ISO 27001 Gap Analysis

SELF ASSESSMENT

ISO 27001:2022

--%
Awaiting input...
Context of the organization
This section covers the foundational context and scope of your ISMS.

1. Have you determined the external and internal issues that are relevant to your organization’s purpose that affects your ability to achieve the intended results of your Information Security Management System (ISMS)?

2. Have you determined the needs and expectations of interested parties that are relevant to the ISMS and do you review these on a regular basis?

3. Have you determined the scope of your ISMS and did this take into account the external and internal issues, interested parties, and any activities performed by other organizations?

4. Has the internal and external issues that may impact the ISMS been considered?

5. Have the risks and opportunities associated with these issues and requirements been considered?

6. Are you aware of the requirements of interested parties, including regulatory, statutory and those of your customers?

7. Have you determined which of the requirements of interested parties will be addressed through the information security management system?

8. Has continual improvement been considered?

9. Have the processes needed to establish, maintain, implement and establish the information security management systems and their interactions been determined and implemented?

Leadership
This section evaluates management's commitment, policies, and allocation of roles.

1. Are the information security policy and objectives that have been established compatible with the context and strategic direction of the organization?

2. Has the information security policy been communicated within the organization and to interested parties?

3. Does the policy include information security objectives or provides the framework for setting information security objectives

4. Are the roles within the ISMS clearly defined, annotated and communicated?

5. Do the roles carry the authority for ensuring conformance and reporting, as well as the responsibility?

6. Has a programme to ensure the ISMS achieves its outcomes, requirements and objectives been developed and put in place?

7. Have you communicated the importance of effective information security management and of conforming to the information security management system requirements?

Planning
This section addresses risk assessment and information security objectives.

1. Have the risks and opportunities identified in the interested parties and scope been addressed to ensure the ISMS can achieve its intended result(s) been established?

2. Has an information security risk assessment process been established to include risk acceptance criteria?

3. Has the information security risk assessment process been defined and developed to be repeatable and ensure consistent, valid and comparable results?

4. Does the risk assessment produce consistent, valid and comparable results?

5. Has the organization planned actions to address these risks and opportunities and determined how to integrate and implement them into the ISMS, and how to evaluate the effectiveness of these actions?

6. Is the information security risk assessment process sufficient to identify risks associated with loss of confidentiality, integrity and availability for information within the scope of the ISMS?

7. Have risk owners been identified?

8. Are information security risks analyzed to assess the realistic likelihood and potential consequences that would result, if they were to occur, and have the levels of risk been determined?

9. Are information security risks compared to the established risk criteria and prioritized?

10. Has information about the information security risk assessment process been documented?

11. Have appropriate risk treatment options been determined and implemented?

12. Have controls been determined to implement the risk treatment option chosen?

13. Have the controls determined, been compared with ISO/IEC 27001:2022 Annex A to verify that no necessary controls have been missed?

14. Is there a Statement of Applicability with revision history in accordance with ISO 27001:2022?

15. Does the Statement of Applicability include whether the necessary controls are implemented or not?

16. Does the Statement of Applicability include justification for the selection or exclusion of controls from Annex A?

17. Has an information security risk treatment plan been created?

17.1 Have risk owners reviewed and approved the plan?

17.2 Have residual information security risks been authorized by risk owners?

17.3 Has it been documented?

18. Have measurable ISMS objectives been established, documented and communicated throughout the organization?

19. In setting its objectives, has the organization determined what needs to be done, when and by whom?

20. Have you determined and documented how the objectives are to be monitored?

21. While planning for change in ISMS have you determined the need for changes to ISMS, and how the changes are to be carried out in a planned manner?

Support
This section covers resources, competence, awareness, and documentation.

1. Have you determined and provided the resources needed to establish, implement, maintain and continually improve the ISMS (including people, infrastructure and environment for the operation of processes)?

2. Have you determined the competence necessary for those performing ISMS roles? (e.g risk owners, internal auditors, etc.)

3. Is there evidence of competence for these roles?

4. Have you ensured that persons doing work under the organization’s control are:
i) aware of the ISMS policy
ii) how their contribution to the effectiveness of the information security management system, including the benefits of improved information security performance.
iii) the implications of not conforming with the information security management system requirements. (e.g disciplinary actions)?

5. Has the documented information required by the standard and necessary for the effective implementation and operation of the ISMS been established?

6. Has the organisation determined what internal and external communications may be relevant?

7. Is the documented information controlled in a way that it is available and adequately protected, distributed, stored, retained and under change control, including documents of external origin required by the organization for the ISMS?

Operations
This section relates to the execution of plans and processes.

1. Have you implemented or are implementing the actions determined in Clause 6, by establishing criteria for the processes and implementing control of the processes in accordance with the criteria?

2. Has documented evidence been kept to show that processes have been carried out as planned?

3. Is there a plan to determine the need for changes to the ISMS and managing their implementation?

4. When changes are planned, are they carried out in a controlled way and actions taken to mitigate any adverse effects?

5. Are externally provided processes appropriately controlled and implemented?

6. Are information security risk assessments carried out at planned intervals or when significant changes occur, and is documented information retained?

7. Has the organization planned actions to address risks and opportunities and integrated them into the system processes?

8. Is there a process to retain documented information on the results of the information security risk assessment?

9. Is there a process to obtain approval for risk treatment and residual risk from the risk owners?

Performance evaluation
This section covers monitoring, measurement, and review of the ISMS.

1. Have you determined what needs to be monitored and measured, when, by whom, the methods to be used, and when the results will be evaluated?

2. Are the results of monitoring and measurement documented?

3. Does top management undertake regular and periodic reviews of the ISMS?

4. Can the auditors selected to conduct internal audits demonstrate objectivity and impartiality during the process?

5. Does the input to management review include changes in external and internal issues and changes in the needs of interested parties?

6. Has the organization established a program for internal audits to check that the ISMS is effective and conforms to the requirements of ISO/IEC 27001 and the organization’s own requirements?

7. Has feedback on information security performance been considered as an input to the management review?

8. Are results of these audits reported to management, documented, and retained?

9. Does the output from the ISMS management review identify changes and improvements?

10. Where nonconformities are identified, has the organization established appropriate processes for managing nonconformities and the related corrective actions?

11. Is documented information available to evidence the results of the management review?

Improvement
This final section covers nonconformity, corrective action, and continual improvement.

1. Have actions to control, correct and deal with the consequences of nonconformities been identified?

2. Has the need for action been evaluated to eliminate the root cause of nonconformities and to prevent reoccurrence?

3. Have any actions identified been implemented and reviewed for effectiveness and given rise to improvements to the ISMS?

4. Is documented information kept as evidence of the nature of non-conformities, actions taken and the results?

Congratulations!

You've completed the assessment. Your final score is:

--%

Download Your Full Report

Enter your details to receive a detailed PDF of your results.

Thank You!

Your report has been downloaded.

Log in

You dont have an account yet? Register Now