ISO 27001 GAP Analysis
Actually, identify the distance to the standard requirements, missing evidence and implementation priorities.
View the ISO 27001 GAP analysis →
ISO 27001 and ISMS
Use ISO 27001 as a risk-driven information security management system. This overview helps you choose between a GAP analysis, guidance and internal audit and brings together the most important knowledge about an operating ISMS.
Risk-driven management system
ISO/IEC 27001 describes requirements for an Information Security Management System. This will organise scope, risk analysis, policies, roles, measures, internal review, management review and continuous improvement as a coherent whole. The value is in the daily operation and the ability to support choices and execution.
ISO 27001 services
Diagnosis, implementation guidance and independent internal audit each have their own purpose. Choose on the basis of the question that management, certifying institution or organisation wants answered.
Actually, identify the distance to the standard requirements, missing evidence and implementation priorities.
View the ISO 27001 GAP analysis →Build or improve ISMS with clear scope, risks, ownership, controls and a working improvement cycle.
View ISO 27001 guidance →Key design, existence and operation before findings are revealed in an external audit or certification.
View the internal audit →GAP analysis, guidance or internal audit?
Identify the services, processes, locations, systems and stakeholders within the ISMS.
Connect information security risks to appropriate controls, ownership and evidence intended.
Perform processes, register deviations and use management information to adjust.
Test independently, conduct management reviews and incorporate findings into the improvement cycle.
Management system above snapshot
A strong ISMS helps the organisation manage risk, build evidence of functioning and improve permanently. Certification can follow, but does not replace ownership, decision-making and day-to-day management that effectively ensures information security.
6 articles
Explanation and tools for scope, risks, controls, audits, certification and demonstrable operation.
Official source
The official ISO/IEC 27001 standard contains the standard requirements. Public explanations and checklists help guide, but do not replace the standard text and a review of its own scope.
View ISO/IEC 27001 at ISO →Please submit your current ISMS, audit planning and desired security. Then we determine whether a GAP analysis, guidance or internal audit is the best fit.
Schedule an introductory call →Frequently Asked Questions
An ISMS is the management system that controls information security. ISO 27001 contains requirements for testing and certification of such a management system.
No. Certification is a choice or contractual requirement. Even without a certification purpose, ISO 27001 can be a useful framework for organising information security risk-driven and demonstrable.
A GAP analysis fits when you need a factual starting point: What requirements have already been met, where is evidence lacking and what improvements are priority?
An internal audit provides independent insight into compliance and operation, supports the management review and is a mandatory part of the ISO 27001 cycle.

An ISMS has value when it can be used to control management and the organisation can show that important measures work over time.