Skip to content
home
we are
we do
the client series
DORA compliance podcasts
gap assessment tools
we use
we upskill
self study
contact
home
we are
we do
the client series
DORA compliance podcasts
gap assessment tools
we use
we upskill
self study
contact
ISO 27001 Gap Assessment
ISO/IEC 27001 Gap Assessment (sample)
1. Do you have a documented Information Security Management System (ISMS) Policy?
Yes
No
2. Have you defined the scope of your ISMS based on organizational context?
Yes
No
3. Have you conducted a formal risk assessment using a repeatable methodology?
Yes
No
4. Is there a documented Statement of Applicability (SoA) based on Annex A controls?
Yes
No
5. Are information security objectives documented and monitored?
Yes
No
6. Is there a documented risk treatment plan, and is it regularly updated?
Yes
No
7. Are roles and responsibilities for information security clearly assigned?
Yes
No
8. Do you perform internal audits of your ISMS at planned intervals?
Yes
No
9. Is management review of the ISMS conducted annually or upon major changes?
Yes
No
10. Do you have documented procedures for incident reporting and response?
Yes
No
Assess
DORA Gap Assessment
DORA Regulation Gap Assessment (sample)
1. Have you documented your organization's Digital Operational Resilience Strategy?
Yes
No
2. Are ICT risk management frameworks implemented and regularly reviewed?
Yes
No
3. Do you have procedures for managing ICT-related incidents and disruptions?
Yes
No
4. Is there a formal process for ICT third-party risk management and due diligence?
Yes
No
5. Are ICT systems regularly tested for operational resilience, including penetration testing?
Yes
No
6. Do you have an incident classification and escalation procedure in line with DORA requirements?
Yes
No
7. Are business continuity and disaster recovery plans regularly tested and updated?
Yes
No
8. Is there a designated ICT risk management function with clear roles and responsibilities?
Yes
No
9. Have you implemented controls for ICT asset inventory and configuration management?
Yes
No
10. Are ICT third-party providers monitored continuously for compliance and performance?
Yes
No
Assess
NIS2 Gap Assessment
NIS 2 Directive Gap Assessment (sample)
1. Have you identified your organization as an essential or important entity under NIS 2?
Yes
No
2. Do you have documented and enforced cybersecurity policies and procedures?
Yes
No
3. Have you implemented access control mechanisms (e.g., MFA, role-based access)?
Yes
No
4. Is your organization capable of detecting and managing cybersecurity incidents?
Yes
No
5. Are incident notification protocols in place and aligned with national CSIRTs?
Yes
No
6. Have you identified dependencies and risks in your supply chain?
Yes
No
7. Is there a responsible person or team for cybersecurity compliance within your organization?
Yes
No
8. Do you conduct periodic cybersecurity training and awareness programs?
Yes
No
9. Have you tested your incident response and business continuity plans?
Yes
No
10. Do you ensure system updates and vulnerability patches are applied in a timely manner?
Yes
No
Assess
error:
Content is protected !!