Select your language

+49 800 / 27 00 001
We are thrilled to serve you

Mo-Th.: 08:00 - 18:00
Friday: 08:00 - 14:00

Audits and Gap Analyses

Information security management must be reviewed regularly and adapted to changing business processes, threats and legal requirements.

Through our audits and gap analyses, we assess the extent to which the requirements of ISO/IEC 27001 and, where applicable, NIS2 and the German BSI Act have been implemented. We examine not only the available documentation, but also the actual application and effectiveness of the defined measures.

Possible areas of assessment

Depending on the agreed scope, we review areas including:

  • the scope, context and governance of the ISMS
  • roles, responsibilities and the involvement of executive management
  • the information security policy and security objectives
  • the inventory and classification of information and other assets
  • protection requirements, risk assessment and risk treatment processes
  • identity and access management
  • vulnerability, patch and change management
  • logging, monitoring and the detection of security events
  • backup, recovery and business continuity arrangements
  • security incident management and notification procedures
  • supplier and service provider management
  • training and awareness measures
  • internal audits, management reviews and continual improvement
  • registration, management responsibilities and reporting obligations under NIS2 and the German BSI Act

NIS2 and the German BSI Act require affected entities not only to implement appropriate risk-management measures, but also to document them and assess their effectiveness. Depending on the entity’s classification, registration, incident notification and supervisory requirements may also apply.

Difference between an audit and a gap analysis

During an audit, we assess against defined criteria whether requirements and internal specifications have been appropriately implemented and are operating effectively.

A gap analysis compares the current state with a defined target state. It is particularly suitable for preparing for ISO/IEC 27001 certification, implementing NIS2 requirements for the first time or planning the further development of the ISMS.

The assessment may include document reviews, interviews, sample-based testing and the evaluation of available evidence.

Clear and actionable results

Depending on the agreed scope, you will receive:

  • a structured overview of the requirements assessed
  • identified strengths and opportunities for improvement
  • identified deviations and documentation gaps
  • an assessment of their criticality
  • specific recommendations for action
  • a prioritised action plan
  • an executive summary upon request

Consulting and audit activities are separated appropriately to avoid improper self-review. Our audits do not replace a certification audit conducted by an independent certification body, but they can prepare your organisation specifically and effectively for such an audit.

Information security audits and gap analyses with consulting and training

Our audits and gap analyses provide transparency regarding the maturity of your information security management and identify the areas in which targeted improvements are required.

Address

Frommel Datenschutz GmbH
Akazienstr. 6a
61352 Bad Homburg
Germany

Contact

Opening hours

Mo.-Th.: 08:00 a.m. – 06:00 p.m.
Friday: 08:00 a.m. – 02:00 p.m.
Saturday: on appointment
In case of emergencies at any time

Our strengths

  • Free and non-binding initial consultation
  • Competent, individual and ongoing support
  • Practical and illustrative use cases
  • Pragmatic solutions
  • Many years of experience