◆ traztech
ISO 27001 Gap Checklist
A starting gap checklist against the ISO/IEC 27001 ISMS requirements and Annex A control themes.
ISO 27001 certifies an information security management system (ISMS), issued by an accredited body. This checklist is a readiness starting point, not the Statement of Applicability.
ISMS foundation (clauses 4-10)
- Defined ISMS scope and context
- Leadership commitment and an information security policy
- Risk assessment and risk treatment methodology
- Statement of Applicability drafted
- Internal audit and management review planned
Organizational controls (Annex A)
- Information security roles and responsibilities defined
- Supplier and cloud service security addressed
- Threat intelligence and incident management process
- Data classification and handling
People & physical controls
- Screening, onboarding, and awareness training
- Remote working and clear-desk policies
- Physical and environmental controls where relevant
Technological controls
- Access control, MFA, and privileged access management
- Cryptography and key management
- Logging, monitoring, and vulnerability management
- Secure development and change management
- Backup, redundancy, and business continuity