ISO 27001 Gap Analysis: A 0-5 Maturity Scoring Method to Know Where You Stand Before You Budget
What an ISO 27001 gap analysis covers, how it differs from an internal audit and SoA, and a practical 0-5 maturity scoring method to prioritize fixes.
What an ISO 27001 gap analysis covers, how it differs from an internal audit and SoA, and a practical 0-5 maturity scoring method to prioritize fixes.
The hub gives the ballpark range. Here is the real ISO 27001 certification cost by phase, company size, hidden costs, and a worked SME budget.
ISO 27001 clause 6.1.2 requires a documented, repeatable risk assessment methodology, not an ad-hoc list. Here’s the ISO 27005-aligned approach auditors expect.
What ISO 27001 clause 4.3 requires your ISMS scope statement to cover, common scoping patterns and tradeoffs, and a worked SME example.
The exact Annex A controls (5.19-5.23) an ISO 27001 supplier security policy must cover, NIS2 overlap, risk tiering, and a free policy skeleton.
What ISO 27001’s business continuity policy actually requires (A.5.29, A.5.30, A.8.13, A.8.14), how it differs from ISO 22301, plus a free policy skeleton.
The exact Annex A controls an ISO 27001 incident response policy must cover, how NIS2’s 24/72-hour clock differs, plus a free policy skeleton.
Which ISO 27001 Annex A controls your access control policy must cover, how NIS2 Article 21(2)(i) already helps, plus a free policy skeleton.
What ISO 27001 clause 9.2 requires from an internal audit, how it differs from a gap analysis, and a risk-based checklist by clause and Annex A control.
What an ISO 27001 Statement of Applicability actually is, how it’s built from your risk assessment, and a worked example across 5 Annex A controls.