Self-serve template
ISO 27001 Gap Analysis Workbook
A self-serve gap analysis kit for organisations preparing for ISO/IEC 27001 certification: a method guide, a scoring workbook and a step-by-step roadmap — with the guide's factual statements dated and traceable to their sources.
What this product is
This workbook set is built for one exercise: measuring how far your information security management system stands, today, from what ISO/IEC 27001 requires — and turning every shortfall into an action with an owner and a date.
It is a working tool, not a course and not a consultancy engagement. You run the analysis yourself, with your own people, on your own schedule. The files give you the method and the machinery; the judgement stays yours.
What's included
- The Gap Analysis Guide (PDF). The method: how to set your scope, how to score honestly, how to separate a gap analysis from the certification audit stages that follow it, and how to build an action plan a certification body's Stage 1 review will find boring — in the good sense. Includes a sourced bibliography; every fact carries the date it was last checked against its primary source.
- The Scoring Workbook (Excel). A seven-worksheet file: assessment sheets covering the standard's main-body requirements and the Annex A control themes, plus setup, action plan and dashboard sheets — with a four-state scoring model (In place · Partial · Not in place · Not applicable) and automatic readiness and gap scores. Reference columns are left open for you to map rows to your own licensed copy of the standard.
- The Certification-Readiness Checklist. A 14-step roadmap from the decision to pursue certification through scoping, scoring and action planning to certification body selection, the Stage 1 and Stage 2 audits and the surveillance cycle.
Who it's for
Information security leads, IT managers and implementers in organisations of any size that are preparing for ISO/IEC 27001 certification — or deciding whether to pursue it.
What this product is not
- It does not grant certification and does not guarantee any audit outcome. Only an accredited, independent certification body can issue an ISO/IEC 27001 certificate. The workbook's scores are your own assessment and carry no certification meaning.
- It does not contain the text of ISO/IEC 27001. The standard is copyrighted; the files refer to it by clause numbers and headings only. To run the analysis you need your own licensed copy, bought from ISO or your national standards body.
- It is not legal advice, and certification does not substitute for compliance with data protection law.
- It is not consultancy. Buying it does not make you a client and does not create an advisory relationship.
Dated verification, corrections and new editions
Every factual claim in the guide states the date on which it was last checked against its primary source, and each file states the date its content was compiled. A downloaded file does not update itself — but if we find a factual error in it, we correct the file and make the corrected version available to existing buyers at no charge. A version rewritten for a new edition of the standard is a new product, not a free update.