ISO 27001 Gap Analysis Template
Structured gap analysis workbook covering the four Annex A themes with remediation priority scoring and evidence mapping.
ISMS leads, GRC managers, and consultants running readiness assessments for Stage 1 certification.
A ready-to-run template for an ISO 27001:2022 gap analysis. It walks the four Annex A themes (organisational, people, physical, technological) and gives a scoring rubric that maps directly onto a remediation backlog.
How to use this template
Work through each of the four theme sections below. For every control, record the current state on the 0–4 maturity scale, capture the evidence source, and mark the remediation priority. The objective is a realistic picture of where the ISMS sits today — not to fabricate a green dashboard.
Maturity scoring rubric
- 0 — Not in place. No evidence the control has been considered.
- 1 — Informal. Ad-hoc activity exists but is undocumented and person-dependent.
- 2 — Defined. A documented policy or procedure exists but is not consistently applied.
- 3 — Operating. The control is documented, applied consistently, and evidence is captured.
- 4 — Measured. The control is operating, monitored, and continuously improved with metrics.
A.5 — Organisational controls (37 controls)
Policies, roles, supplier management, threat intelligence, classification, and incident management. This is typically where the largest volume of gaps sits on a first assessment.
- A.5.1 — Information security policies approved, published, and reviewed
- A.5.2 — Information security roles and responsibilities defined
- A.5.7 — Threat intelligence process in place
- A.5.19–A.5.23 — Supplier relationship and cloud-service controls
- A.5.24–A.5.30 — Incident management lifecycle (planning, response, lessons, evidence)
- A.5.31–A.5.37 — Legal, contractual, IP, PII, and documented operating procedures
A.6 — People controls (8 controls)
- A.6.1 — Screening prior to employment
- A.6.2 — Terms and conditions of employment reference security duties
- A.6.3 — Security awareness, education, and training programme
- A.6.4 — Disciplinary process for violations
- A.6.5 — Responsibilities after termination or change of employment
- A.6.7 — Remote working controls
- A.6.8 — Event reporting routes
A.7 — Physical controls (14 controls)
- A.7.1 — Physical security perimeters
- A.7.2 — Physical entry controls
- A.7.4 — Physical security monitoring
- A.7.5 — Protection against physical and environmental threats
- A.7.9 — Security of assets off-premises
- A.7.10 — Storage media handling
- A.7.14 — Secure disposal or reuse of equipment
A.8 — Technological controls (34 controls)
- A.8.1 — User endpoint devices
- A.8.2 — Privileged access rights
- A.8.5 — Secure authentication
- A.8.7 — Protection against malware
- A.8.8 — Management of technical vulnerabilities
- A.8.9 — Configuration management
- A.8.12 — Data leakage prevention
- A.8.16 — Monitoring activities
- A.8.22 — Segregation of networks
- A.8.23 — Web filtering
- A.8.24 — Use of cryptography
- A.8.25–A.8.28 — Secure development lifecycle
- A.8.29 — Security testing in development and acceptance
- A.8.32 — Change management
Output
The finished template produces: a heat-map per theme, a prioritised remediation backlog, and a list of controls that need Statement of Applicability entries — the three artefacts you need to enter Stage 1.
CyberZonic runs engagements that turn material like this into evidence.
If you need help scoping the work, turning this into a project plan, or running the assessment itself, get in touch.


