Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

ISMS Gap & Remediation Tracker

Converts readiness findings into an owned, dated remediation plan sequenced against the certification audit date.

Available soon

Format
Excel
Size
94 KB
Length
9 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Gap Register
  • Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Summary: set the as-at date (today's date, or =TODAY()), the planned Stage 1 and Stage 2 dates, the planned end of internal audit fieldwork and the management review date, and the number of requirements your readiness assessment covers. Replace every EXAMPLE value.
2Lists: replace the EXAMPLE owners with your own (column 'OwnerList'); the Owner column offers them.
3Gap Register: add one row for every requirement below Operating in the Certification Readiness Self-Assessment: its number (the title and blocker flag fill in), its readiness now (0, 1 or 2), the gap, the action, the owner and the weeks of work to put it in place. For a gap already In place, enter the date it went In place instead of weeks.
4Agree the start and due dates with each owner (IS-08: "Every gap must have an owner and a date, sequenced so that blockers close before the Stage 2 date."). Use the forecast columns as the starting point: they assume the owner works through their gaps one at a time, blockers first. Column 'Due fits Stage 2?' says No when an agreed due date is later than the latest date the Stage 2 plan allows.
5Update the tracker at least monthly (IS-10): status, weeks of work still left (reduce column J as work is done), readiness now, and the In place date once reached. Set the status to 'In place' and readiness to 2 when the action is done; set 'Closed' with the date only when the requirement is Operating — 3 months of records an auditor could sample.
6Summary: read ISM-01 to ISM-04, the estimate and the owner workload. An overdue gap on the critical path is the first thing to raise with the executive sponsor. Nonconformities from the internal audit are corrective actions: record them here too, with the root cause in the Gap column (IS-09).
7To remove the EXAMPLE: delete the EXAMPLE rows (whole table rows), replace the EXAMPLE owners on the Lists sheet and the EXAMPLE settings on the Summary sheet. The formulas keep working.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Readiness now: 0 Not started — Nothing exists yet. 1 Planned — Owner and approach agreed; not yet in place. 2 In place — Documented and working, but little or no record yet. A requirement at Operating (Working, with records covering at least [[3]] months, and an auditor could sample it.) is not a gap.

Status: Not started; In progress; In place (the action is done, records are building up); Closed (Operating, with the date). Overdue: not Closed and the agreed due date is before the as-at date.

Forecast. For a gap at 0 or 1: the as-at date plus the weeks of work of the owner's gaps up to and including this one, blockers first, then in the standard's order. For a gap at 2: its In place date. Forecast Operating: the forecast In place date plus 3 months (IS-05).

Latest In place for Stage 2: a blocker must be In place 3 months before the planned Stage 2 date (IS-05: "The ISMS must run for at least [[3]] months, producing records, before the Stage 2 audit."), so it can be Operating by then; any other gap by the Stage 2 date itself.

The estimate (Summary sheet) is the latest of (a) every gap In place, (b) the last blocker In place plus 3 months (IS-05), and (c) the internal audit and management review done (IS-06: "At least one full internal audit cycle and one management review must be completed before Stage 2."), the audit programme's forecast In place plus 4 weeks or your planned dates if later. Float is how many weeks a gap can slip before that date moves; a gap with float of 2 weeks or less is on the critical path. Weeks are calendar weeks.

EXAMPLE: a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30. Stage 1 is booked for 2027-01-18 and Stage 2 for 2027-03-01. Gaps already at In place are listed after the blockers with their In place date; GAP-006 (A.5.19) shows an overdue gap.

Tailoring — small organisation: one owner may hold most gaps. The forecast then shows plainly how long one person needs; either accept the date or bring in help. Merge small related gaps into one row if it keeps the tracker readable, but never merge a blocker into another gap.

Tailoring — regulated entity: certification to ISO/IEC 27001:2022 is evidence for a supervisor, not compliance with NIS2 or DORA in itself. Keep regulatory findings in the same tracker with their own reference in the notes, so one list is managed; a supervisor may ask for it.

Tailoring — IT run by a service provider: name as owner the person in your organisation who manages the provider, and record the provider's commitment (ticket or change reference) in the notes. The provider's delivery date is not your due date until you have agreed it.

Gap Register

One row per requirement below Operating. Yellow columns are yours; the rest is calculated. Blockers first (IS-08).

RowGap IDRequirement (clause or control)Title (number and title only)Blocker?Readiness now (0–2)Gap — what is missingActionOwnerWeeks of work leftIn place since (readiness 2)Agreed startAgreed dueStatusClosed onForecast In placeForecast OperatingLatest In place for Stage 2Due fits Stage 2?Float (weeks)Critical path?Overdue?Days overdueEvidence, links and notesQueue order (working)Blocker In place (working)
EXAMPLEGAP-0019.3.3Management review resultsYes1No review held, so no recorded decisions.Confirm the date, attendees and minute-taker, and a template that records decisions and actions.Chief Operating Officer130 Sep 20267 Oct 2026Not started7 Oct 20267 Jan 20271 Dec 2026Yes5.0No287 Oct 2026
EXAMPLEGAP-0026.2Information security objectives and planning to achieve themYes1Objectives drafted but not approved; no measure, owner or date for each.Agree five to seven measurable objectives, each with an owner, a measure and a date; have top management approve them and communicate them.Head of Information Security314 Sep 202621 Oct 2026In progress21 Oct 202621 Jan 20271 Dec 2026Yes3.0No1121 Oct 2026
EXAMPLEGAP-0039.2.2Internal audit programmeYes1Internal audit not started: the programme is drafted but not approved, and the contracted auditors are not yet confirmed.Finish the audit programme so it covers every clause and the applicable controls before Stage 2, have the Chief Operating Officer approve it as sponsor, confirm the independent auditors (IS-07) and book the fieldwork.Head of Information Security121 Sep 202628 Oct 2026In progress28 Oct 202628 Jan 20271 Dec 2026Yes2.0Yes2528 Oct 2026
EXAMPLEGAP-00410.2Nonconformity and corrective actionYes1Corrective actions are raised only for incidents; no procedure for nonconformities, root cause or effectiveness checks.Approve a nonconformity and corrective action procedure (root cause, correction, corrective action, effectiveness check — IS-09) and start the log.Head of Information Security228 Oct 202611 Nov 2026Not started11 Nov 202611 Feb 20271 Dec 2026Yes0.0Yes3011 Nov 2026
EXAMPLEGAP-0056.1.3Information security risk treatmentYes2In place since 2026-08-24; records cover less than 3 months. Statement of Applicability and risk treatment plan approved on 2026-08-24; treatment is under way.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of Information Security024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Dec 2026Yes11.3No1024 Aug 2026
EXAMPLEGAP-006A.5.19Information security in supplier relationshipsNo1The Supplier Security Policy (P04 register SUP-001) is awaiting approval; supplier tiers not yet applied.Obtain approval of the Supplier Security Policy (P04 register SUP-001), publish it, and tier the existing suppliers, using the supplier-assessment templates in the P06 pack.Head of Procurement17 Sep 202625 Sep 2026In progress7 Oct 20267 Jan 20271 Mar 2027Yes18.1NoOverdue5EXAMPLE — started 2026-09-07; one week of work left at the as-at date.10049
EXAMPLEGAP-0076.1.1GeneralNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Head of Information Security06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10008
EXAMPLEGAP-0088.1Operational planning and controlNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Head of Information Security06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10020
EXAMPLEGAP-009A.5.6Contact with special interest groupsNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Head of Information Security06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10036
EXAMPLEGAP-010A.5.11Return of assetsNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.HR Director06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10041
EXAMPLEGAP-011A.5.27Learning from information security incidentsNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Head of Information Security06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10057
EXAMPLEGAP-012A.5.32Intellectual property rightsNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Legal Counsel06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10062
EXAMPLEGAP-013A.5.34Privacy and protection of PIINo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Legal Counsel06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10064
EXAMPLEGAP-014A.6.2Terms and conditions of employmentNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.HR Director06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10069
EXAMPLEGAP-015A.6.6Confidentiality or non-disclosure agreementsNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.HR Director06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10073
EXAMPLEGAP-016A.6.8Information security event reportingNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Head of Information Security06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10075
EXAMPLEGAP-017A.7.3Securing offices, rooms and facilitiesNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Office Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10078
EXAMPLEGAP-018A.7.5Protecting against physical and environmental threatsNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Office Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10080
EXAMPLEGAP-019A.7.6Working in secure areasNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Office Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10081
EXAMPLEGAP-020A.7.8Equipment siting and protectionNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Office Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10083
EXAMPLEGAP-021A.7.11Supporting utilitiesNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.IT Operations Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10086
EXAMPLEGAP-022A.7.12Cabling securityNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.IT Operations Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10087
EXAMPLEGAP-023A.7.13Equipment maintenanceNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.IT Operations Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10088
EXAMPLEGAP-024A.8.17Clock synchronizationNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.IT Operations Manager06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10106
EXAMPLEGAP-025A.8.34Protection of information systems during audit testingNo2In place since 2026-07-06; records cover less than 3 months.Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close.Head of IT06 Jul 20266 Jul 20266 Oct 2026In place6 Jul 20266 Oct 20261 Mar 2027Yes31.4No10123
EXAMPLEGAP-026A.5.8Information security in project managementNo1Security is not a step in the project method.Add a security checkpoint (risks and requirements) to the project start and go-live gates, with a short record.Head of Engineering130 Sep 20267 Oct 2026Not started7 Oct 20267 Jan 20271 Mar 2027Yes18.1No10038
EXAMPLEGAP-027A.5.28Collection of evidenceNo1No agreed way to collect and preserve evidence from an incident.Write a one-page evidence-handling note (what to keep, who, how, chain of custody) and add it to the incident procedure.Legal Counsel130 Sep 20267 Oct 2026Not started7 Oct 20267 Jan 20271 Mar 2027Yes18.1No10058
EXAMPLEGAP-028A.6.4Disciplinary processNo1The disciplinary procedure does not mention information security breaches.Add security breaches to the disciplinary procedure and tell staff through the awareness programme.HR Director130 Sep 20267 Oct 2026Not started7 Oct 20267 Jan 20271 Mar 2027Yes18.1No10071
EXAMPLEGAP-0296.3Planning of changesNo1No agreed way to plan changes to the ISMS itself (scope, roles, processes).Add a short ISMS change step to the steering group's agenda (the Chief Operating Officer chairs it): purpose, consequences, resources and who is responsible, recorded in the minutes.Chief Operating Officer17 Oct 202614 Oct 2026Not started14 Oct 202614 Jan 20271 Mar 2027Yes17.1No10012
EXAMPLEGAP-030A.5.13Labelling of informationNo0No labelling of classified information.Apply the classification labels in the document and email tools, default to Internal, and brief staff.Head of IT230 Sep 202614 Oct 2026Not started14 Oct 202614 Jan 20271 Mar 2027Yes17.1No10043
EXAMPLEGAP-031A.7.4Physical security monitoringNo1Camera coverage and alarm monitoring of the second office are not confirmed.Agree monitoring of both offices with the landlord, confirm coverage of entrances and the equipment room, and record the check.Office Manager230 Sep 202614 Oct 2026Not started14 Oct 202614 Jan 20271 Mar 2027Yes17.1No10079
EXAMPLEGAP-0328.2Information security risk assessmentNo2In place since 2026-07-20; records cover less than 3 months. The first full risk assessment was accepted by risk owners in July; the planned reassessment has not run yet.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of Information Security020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10021
EXAMPLEGAP-033A.5.3Segregation of dutiesNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10033
EXAMPLEGAP-034A.5.9Inventory of information and other associated assetsNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10039
EXAMPLEGAP-035A.7.9Security of assets off-premisesNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10084
EXAMPLEGAP-036A.7.10Storage mediaNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10085
EXAMPLEGAP-037A.8.1User endpoint devicesNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10090
EXAMPLEGAP-038A.8.3Information access restrictionNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10092
EXAMPLEGAP-039A.8.4Access to source codeNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of Engineering020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10093
EXAMPLEGAP-040A.8.19Installation of software on operational systemsNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10108
EXAMPLEGAP-041A.8.22Segregation of networksNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of IT020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10111
EXAMPLEGAP-042A.8.31Separation of development, test and production environmentsNo2In place since 2026-07-20; records cover less than 3 months.Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close.Head of Engineering020 Jul 202620 Jul 202620 Oct 2026In place20 Jul 202620 Oct 20261 Mar 2027Yes29.4No10120
EXAMPLEGAP-0439.3.1GeneralNo1No management review held or scheduled.Schedule the first management review with top management after the internal audit report, and a yearly cycle after that.Chief Operating Officer114 Oct 202621 Oct 2026Not started21 Oct 202621 Jan 20271 Mar 2027Yes16.1No10026
EXAMPLEGAP-044A.7.7Clear desk and clear screenNo1No clear desk and clear screen rule.Publish the rule, set screen lock by policy on every device, and check the offices monthly.Office Manager114 Oct 202621 Oct 2026Not started21 Oct 202621 Jan 20271 Mar 2027Yes16.1No10082
EXAMPLEGAP-045A.5.30ICT readiness for business continuityNo1Recovery objectives are set but the platform's recovery has not been tested.Test the recovery of the production platform against its recovery objectives and record the result and the fixes.IT Operations Manager430 Sep 202628 Oct 2026Not started28 Oct 202628 Jan 20271 Mar 2027Yes15.1No10060
EXAMPLEGAP-046A.5.31Legal, statutory, regulatory and contractual requirementsNo1No register of legal, regulatory and contractual security requirements.Build the register (including NIS2 duties and customer contract terms), with an owner for each and a yearly review.Legal Counsel37 Oct 202628 Oct 2026Not started28 Oct 202628 Jan 20271 Mar 2027Yes15.1No10061
EXAMPLEGAP-047A.5.35Independent review of information securityNo1No plan for independent review of the ISMS beyond the certification audit.Record in the audit programme how and how often the ISMS is independently reviewed.Chief Operating Officer121 Oct 202628 Oct 2026Not started28 Oct 202628 Jan 20271 Mar 2027Yes15.1No10065
EXAMPLEGAP-048A.8.11Data maskingNo0Production data is copied to test without masking.Mask personal and customer data in every copy made for testing, and block unmasked copies.Head of Engineering37 Oct 202628 Oct 2026Not started28 Oct 202628 Jan 20271 Mar 2027Yes15.1No10100
EXAMPLEGAP-0495.3Organizational roles, responsibilities and authoritiesNo2In place since 2026-08-03; records cover less than 3 months. Roles and responsibilities approved in August; control owners confirmed their roles in writing.Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close.Chief Operating Officer03 Aug 20263 Aug 20263 Nov 2026In place3 Aug 20263 Nov 20261 Mar 2027Yes27.4No10007
EXAMPLEGAP-0507.4CommunicationNo2In place since 2026-08-03; records cover less than 3 months.Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close.Head of Information Security03 Aug 20263 Aug 20263 Nov 2026In place3 Aug 20263 Nov 20261 Mar 2027Yes27.4No10016
EXAMPLEGAP-051A.5.2Information security roles and responsibilitiesNo2In place since 2026-08-03; records cover less than 3 months.Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close.Head of Information Security03 Aug 20263 Aug 20263 Nov 2026In place3 Aug 20263 Nov 20261 Mar 2027Yes27.4No10032
EXAMPLEGAP-052A.5.4Management responsibilitiesNo2In place since 2026-08-03; records cover less than 3 months.Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close.Chief Operating Officer03 Aug 20263 Aug 20263 Nov 2026In place3 Aug 20263 Nov 20261 Mar 2027Yes27.4No10034
EXAMPLEGAP-053A.5.18Access rightsNo2In place since 2026-08-03; records cover less than 3 months. Quarterly access reviews started in August (see the P07 pack).Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close.Head of IT03 Aug 20263 Aug 20263 Nov 2026In place3 Aug 20263 Nov 20261 Mar 2027Yes27.4No10048
EXAMPLEGAP-054A.8.2Privileged access rightsNo2In place since 2026-08-03; records cover less than 3 months.Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close.Head of IT03 Aug 20263 Aug 20263 Nov 2026In place3 Aug 20263 Nov 20261 Mar 2027Yes27.4No10091
EXAMPLEGAP-055A.5.20Addressing information security within supplier agreementsNo1Security clauses are missing from most key supplier contracts.Add the security clauses for each supplier tier to the contracts of the Tier 1 suppliers at renewal, or by side letter.Head of Procurement47 Oct 20264 Nov 2026Not started4 Nov 20264 Feb 20271 Mar 2027Yes14.1No10050
EXAMPLEGAP-056A.7.14Secure disposal or re-use of equipmentNo1Disposal of laptops and drives is done by a supplier without certificates.Require a destruction certificate for every disposed device and reconcile it with the asset inventory.IT Operations Manager128 Oct 20264 Nov 2026Not started4 Nov 20264 Feb 20271 Mar 2027Yes14.1No10089
EXAMPLEGAP-057A.5.23Information security for use of cloud servicesNo2In place since 2026-08-10; records cover less than 3 months.Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close.Head of IT010 Aug 202610 Aug 202610 Nov 2026In place10 Aug 202610 Nov 20261 Mar 2027Yes26.4No10053
EXAMPLEGAP-058A.8.14Redundancy of information processing facilitiesNo2In place since 2026-08-10; records cover less than 3 months.Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close.IT Operations Manager010 Aug 202610 Aug 202610 Nov 2026In place10 Aug 202610 Nov 20261 Mar 2027Yes26.4No10103
EXAMPLEGAP-059A.8.15LoggingNo2In place since 2026-08-10; records cover less than 3 months.Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close.Head of IT010 Aug 202610 Aug 202610 Nov 2026In place10 Aug 202610 Nov 20261 Mar 2027Yes26.4No10104
EXAMPLEGAP-060A.8.21Security of network servicesNo2In place since 2026-08-10; records cover less than 3 months.Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close.Head of IT010 Aug 202610 Aug 202610 Nov 2026In place10 Aug 202610 Nov 20261 Mar 2027Yes26.4No10110
EXAMPLEGAP-061A.5.33Protection of recordsNo1Retention periods are not set for security records.Set retention and protection for the ISMS and security records in the records schedule.Legal Counsel228 Oct 202611 Nov 2026Not started11 Nov 202611 Feb 20271 Mar 2027Yes13.1No10063
EXAMPLEGAP-062A.8.9Configuration managementNo1No approved baseline configurations for servers, laptops or cloud services.Approve baseline configurations for the main system types, apply them, and check drift monthly.Head of IT421 Sep 202611 Nov 2026In progress11 Nov 202611 Feb 20271 Mar 2027Yes13.1No10098
EXAMPLEGAP-063A.8.26Application security requirementsNo1Security requirements are not written into feature specifications.Add a security requirements section to the specification template and review it at design sign-off.Head of Engineering228 Oct 202611 Nov 2026Not started11 Nov 202611 Feb 20271 Mar 2027Yes13.1No10115
EXAMPLEGAP-064A.5.12Classification of informationNo2In place since 2026-08-17; records cover less than 3 months.Keep it running and keep its records; on 2026-11-17 check that an auditor could sample 3 months of them, then close.Head of Information Security017 Aug 202617 Aug 202617 Nov 2026In place17 Aug 202617 Nov 20261 Mar 2027Yes25.4No10042
EXAMPLEGAP-065A.5.14Information transferNo2In place since 2026-08-17; records cover less than 3 months.Keep it running and keep its records; on 2026-11-17 check that an auditor could sample 3 months of them, then close.Head of Information Security017 Aug 202617 Aug 202617 Nov 2026In place17 Aug 202617 Nov 20261 Mar 2027Yes25.4No10044
EXAMPLEGAP-0667.5.3Control of documented informationNo1Two documents are past their review date (AUP-001, BKP-001) and one is awaiting approval (the Supplier Security Policy, P04 register SUP-001) in the policy register.Complete the two overdue reviews, take the Supplier Security Policy (P04 register SUP-001) to its approver, and add a monthly check of review dates to the ISMS manager's routine.Head of Information Security111 Nov 202618 Nov 2026Not started18 Nov 202618 Feb 20271 Mar 2027Yes12.1No10019
EXAMPLEGAP-067A.5.21Managing information security in the ICT supply chainNo1No check of the security of the software and cloud supply chain.Ask Tier 1 technology suppliers about their own suppliers and components, and record the answers with the supplier assessment.Head of Procurement24 Nov 202618 Nov 2026Not started18 Nov 202618 Feb 20271 Mar 2027Yes12.1No10051
EXAMPLEGAP-068A.8.6Capacity managementNo1Capacity is watched but no thresholds or forecast exist.Set capacity thresholds and alerts for the platform and review a quarterly forecast.IT Operations Manager24 Nov 202618 Nov 2026Not started18 Nov 202618 Feb 20271 Mar 2027Yes12.1No10095
EXAMPLEGAP-0694.4Information security management systemNo2In place since 2026-08-24; records cover less than 3 months. The ISMS processes and how they connect are described in the ISMS manual; it has run as a whole only since late August.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of Information Security024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10004
EXAMPLEGAP-0707.5.1GeneralNo2In place since 2026-08-24; records cover less than 3 months.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of Information Security024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10017
EXAMPLEGAP-071A.5.37Documented operating proceduresNo2In place since 2026-08-24; records cover less than 3 months.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.IT Operations Manager024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10067
EXAMPLEGAP-072A.8.24Use of cryptographyNo2In place since 2026-08-24; records cover less than 3 months.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of IT024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10113
EXAMPLEGAP-073A.8.25Secure development life cycleNo2In place since 2026-08-24; records cover less than 3 months.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of Engineering024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10114
EXAMPLEGAP-074A.8.28Secure codingNo2In place since 2026-08-24; records cover less than 3 months.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of Engineering024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10117
EXAMPLEGAP-075A.8.29Security testing in development and acceptanceNo2In place since 2026-08-24; records cover less than 3 months.Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close.Head of Engineering024 Aug 202624 Aug 202624 Nov 2026In place24 Aug 202624 Nov 20261 Mar 2027Yes24.4No10118
EXAMPLEGAP-076A.8.27Secure system architecture and engineering principlesNo1Architecture principles for security are not written down.Write the secure architecture principles for the platform and apply them in design reviews.Head of Engineering211 Nov 202625 Nov 2026Not started25 Nov 202625 Feb 20271 Mar 2027Yes11.1No10116
EXAMPLEGAP-0777.2CompetenceNo2In place since 2026-09-01; records cover less than 3 months. Competence requirements for ISMS roles set in September; training records are in the HR system.Keep it running and keep its records; on 2026-12-01 check that an auditor could sample 3 months of them, then close.HR Director01 Sep 20261 Sep 20261 Dec 2026In place1 Sep 20261 Dec 20261 Mar 2027Yes23.3No10014
EXAMPLEGAP-0788.3Information security risk treatmentNo1Treatment actions are under way but their completion and the residual risk are not recorded.Record each completed treatment action and the residual risk it leaves in the risk register, and have risk owners accept it.Head of Information Security218 Nov 20262 Dec 2026Not started2 Dec 20262 Mar 20271 Mar 2027Yes10.1No10022
EXAMPLEGAP-079A.5.22Monitoring, review and change management of supplier servicesNo1Supplier performance and changes are not reviewed for security.Set a review interval per supplier tier and hold the first reviews of Tier 1 suppliers.Head of Procurement218 Nov 20262 Dec 2026Not started2 Dec 20262 Mar 20271 Mar 2027Yes10.1No10052
EXAMPLEGAP-080A.8.10Information deletionNo1Customer data is not deleted on a set schedule after contracts end.Define deletion periods for customer and internal data, automate the deletion job, and keep its log.IT Operations Manager218 Nov 20262 Dec 2026Not started2 Dec 20262 Mar 20271 Mar 2027Yes10.1No10099
EXAMPLEGAP-081A.8.12Data leakage preventionNo0No controls to detect data leaving through email, storage or endpoints.Turn on data loss prevention rules for customer data in email and cloud storage, in report-only mode first, then block.Head of IT311 Nov 20262 Dec 2026Not started2 Dec 20262 Mar 20271 Mar 2027Yes10.1No10101
EXAMPLEGAP-082A.5.29Information security during disruptionNo2In place since 2026-09-07; records cover less than 3 months.Keep it running and keep its records; on 2026-12-07 check that an auditor could sample 3 months of them, then close.IT Operations Manager07 Sep 20267 Sep 20267 Dec 2026In place7 Sep 20267 Dec 20261 Mar 2027Yes22.4No10059
EXAMPLEGAP-083A.8.33Test informationNo1No rules for selecting and protecting test data.Set rules for choosing, protecting and deleting test data, together with the masking in A.8.11.Head of Engineering225 Nov 20269 Dec 2026Not started9 Dec 20269 Mar 20271 Mar 2027Yes9.1No10122
EXAMPLEGAP-084A.5.36Compliance with policies, rules and standards for information securityNo2In place since 2026-09-10; records cover less than 3 months. Security Exception & Waiver Standard EXC-STD approved on 2026-09-10.Keep it running and keep its records; on 2026-12-10 check that an auditor could sample 3 months of them, then close.Head of Information Security010 Sep 202610 Sep 202610 Dec 2026In place10 Sep 202610 Dec 20261 Mar 2027Yes22.0No10066
EXAMPLEGAP-085A.8.8Management of technical vulnerabilitiesNo2In place since 2026-09-10; records cover less than 3 months. Vulnerability & Exposure Management Standard VMS-001 approved on 2026-09-10 (see the P01 pack).Keep it running and keep its records; on 2026-12-10 check that an auditor could sample 3 months of them, then close.Head of IT010 Sep 202610 Sep 202610 Dec 2026In place10 Sep 202610 Dec 20261 Mar 2027Yes22.0No10097
EXAMPLEGAP-0867.3AwarenessNo2In place since 2026-09-14; records cover less than 3 months. Awareness campaign launched in September; completion is tracked.Keep it running and keep its records; on 2026-12-14 check that an auditor could sample 3 months of them, then close.Head of Information Security014 Sep 202614 Sep 202614 Dec 2026In place14 Sep 202614 Dec 20261 Mar 2027Yes21.4No10015
EXAMPLEGAP-087A.6.3Information security awareness, education and trainingNo2In place since 2026-09-14; records cover less than 3 months.Keep it running and keep its records; on 2026-12-14 check that an auditor could sample 3 months of them, then close.Head of Information Security014 Sep 202614 Sep 202614 Dec 2026In place14 Sep 202614 Dec 20261 Mar 2027Yes21.4No10070
EXAMPLEGAP-0889.1Monitoring, measurement, analysis and evaluationNo1Measures are listed but not yet collected or reported; no one analyses the results.Choose the measures, their owners and frequency; produce the first monthly report and take it to the steering group.Head of Information Security32 Dec 202623 Dec 2026Not started23 Dec 202623 Mar 20271 Mar 2027Yes7.1No10023
EXAMPLEGAP-089A.8.16Monitoring activitiesNo1Logs are collected but not monitored for anomalies.Define the alerts that matter, route them to the on-call rota, and record the weekly review.Head of IT32 Dec 202623 Dec 2026Not started23 Dec 202623 Mar 20271 Mar 2027Yes7.1No10105
EXAMPLEGAP-0909.2.1GeneralNo1No check yet that each audit has set criteria and scope, an independent auditor and results reported to management.After the first audit cycle, confirm each audit had criteria, scope and an independent auditor (IS-07) and that its results reached management; correct the programme where they did not.Head of Information Security123 Dec 202630 Dec 2026Not started30 Dec 202630 Mar 20271 Mar 2027Yes6.1No10024
EXAMPLEGAP-091A.8.18Use of privileged utility programsNo1Use of privileged utility programs is not restricted.List the utility programs that can override controls, restrict them to named administrators and log their use.Head of IT123 Dec 202630 Dec 2026Not started30 Dec 202630 Mar 20271 Mar 2027Yes6.1No10107
EXAMPLEGAP-0929.3.2Management review inputsNo1No template for the inputs the review must consider.Prepare the review pack with every required input, from the Management Review Meeting Pack.Head of Information Security130 Dec 20266 Jan 2027Not started6 Jan 20276 Apr 20271 Mar 2027Yes5.1No10027
EXAMPLEGAP-093A.8.23Web filteringNo1Web filtering is on in the offices only, not on remote devices.Extend the web filter to every managed device wherever it connects.Head of IT130 Dec 20266 Jan 2027Not started6 Jan 20276 Apr 20271 Mar 2027Yes5.1No10112
EXAMPLEGAP-09410.1Continual improvementNo1Improvements are made but not recorded as such.Keep an improvement log fed by audits, incidents, measures and suggestions, reviewed by the steering group.Head of Information Security16 Jan 202713 Jan 2027Not started13 Jan 202713 Apr 20271 Mar 2027Yes4.1No10029
EXAMPLEGAP-095A.5.5Contact with authoritiesNo1No list of which authorities to contact, when, and who may do it.Record the authorities (regulator, national incident response team, police, data protection authority), the route and who may contact them; link it from the incident procedure.Head of Information Security113 Jan 202720 Jan 2027Not started20 Jan 202720 Apr 20271 Mar 2027Yes3.1No10035
EXAMPLEGAP-096A.5.7Threat intelligenceNo1Threat information is read informally; nothing is recorded or acted on.Choose two or three threat sources relevant to the platform, review them weekly, and record what was relevant and what was done.Head of Information Security220 Jan 20273 Feb 2027Not started3 Feb 20273 May 20271 Mar 2027Yes1.1Yes10037

Summary

Tracker summary

The settings the forecasts use, the headline measures ISM-01 to ISM-04, the estimate of the earliest Stage 2 date — worked out as in the Certification Readiness Self-Assessment — and each owner's workload.

EXAMPLE: the example organisation's gaps, as at 2026-09-30. Delete the EXAMPLE rows and settings to use your own.

Settings

As-at date30 Sep 2026EXAMPLE — the example's as-at date. Replace it with today's date, or type =TODAY(). Overdue and forecasts count from it.
Planned Stage 1 audit18 Jan 2027EXAMPLE. For reference; the latest dates are set by Stage 2.
Planned Stage 2 audit1 Mar 2027EXAMPLE. The date booked with your certification body.
Internal audits end (planned)9 Dec 2026EXAMPLE. Leave blank if not yet planned.
Management review (planned)6 Jan 2027EXAMPLE. After the audit report.
Months of operation before Stage 2 (IS-05)3The [[3]] in IS-05. Keep it the same as in the Certification Readiness Self-Assessment.
Check phase: audit programme in place to review done (weeks)4The Check phase in the ISO 27001 Implementation Methodology & Project Plan.
Critical-path float (weeks)2A gap whose slip of this many weeks or fewer would move the estimate is on the critical path.
Requirements assessed (clauses and applicable controls)122EXAMPLE — from the Certification Readiness Self-Assessment ('Everything assessed'). Used for ISM-02.

Headline measures

MeasureResultTarget
ISM-01 Blocking items operating3 of 8 blockers at OperatingAll, before the Stage 2 date
ISM-02 Requirements operating26 of 122 requirements at Operating (96 open gaps)Rising monthly
ISM-03 Gaps overdue1 gap overdue, 0 of them on the critical pathZero on the critical path
ISM-04 Weeks to certification20 weeks to the earliest Stage 2 date (planned: 22 weeks)On or before the planned date

Estimated earliest Stage 2 date, step by step

StepDateWorking
(a) Remaining work: every gap In place3 Feb 2027Last: A.5.7 (Head of Information Security), at the end of that owner's 18 weeks of work.
(b) IS-05: last blocker In place + 3 months11 Feb 2027Last blocker In place: 10.2 on 2026-11-11, plus 3 months of records.
(c) IS-06: internal audit and management review done6 Jan 2027Earliest end of the Check phase 2026-11-25; planned audit end 2026-12-09; planned review 2027-01-06.
Estimated earliest Stage 2 date11 Feb 2027The latest of (a), (b) and (c): set by (b), IS-05.
Planned Stage 2 date1 Mar 2027From the settings above.
VerdictOn track: 2.6 weeks to spare before the planned Stage 2 date.

Gaps by status

StatusAll gapsBlockersOverdueCritical path
Not started36202
In progress4211
In place56100
Closed0000

Owner workload

OwnerOpen gapsWeeks queuedQueue endsOn critical pathOverdueNote
Chief Operating Officer6428 Oct 202600
Head of Information Security27183 Feb 202730Queue ends close to the estimate: this owner's gaps set the pace.
Head of IT22146 Jan 202700
IT Operations Manager1192 Dec 202600
Head of Procurement492 Dec 202601
HR Director517 Oct 202600
Head of Engineering10109 Dec 202600
Office Manager6321 Oct 202600
Legal Counsel5611 Nov 202600

Owners come from the OwnerList on the Lists sheet. Weeks queued counts only gaps below In place; gaps already In place need time, not work.

Lists

StatusReadinessGapOwnerListBlockersReqIdReqTitle
Not started0Chief Operating Officer4.34.1Understanding the organization and its context
In progress1Head of Information Security5.24.2Understanding the needs and expectations of interested parties
In place2Head of IT6.1.24.3Determining the scope of the information security management system
ClosedIT Operations Manager6.1.34.4Information security management system
Head of Procurement6.25.1Leadership and commitment
HR Director9.2.25.2Policy
Head of Engineering9.3.35.3Organizational roles, responsibilities and authorities
Office Manager10.26.1.1General
Legal Counsel6.1.2Information security risk assessment
6.1.3Information security risk treatment
6.2Information security objectives and planning to achieve them
6.3Planning of changes
7.1Resources
7.2Competence
7.3Awareness
7.4Communication
7.5.1General
7.5.2Creating and updating
7.5.3Control of documented information
8.1Operational planning and control
8.2Information security risk assessment
8.3Information security risk treatment
9.1Monitoring, measurement, analysis and evaluation
9.2.1General
9.2.2Internal audit programme
9.3.1General
9.3.2Management review inputs
9.3.3Management review results
10.1Continual improvement
10.2Nonconformity and corrective action
A.5.1Policies for information security
A.5.2Information security roles and responsibilities
A.5.3Segregation of duties
A.5.4Management responsibilities
A.5.5Contact with authorities
A.5.6Contact with special interest groups
A.5.7Threat intelligence
A.5.8Information security in project management
A.5.9Inventory of information and other associated assets
A.5.10Acceptable use of information and other associated assets
A.5.11Return of assets
A.5.12Classification of information
A.5.13Labelling of information
A.5.14Information transfer
A.5.15Access control
A.5.16Identity management
A.5.17Authentication information
A.5.18Access rights
A.5.19Information security in supplier relationships
A.5.20Addressing information security within supplier agreements
A.5.21Managing information security in the ICT supply chain
A.5.22Monitoring, review and change management of supplier services
A.5.23Information security for use of cloud services
A.5.24Information security incident management planning and preparation
A.5.25Assessment and decision on information security events
A.5.26Response to information security incidents
A.5.27Learning from information security incidents
A.5.28Collection of evidence
A.5.29Information security during disruption
A.5.30ICT readiness for business continuity
A.5.31Legal, statutory, regulatory and contractual requirements
A.5.32Intellectual property rights
A.5.33Protection of records
A.5.34Privacy and protection of PII
A.5.35Independent review of information security
A.5.36Compliance with policies, rules and standards for information security
A.5.37Documented operating procedures
A.6.1Screening
A.6.2Terms and conditions of employment
A.6.3Information security awareness, education and training
A.6.4Disciplinary process
A.6.5Responsibilities after termination or change of employment
A.6.6Confidentiality or non-disclosure agreements
A.6.7Remote working
A.6.8Information security event reporting
A.7.1Physical security perimeters
A.7.2Physical entry
A.7.3Securing offices, rooms and facilities
A.7.4Physical security monitoring
A.7.5Protecting against physical and environmental threats
A.7.6Working in secure areas
A.7.7Clear desk and clear screen
A.7.8Equipment siting and protection
A.7.9Security of assets off-premises
A.7.10Storage media
A.7.11Supporting utilities
A.7.12Cabling security
A.7.13Equipment maintenance
A.7.14Secure disposal or re-use of equipment
A.8.1User endpoint devices
A.8.2Privileged access rights
A.8.3Information access restriction
A.8.4Access to source code
A.8.5Secure authentication
A.8.6Capacity management
A.8.7Protection against malware
A.8.8Management of technical vulnerabilities
A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.13Information backup
A.8.14Redundancy of information processing facilities
A.8.15Logging
A.8.16Monitoring activities
A.8.17Clock synchronization
A.8.18Use of privileged utility programs
A.8.19Installation of software on operational systems
A.8.20Networks security
A.8.21Security of network services
A.8.22Segregation of networks
A.8.23Web filtering
A.8.24Use of cryptography
A.8.25Secure development life cycle
A.8.26Application security requirements
A.8.27Secure system architecture and engineering principles
A.8.28Secure coding
A.8.29Security testing in development and acceptance
A.8.30Outsourced development
A.8.31Separation of development, test and production environments
A.8.32Change management
A.8.33Test information
A.8.34Protection of information systems during audit testing

Definitions

Definitions

TermMeaning in this workbook
GapA requirement (clause requirement or applicable Annex A control) below Operating in the readiness assessment.
0 — Not startedNothing exists yet.
1 — PlannedOwner and approach agreed; not yet in place.
2 — In placeDocumented and working, but little or no record yet.
3 — OperatingWorking, with records covering at least [[3]] months, and an auditor could sample it.
BlockerOne of the 8 clause requirements without which a Stage 2 audit cannot pass: 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 9.2.2, 9.3.3, 10.2. Each must be Operating before the Stage 2 date.
Forecast In placeWhen the gap is expected to reach In place if its owner works through their gaps one at a time from the as-at date, blockers first.
Latest In place for Stage 2The last date the gap can reach In place and still allow the planned Stage 2 date: 3 months before it for a blocker (IS-05), the date itself for any other gap.
FloatWeeks a gap can slip before the estimated Stage 2 date moves.
Critical pathGaps whose float is at or below the Summary setting.
OverdueNot Closed, with an agreed due date before the as-at date.
Corrective actionAn action to remove the cause of a nonconformity so it does not happen again (clause 10.2); record it here with its root cause (IS-09).
EXAMPLEValues for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity) as at 2026-09-30. Delete them before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 10.2 — Nonconformity and corrective actionGap Register: actions with owners, dates and a check that they worked; audit nonconformities recorded here (IS-09)
ISO/IEC 27001:2022Clause 6.1.3 — Information security risk treatmentGap Register: the risk treatment plan's actions tracked to completion
ISO/IEC 27001:2022Clause 6.2 — Information security objectives and planning to achieve themSummary: planning what will be done, by whom and when, towards the certification objective
NIST CSF 2.0ID.IM-03 — “Improvements are identified from execution of operational processes, procedures, and activities”Gap Register: improvements identified while putting processes and controls in place
NIST CSF 2.0ID.IM-01 — “Improvements are identified from evaluations”Whole workbook: improvements from the readiness assessment tracked to closure

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0