ISO 27001/2 Gap Analysis
ISO 27001 Reviews & Gap Analysis Assessments.
- ISO 27001 is the internationally accepted standard for Information Security management.
- A number of regulating agencies, including the Data Protection Commissioner, have declared ISO 27001 to be a benchmark for prudent and competent practice.
- commissum offers expert, independent assessment of the gap between current security management and an implementation of ISO 27001 that is appropriate to the organisation.
An ISO 27001/2 gap analysis identifies:
- Improvements in security based upon industry best practice.
- Achievement and shortfall in ISO 27001/2 control areas relevant to the business.
- Plan of activities for ISO 27001 compliance.
- Expert comment on formal ISO 27001 certification.
ISO 27001/2 gap analysis issues
ISO 27001 is the internationally accepted standard for Information Security management. Organisations of all sizes have identified the value of compliance, either pursuing formal certification through accreditation agencies, or adopting the standard through implementing ISO 27001 as their guiding framework for internal security management.
This issue been reinforced by a number of regulating agencies declaring ISO 27001 as their benchmark for prudent and competent practice, including the Data Protection Commissioner. There is also growing support within government contracting circles for ISO 27001 to be a future mandated standard.
There is obviously increased pressure to comply with ISO 27001. However, the scope of the standard is wide, and experienced, professional interpretation and guidance is essential for effective and economical application of the standard.
It can be difficult for an enterprise to make objective, well-informed decisions about how to adopt the standard cost-effectively, and whether to seek formal certification. It is a sensible first step to commission an independent expert review to assess how current practice compares with the standard and with accepted industry practice.
Approach
The gap analysis is essentially an audit focused on identifying the appropriate implementation of ISO 27001, and outlining the improvements required to achieve this.
The steps followed are:
- Review information security policy and advise on and agree scope of the Information Security Management System.
- Conduct a risk assessment workshop.
- Agree control objectives (Statement of Applicability).
- Review controls (interview, observation, and inspection).
- Information Security Management status report and findings workshop - agree gap analysis.
- Final report with recommendations for improvement and options for implementation of ISO 27001.
ISO 27001/2 gap analysis customer benefits
- Provision of an expert, independent assessment of the gap between current security management and an implementation of ISO27001 appropriate to the customer's organisation.
- Recommendations on business areas, systems and processes requiring improvements in security, based upon industry best practice.
- Statement of achievement and shortfall in ISO27001 control areas relevant to the business.
- Outline plan of activities for ISO27001 compliance.
- Expert comment on the advisability of seeking formal ISO27001 certification.
Get in touch with one of our security consultants today
- No obligation
- Expert advice
- Tailored solutions
"We were delighted with the work commissum did for us; this included a gap analysis against ISO27001 and ongoing security testing throughout the year. In particular, commissum’s reporting is clear and easy to understand; we especially liked the concrete and actionable nature of the recommendations for fixing the issues raised. Although we were initially concerned that security assessments might interfere with our day-to-day work, in fact we found everything went very smoothly with no interruptions. I would certainly recommend commissum and their services.”
IT Director, National Law Firm
Find out more about this and other testimonials
Latest News
Alleged Chinese Government Hacking Department back in action
Allegedly the Chinese state sponsored cyber division named as Unit 61398 are back in action after a lull in their activities. This group that allegedly specialises in governmental and industrial espionage was very active and successful up until February this year. The targets of Unit 61398, also known as APT1, have ...Tue 21 May, 2013 //
Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years
A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...Wed 08 May, 2013 //
Suspected hacker arrested after “biggest-ever DDoS attack”
Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...Tue 30 Apr, 2013 //


