Gap Assessment

ISO 27001:2022 Gap Assessment

Answer 22 questions to receive a scored readiness report against all 7 mandatory clauses.

0/22 answered0% complete

Clause 4 — Context

Q1Has the organisation formally documented the internal and external issues relevant to its ISMS scope?

Q2Have interested parties been identified and their information security requirements documented?

Q3Is the ISMS scope formally documented and approved by leadership?

Clause 5 — Leadership

Q4Has top management approved and communicated an information security policy?

Q5Are information security roles and responsibilities formally assigned and understood by staff?

Clause 6 — Planning

Q6Has a formal risk assessment been performed using a documented methodology?★ High weight

Q7Has a risk treatment plan been developed and reviewed by management?★ High weight

Q8Has a Statement of Applicability (SoA) been produced covering all 93 Annex A controls?★ High weight

Q9Are measurable information security objectives defined at relevant functions and levels?

Clause 7 — Support

Q10Do staff receive regular information security awareness training?

Q11Are required ISMS documents controlled, versioned, and accessible to relevant personnel?

Q12Are adequate resources (budget, personnel, tools) allocated to the ISMS?

Clause 8 — Operation

Q13Are operational processes for implementing risk treatments documented and followed?

Q14Is a risk reassessment performed when significant changes occur?

Clause 9 — Performance

Q15Are key information security metrics monitored and reported to management regularly?

Q16Has an internal ISMS audit been conducted within the last 12 months?★ High weight

Q17Has top management conducted a formal ISMS management review within the last 12 months?★ High weight

Clause 10 — Improvement

Q18Are nonconformities formally logged, root-caused, and corrective actions tracked to closure?

Q19Is there a continual improvement process that demonstrates year-on-year ISMS maturity growth?

Annex A Controls

Q20Are critical Annex A controls (access control, malware protection, logging, backup, patch management) demonstrably implemented?★ High weight

Q21Is there documented evidence of controls being tested and verified (not just claimed to be in place)?★ High weight

Q22Is supplier/third-party information security risk managed with contracts and periodic reviews?

Answer all 22 questions to submit