Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Gap analysis · ISO/IEC 27001 2022

Where are our gaps?

Answer 118 questions about how your organisation actually works, and see which parts of ISO/IEC 27001 2022 you would struggle to evidence. Every question explains itself as it is asked.

The baseline is ISO/IEC 27001:2022 itself. Every clause requirement applies to every management system, and every Annex A control is presumed to apply unless you rule it out with a justification. So a gap here means a requirement that applies to you and that you told us you could not evidence. That is the standard's own bar, not one we invented — but it is measured entirely from what you said about yourself.

  • About 70 minutes.
  • No account, and no email needed to see your result.
  • Nothing leaves your browser unless you ask for the full report.

First, a few things about you

Loading the questions…