ISO 27001 practical guide
ISO 27001 Gap Analysis
An ISO 27001 gap analysis compares current arrangements with defined criteria, tests available evidence and records prioritized actions. It is most useful early in implementation or after significant change. The result is not a certification decision; it is a practical baseline for planning work and risk.
- Search intent
- Understand and perform a concise implementation-focused ISO 27001 gap analysis.
- Guide area
- Implementation
- Review status
- Practitioner reviewed
What this means in practice
This topic page explains the assessment task and connects to the detailed editorial guide. The existing gap-analysis guide provides the deeper planning walkthrough, while the readiness checker provides an indicative browser-based baseline.
Classify gaps consistently and distinguish missing design, incomplete implementation, weak coverage and ineffective operation. These conditions require different actions.
Step-by-step implementation
- Step 1. Define scope, objectives, criteria and assessment boundaries.
- Step 2. Collect core context, risk, treatment, policy and assurance information.
- Step 3. Interview process owners and inspect representative records.
- Step 4. Assess Clauses 4–10 and relevant Annex A control arrangements.
- Step 5. Record evidence, current condition, gap and practical consequence.
- Step 6. Prioritize using risk, dependencies and implementation effort.
- Step 7. Assign actions, owners, target sequencing and validation method.
What to prepare
- licensed standard and applicable criteria
- current ISMS scope and process owners
- risk and treatment records
- policies, procedures and operating samples
- prior audit, incident and improvement records
Documents, records and evidence
| Area or field | Example | Why it matters |
|---|---|---|
| Gap type | Design missing | No defined method or responsibility |
| Gap type | Partially implemented | Design exists but coverage is incomplete |
| Gap type | Operating weakness | Process runs inconsistently or records are missing |
| Gap type | Effectiveness weakness | Process operates but intended result is not achieved |
| Action priority | Risk and dependency informed | Not simply clause-number order |
From finding to action
Finding: access reviews occur for the finance system but not cloud administration. Evidence identifies the reviewed population and missing platform. Action: extend the identity inventory, assign the cloud owner, complete an initial review and verify recurring coverage through the next reporting cycle.
What an auditor will look for
- Defined criteria and honest scope.
- Evidence references supporting each conclusion.
- Representative interviews and samples.
- Actions aligned to risk and verified after implementation.
An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.
Common mistakes
- Scoring without recording evidence or rationale.
- Treating every partial answer as the same severity.
- Reviewing policy documents without operational samples.
- Producing a long finding list with no dependencies or ownership.
Practical checklist
- □ Assessment scope and criteria are explicit.
- □ Owners and authoritative evidence sources are identified.
- □ Samples cover design, operation and effectiveness.
- □ Findings distinguish different gap types.
- □ Actions have owners, priorities and validation methods.
Frequently asked questions
Is a gap analysis required by ISO 27001?
A gap analysis is a useful implementation technique, not a named mandatory process.
Is it the same as an internal audit?
No. Internal audit is a planned objective assurance process within the ISMS; gap analysis commonly supports implementation planning.
Can the readiness checker replace professional assessment?
No. It provides an indicative baseline and downloadable report, not certification or assurance.
Continue through the practical guide library
Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.