Select your language

+49 800 / 27 00 001
We are thrilled to serve you

Mo-Th.: 08:00 - 18:00
Friday: 08:00 - 14:00

Gap Analysis and Project Planning

A successful ISO 27001 certification project begins with a realistic assessment of the organisation’s existing information security arrangements. Policies, technical security measures and organisational processes are often already in place but may not yet fully meet the requirements of a structured Information Security Management System.

As part of a gap analysis, we assess your organisation’s current level of implementation and identify the measures required to establish or further develop an ISMS in accordance with ISO/IEC 27001.

Our Services

The gap analysis may include the following areas:

  • Defining the objectives and intended scope of the ISMS
  • Reviewing existing policies, processes and security measures
  • Assessing existing roles and responsibilities
  • Evaluating the information security risk management process
  • Reviewing available documentation and evidence
  • Comparing the current arrangements with the requirements of ISO/IEC 27001
  • Assessing security measures that have already been implemented
  • Identifying organisational, technical and documentation-related gaps
  • Prioritising the required actions
  • Estimating the necessary time, personnel and consulting resources

We consider the size, structure, industry and current situation of your organisation. The objective is not to create an unnecessarily complex management system, but to develop an appropriate and practical solution.

Structured Project Planning

Based on the gap analysis, we work with you to develop a transparent and manageable project plan. This may include:

  • Project phases and milestones
  • Tasks and responsibilities
  • Required resources
  • Priorities and dependencies
  • Planned training courses and workshops
  • Internal review and approval steps
  • The intended certification date

As a result, you receive a clear overview of the current implementation status and a prioritised action plan for the next stages of the project.

We establish the basis for a structured, manageable and goal-oriented ISO 27001 project. If you're interested, please feel free to contact us—it's free and there's no obligation.

ISO 27001 gap analysis and project planning as the first step toward implementing an Information Security Management System (ISMS).

Address

Frommel Datenschutz GmbH
Akazienstr. 6a
61352 Bad Homburg
Germany

Contact

Opening hours

Mo.-Th.: 08:00 a.m. – 06:00 p.m.
Friday: 08:00 a.m. – 02:00 p.m.
Saturday: on appointment
In case of emergencies at any time

Our strengths

  • Free and non-binding initial consultation
  • Competent, individual and ongoing support
  • Practical and illustrative use cases
  • Pragmatic solutions
  • Many years of experience