Expert Advice Community

Guest

Gap Analysis

  Quote
Guest
Guest post Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

Gap Analysis

Hi friends, Could you help me with the following question please?: Is need or mandatory to perform a Gap Analysis before to begin the isms implementation? Its Gap Analysis is about the ISO 27002 controls? Or about the requirements of the ISO 27001? Which is the best way to perform this activity? based in the CMMI? Thanks so much. Best regards.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 13, 2016
The gap analysis is not mandatory before the begin of the ISMS implementation according to ISO 27001:2013, although it can be very useful. The Gap analysis is about the requirements of ISO 27001, including the security controls of Annex A (that as you know are the same as the security controls of ISO 27002).

To perform this activity, of course you can use CMMI levels to assess the compliance of each requirement, and you can also use our free tool "Free ISO 27001 Gap Analysis Tool" :https://advisera.com/27001academy/free-iso-27001-gap-analysis-tool/
Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Jun 09, 2023