+49 800 / 27 00 001
We are thrilled to serve you
Audits and Gap Analyses
Information security management must be reviewed regularly and adapted to changing business processes, threats and legal requirements.
Through our audits and gap analyses, we assess the extent to which the requirements of ISO/IEC 27001 and, where applicable, NIS2 and the German BSI Act have been implemented. We examine not only the available documentation, but also the actual application and effectiveness of the defined measures.
Possible areas of assessment
Depending on the agreed scope, we review areas including:
- the scope, context and governance of the ISMS
- roles, responsibilities and the involvement of executive management
- the information security policy and security objectives
- the inventory and classification of information and other assets
- protection requirements, risk assessment and risk treatment processes
- identity and access management
- vulnerability, patch and change management
- logging, monitoring and the detection of security events
- backup, recovery and business continuity arrangements
- security incident management and notification procedures
- supplier and service provider management
- training and awareness measures
- internal audits, management reviews and continual improvement
- registration, management responsibilities and reporting obligations under NIS2 and the German BSI Act
NIS2 and the German BSI Act require affected entities not only to implement appropriate risk-management measures, but also to document them and assess their effectiveness. Depending on the entityβs classification, registration, incident notification and supervisory requirements may also apply.
Difference between an audit and a gap analysis
During an audit, we assess against defined criteria whether requirements and internal specifications have been appropriately implemented and are operating effectively.
A gap analysis compares the current state with a defined target state. It is particularly suitable for preparing for ISO/IEC 27001 certification, implementing NIS2 requirements for the first time or planning the further development of the ISMS.
The assessment may include document reviews, interviews, sample-based testing and the evaluation of available evidence.
Clear and actionable results
Depending on the agreed scope, you will receive:
- a structured overview of the requirements assessed
- identified strengths and opportunities for improvement
- identified deviations and documentation gaps
- an assessment of their criticality
- specific recommendations for action
- a prioritised action plan
- an executive summary upon request
Consulting and audit activities are separated appropriately to avoid improper self-review. Our audits do not replace a certification audit conducted by an independent certification body, but they can prepare your organisation specifically and effectively for such an audit.

Our audits and gap analyses provide transparency regarding the maturity of your information security management and identify the areas in which targeted improvements are required.
Address
Frommel Datenschutz GmbH
Akazienstr. 6a
61352 Bad Homburg
Germany
Phone: +49 6172 / 1710179
Fax: +49 6172 / 1714896
WhatsApp: +49 6172 / 4954596
E-Mail: datenschutz@frommel.com
Web: datenschutz.frommel.com
Opening hours
| Mo.-Th.: | 08:00 a.m. β 06:00 p.m. |
| Friday: | 08:00 a.m. β 02:00 p.m. |
| Saturday: | on appointment |
Our strengths
- Free and non-binding initial consultation
- Competent, individual and ongoing support
- Practical and illustrative use cases
- Pragmatic solutions
- Many years of experience
