Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud.
We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
1) At the moment there’s more than 6000 ISO 27001 certified organisations worldwide. Organisation which is ISO 27001 certified tends to do business with other organisations that are certified. Lack of ISO 27001 certificate may be just the thing that drags you down. In many cases, if your company is not ISO 27001 certified, then as a supplier you wont even get a chance to bid. Just ask japanese ICT service providers. If other vendors are certified, then you have to get certified as well if you want to survive.
2) ISO 27001 certificate is a powerful marketing weapon. It makes difference to informed clients whether you’re certified or not. It produces confidence that client’s personal and other information will be (is) adequately protected. It’s a fear killer.
3) Microsoft values ISO 27001. You have to respect that such a gigantic company wants ISO 27001 certificate. That means that ISO 27001 is already mainstream. It’s a must have. They said that in order to create confidence (read: sell) in new (risky?) services, you should get them ISO 27001 certified. The fact that there is no other standard that Microsoft considers for it’s cloud services (speaking of certification) means a great deal.
4) Since you’ve worked so hard on implementation of your security programm, then it would be a waste to not get an applause for your efforts. Many regulatory / legal requirements (in many countries) are copy-pasted from ISO 27001. Many organisations could get ISO 27001 certificate with minimal efforts, because they already are very much compliant with the standard (whether or not they know it).
5) ISO 27001 is THE ultimate and in-practice-proved-to-work framework for managing information security. You CAN NOT go wrong if you want to manage your ISMS according to ISO 27001.