Could you help me with the following question please?:
Is need or mandatory to perform a Gap Analysis before to begin the isms implementation? Its Gap Analysis is about the ISO 27002 controls? Or about the requirements of the ISO 27001?
Which is the best way to perform this activity? based in the CMMI?
Thanks so much.
The gap analysis is not mandatory before the begin of the ISMS implementation according to ISO 27001:2013, although it can be very useful. The Gap analysis is about the requirements of ISO 27001, including the security controls of Annex A (that as you know are the same as the security controls of ISO 27002).