שינויים, עובדים, נכסים, פיתוח מאובטח ועוד.
6. הטמעה ואיסוף ראיות
הסמכה לא מתקבלת על ניסוח יפה. צריך ראיות: אישורים, לוגים, סקרי ספקים, תרגילים, הדרכות, ביקורות ומעקב אחרי משימות.
7. ביקורת פנימית וסקר הנהלה
לפני ביקורת ההסמכה בודקים שהמערכת עובדת, מטפלים בפערים ומכינים את ההנהלה והצוותים לשאלות.
8. ליווי בביקורת
מלווים את שלב 1 ושלב 2, מסייעים להציג ראיות ולטפל באי-התאמות אם עולות.
מה מקבלים?
בהתאם להיקף:
- דוח פערים ותוכנית עבודה
- מסמך היקף ISMS
- מתודולוגיית סיכונים ומרשם סיכונים
- תוכנית טיפול בסיכונים
- Statement of Applicability
- מדיניות ונהלים מותאמים
- תוכנית מודעות והדרכה
- תהליך ניהול ספקים ואירועים
- מדדים ודיווח להנהלה
- ביקורת פנימית וסקר הנהלה
- תיק ראיות לביקורת
- הכנה וליווי מול גוף ההתעדה
כמה זמן לוקח לקבל הסמכה?
אין לוח זמנים אחיד. חברה קטנה עם היקף ברור וצוות זמין יכולה להתקדם מהר יותר מארגון עם הרבה מערכות, ספקים וחברות בקבוצה. גם נקודת הפתיחה קובעת: מי שכבר מנהל סיכונים, הרשאות וספקים צריך בעיקר לסדר ולהוכיח; מי שמתחיל מאפס צריך גם להטמיע.
אחרי סקר פערים קצר אפשר לתת לוח זמנים אמין. הבטחה להסמכה תוך מספר קבוע של שבועות בלי לבדוק את הארגון אינה רצינית.
כמה עולה ליווי ISO 27001?
המחיר נקבע לפי:
- היקף ההסמכה ומספר הישויות
- מספר המערכות, האתרים והספקים
- רמת הבשלות הקיימת
- כמות המדיניות והבקרות שצריך לבנות או לתקן
- זמינות הצוות הפנימי
- מידת הליווי הנדרשת מול גוף ההתעדה
אפשר להתחיל בסקר פערים במחיר קבוע, להמשיך לפרויקט מלא עם תוצרים ולוחות זמנים, או לעבוד במודל משולב עם ליווי חודשי לאחר ההסמכה.
עלות גוף ההתעדה היא נפרדת ומשולמת לגוף ההתעדה. Art of Cyber מכינה ומלווה את הארגון, אך אינה הגוף שמעניק את התעודה.
למה Art of Cyber?
- ניסיון מעשי בליווי מעל 30 הסמכות ISO 27001
- עבודה ישירה עם CISO בכיר, לא העברה אוטומטית ליועץ זוטר
- חיבור בין התקן, הסיכון העסקי והמערכות בפועל
- מסמכים מותאמים לארגון ולא חבילת תבניות גנרית
- ליווי גם אחרי כתיבת המסמכים: הטמעה, ראיות, ביקורת וטיפול בפערים
השורה התחתונה
הסמכת ISO/IEC 27001 צריכה לעזור לעסק לעבור ביקורת, אבל גם להשאיר אחריה מערכת ניהול שאפשר להפעיל. אם המסמכים לא משקפים את המציאות, הבעיה תחזור בביקורת הבאה.
השאירו פרטים לשיחת מיפוי. נגדיר היקף, נבדוק את נקודת הפתיחה ונציע את הדרך הקצרה והנכונה להסמכה.
שאלות נפוצות
האם ISO 27001 מחייב את כל בקרות Annex A?
לא אוטומטית. הארגון בוחר בקרות לפי הערכת הסיכונים, דרישות חוקיות, חוזיות ועסקיות, ומנמק את ההחלטות ב-Statement of Applicability.
מי נותן את התעודה?
גוף התעדה עצמאי מבצע את הביקורת ומעניק את התעודה. Art of Cyber מכינה את הארגון, מלווה את ההטמעה ומסייעת במהלך הביקורת.
האם אפשר לקנות רק מסמכים?
מסמכים לבדם אינם מספיקים להסמכה. התקן דורש תהליכים פעילים וראיות. אפשר להשתמש בתבניות כנקודת פתיחה, אבל צריך להתאים ולהטמיע אותן.
מה קורה אחרי ההסמכה?
ממשיכים לנהל סיכונים, מדדים, אירועים, ספקים, הדרכות וביקורות. גוף ההתעדה מבצע ביקורות מעקב, וה-ISMS צריך להשתפר לאורך זמן.
ISO/IEC 27001:2022 is a standard for an information security management system. It is not a document pack or a penetration test. Companies must define scope, manage risk, select and operate controls, and provide evidence that the system works.
Art of Cyber supports companies in Israel from the first assessment to certification-audit readiness. Boris Pustilnik has supported more than 30 ISO 27001 certifications. The work is direct and practical: build only what the organization needs, connect every document to real activity, and do not leave the team alone in front of the auditor.
Who is it for?
- A SaaS company required to certify by a customer or investor
- Fintech, medtech or any company handling sensitive data
- An organization entering a tender or a deal with security requirements
- A company that grew and needs an orderly management system
- An organization that started alone but whose documents, evidence and controls do not connect
- A certified company preparing for a surveillance audit or the move to the 2022 version
What does the process include?
1. ISMS scope definition
Decide which services, teams, locations and systems are included. A scope that is too wide creates unnecessary work; too narrow misses the business need.
2. Gap assessment
Check the current state against the standard and Annex A. The output is a work plan, not just a nonconformity list.
3. Risk assessment
Identify assets, threats, weaknesses and business impact. Set treatment, owners and timelines. Risk drives the controls, not the other way around.
4. Statement of Applicability
Document which controls apply, why they were chosen, what does not apply and the implementation status. Auditors test this document against reality.
5. Policies and processes
Build or fix what the organization actually needs: access management, vendors, incidents, continuity, backup, change management, employees, assets, secure development and more.
6. Implementation and evidence
Certification is not granted on nice wording. You need evidence: approvals, logs, vendor reviews, exercises, training, audits and task tracking.
7. Internal audit and management review
Before the certification audit, check the system works, fix gaps and prepare leadership and teams for questions.
8. Audit support
We accompany Stage 1 and Stage 2, help present evidence and handle nonconformities if they come up.
What do you get?
Depending on scope:
- Gap report and work plan
- ISMS scope document
- Risk methodology and risk register
- Risk treatment plan
- Statement of Applicability
- Tailored policies and procedures
- Awareness and training plan
- Vendor and incident management processes
- Metrics and management reporting
- Internal audit and management review
- An evidence pack for the audit
- Preparation and support with the certification body
How long does certification take?
There is no single timeline. A small company with a clear scope and an available team can move faster than an organization with many systems, vendors and group entities. The starting point also matters: an organization already managing risk, permissions and vendors mainly needs to organize and prove; one starting from zero also needs to implement.
After a short gap assessment we can give a reliable timeline. A promise of certification in a fixed number of weeks without examining the organization is not serious.
How much does ISO 27001 support cost?
Price is set by:
- Certification scope and number of entities
- Number of systems, sites and vendors
- Current maturity
- How much policy and control work needs building or fixing
- Internal team availability
- The level of support needed with the certification body
You can start with a fixed-price gap assessment, continue to a full project with deliverables and timelines, or work in a combined model with monthly support after certification. Certification-body fees are separate and paid to the certification body. Art of Cyber prepares and supports the organization; it is not the body issuing the certificate.
Why Art of Cyber?
- Hands-on experience supporting more than 30 ISO 27001 certifications
- Direct work with a senior CISO, not an automatic handoff to a junior consultant
- A connection between the standard, business risk and the systems in place
- Documents fitted to the organization, not a generic template pack
- Support past the writing stage: implementation, evidence, audit and gap closure
Bottom line
ISO/IEC 27001 certification should help the business pass the audit, but also leave behind a management system that actually runs. If the documents do not reflect reality, the problem returns at the next audit.
Book a scoping call and we will come back with a precise proposal.