Information security

Gap assessment and maturity evaluation

To improve information security management you first have to know your starting point. The assessment establishes the real gaps and turns a hunch about risk into a plan with priorities, effort and owners.

Typical duration
3 to 6 weeks
Delivery
Blended — on site and remote
Deliverable
Report and prioritised roadmap
Technical scope
High-level vulnerability analysis

Objective and scope

We determine how far each of the 93 Annex A controls of ISO/IEC 27001:2022 is implemented, through personal interviews, document review and technical verification. Our six-level maturity scale gives an objective reading of compliance and a holistic view by control domain, from which the optimal plan in terms of priority and effort follows.


Project phases

Phase 1

Planning and interviews

We define the scope, identify the counterparts and interview the business, IT and support teams to understand processes, assets and dependencies.

Phase 2

Document and technical review

We review existing policies, procedures and records, and run a high-level vulnerability analysis over exposed infrastructure and systems.

Phase 3

Maturity evaluation

We assess the 93 controls independently against the six-level scale, giving the current state control by control and domain by domain.

Phase 4

Report and roadmap

We present the Board with the gaps, the level of risk being carried, the immediate actions and a plan prioritised by criticality and effort, with an estimate of the resources required.


What the implementation includes

  • Interviews with business and IT teams
  • Review of documented information
  • Assessment of the 93 Annex A controls
  • Six-level maturity scale
  • High-level vulnerability analysis
  • Identification of immediate actions
  • Roadmap prioritised by criticality
  • Executive presentation to the Board

Frequently asked questions

Is it useful if we do not want to certify?

Yes, and that is the most common case. The assessment uses ISO/IEC 27001 as its frame of reference because it is complete and widely recognised, but the deliverable is a security roadmap that is useful regardless of any decision to certify.

Is it a penetration test?

No. It includes a high-level vulnerability analysis over infrastructure and systems, which is broader and shallower than a pentest. If you need a focused penetration test, we handle that as a separate engagement.

How often should it be repeated?

Annually, or whenever something significant changes: a merger, a change of critical IT supplier, a new line of business or a serious incident.

your business partner

Protecting you today, innovating for tomorrow