ISO 27001 Gap Analysis Guide
Budget: £5 – £10 GBP
I’m ready to kick-off our organisation’s journey toward ISO 27001 certification, starting with a clean slate. My immediate need is a comprehensive initial gap analysis that benchmarks every clause and Annex A control against our current practices, followed by solid risk identification and assessment.
You will lead focused discovery sessions, extract the necessary information from line-of-business owners, and translate it into a clear picture of where we meet—or miss—ISO 27001:2022 requirements. Because we have zero existing policies or prior assessments, you’ll be building the baseline documentation from scratch and making sure it is audit-ready.
Deliverables
• Gap analysis matrix mapped to each ISO 27001 requirement
• Executive summary with key deficiencies and a prioritised remediation roadmap
• Risk register detailing assets, threats, vulnerabilities, and scored impact/likelihood, plus a heat map
• Recorded walk-through meeting so my team fully understands findings and next steps
Acceptance criteria: every document must follow ISO 27001:2022 terminology, be editable (Word, Excel, or PowerPoint), and stand up to an external Stage-1 audit review.
When you reply, outline your methodology, comparable engagements, and the timeline you’d follow to reach these deliverables.
You will lead focused discovery sessions, extract the necessary information from line-of-business owners, and translate it into a clear picture of where we meet—or miss—ISO 27001:2022 requirements. Because we have zero existing policies or prior assessments, you’ll be building the baseline documentation from scratch and making sure it is audit-ready.
Deliverables
• Gap analysis matrix mapped to each ISO 27001 requirement
• Executive summary with key deficiencies and a prioritised remediation roadmap
• Risk register detailing assets, threats, vulnerabilities, and scored impact/likelihood, plus a heat map
• Recorded walk-through meeting so my team fully understands findings and next steps
Acceptance criteria: every document must follow ISO 27001:2022 terminology, be editable (Word, Excel, or PowerPoint), and stand up to an external Stage-1 audit review.
When you reply, outline your methodology, comparable engagements, and the timeline you’d follow to reach these deliverables.
Related categories:
Project Management
Training
Audit
Compliance
Risk Management
Documentation
Risk Assessment
Data Protection