Gap Assessment
ISO 27001:2022 Gap Assessment
Answer 22 questions to receive a scored readiness report against all 7 mandatory clauses.
Clause 4 — Context
Q1Has the organisation formally documented the internal and external issues relevant to its ISMS scope?
Q2Have interested parties been identified and their information security requirements documented?
Q3Is the ISMS scope formally documented and approved by leadership?
Clause 5 — Leadership
Q4Has top management approved and communicated an information security policy?
Q5Are information security roles and responsibilities formally assigned and understood by staff?
Clause 6 — Planning
Q6Has a formal risk assessment been performed using a documented methodology?★ High weight
Q7Has a risk treatment plan been developed and reviewed by management?★ High weight
Q8Has a Statement of Applicability (SoA) been produced covering all 93 Annex A controls?★ High weight
Q9Are measurable information security objectives defined at relevant functions and levels?
Clause 7 — Support
Q10Do staff receive regular information security awareness training?
Q11Are required ISMS documents controlled, versioned, and accessible to relevant personnel?
Q12Are adequate resources (budget, personnel, tools) allocated to the ISMS?
Clause 8 — Operation
Q13Are operational processes for implementing risk treatments documented and followed?
Q14Is a risk reassessment performed when significant changes occur?
Clause 9 — Performance
Q15Are key information security metrics monitored and reported to management regularly?
Q16Has an internal ISMS audit been conducted within the last 12 months?★ High weight
Q17Has top management conducted a formal ISMS management review within the last 12 months?★ High weight
Clause 10 — Improvement
Q18Are nonconformities formally logged, root-caused, and corrective actions tracked to closure?
Q19Is there a continual improvement process that demonstrates year-on-year ISMS maturity growth?
Annex A Controls
Q20Are critical Annex A controls (access control, malware protection, logging, backup, patch management) demonstrably implemented?★ High weight
Q21Is there documented evidence of controls being tested and verified (not just claimed to be in place)?★ High weight
Q22Is supplier/third-party information security risk managed with contracts and periodic reviews?
Answer all 22 questions to submit