ISO 27001
ISO 27001 Gap Assessment
Cycore's 115-prompt ISO 27001 self-assessment. Score each prompt 0 to 3, record the evidence and the owner, and find your gaps before you talk to an auditor.
We built this gap assessment for teams preparing for an ISO 27001 audit, or tightening an information security management system they already run. It's a Cycore self-assessment based on ISO/IEC 27001:2022. Work through it with the people who own each area, and you'll have a list of gaps with a name next to each one before you talk to an auditor.
What's inside
Seven clause sections, 115 prompts:
- Clause 4, Context of the organization (16)
- Clause 5, Leadership (18)
- Clause 6, Planning (20)
- Clause 7, Support (19)
- Clause 8, Operation (10)
- Clause 9, Performance evaluation (23)
- Clause 10, Improvement (9)
Every prompt scores 0 to 3, so the 115 prompts make a maximum of 345, with space to write in the evidence and the owner. After the scored sections there's an unscored sample of 38 of the 93 Annex A reference controls, each with the gap we commonly find.
How to use it
Score each prompt, add up each clause, and total out of 345. The score is a Cycore planning signal. It isn't a certification status, and it doesn't predict how long the work will take. Give every prompt under 3 an owner and a date, and carry them back into your GRC platform if you run one. The Annex A sample isn't scored. Use it to check your own control set, then compare against the full Annex A.
Download the PDF and work through it with your team.
proof of work
Read the case study