Gap-Analysis (SoA)
Gap analysis and the Statement of Applicability (SoA) (baseline) form the strategic foundation for the successful establishment of an Information Security Management System (ISMS). These systematic tools enable organizations to objectively assess the current security status and develop a clear roadmap to achieve the desired certification.
Why are these instruments indispensable? In the complex landscape of information security, they create transparency about existing protective measures and precisely identify where action is needed. This not only saves time and resources but also minimizes the risk of compliance violations and security gaps.
Gap Analysis: Systematic Inventory
Section titled “Gap Analysis: Systematic Inventory”Definition and Purpose
Section titled “Definition and Purpose”A gap analysis in the ISMS context is a structured method for identifying the difference between an organization’s current security level and the requirements of a specific standard (ISO 27001, BSI IT-Grundschutz, or industry-specific requirements).
Core Objectives of Gap Analysis
Section titled “Core Objectives of Gap Analysis”1. Capture Current State
- Documentation of existing security measures
- Assessment of the effectiveness of implemented controls
- Identification of informal security practices
Note: This is accomplished in the Security Check/Modeling module.

2. Define Target Requirements
- Systematic comparison with standard specifications
- Consideration of legal and contractual requirements
- Integration of industry-specific best practices
3. Identify Gaps
- Categorization by criticality
- Risk assessment of missing measures
- Prioritization by implementation effort

Note: This is handled in the Risk Analysis module.
4. Develop Action Plan
- Concrete action recommendations
- Resource planning and budgeting
- Temporal roadmap to certification readiness
Note: This is visible in the Risk Monitoring module (Risk Treatment Plan)
Implementation Methodology
Section titled “Implementation Methodology”The gap analysis follows a structured process:
Phase 1: Preparation
- Define scope and system boundaries
- Assemble project team
- Collect relevant documentation
Phase 2: Data Collection
- Interviews with process owners
- Review existing policies and procedures
- Technical review of IT infrastructure
Phase 3: Assessment
- Comparison with standard catalog
- Maturity assessment of controls
- Documentation of deviations
Phase 4: Results Preparation
- Creation of gap analysis report
- Visualization of results
- Derivation of action catalog
Practice Tip: Conduct the gap analysis iteratively. An initial rough analysis quickly provides an overview, while subsequent detailed analyses deepen specific areas.

Statement of Applicability (SoA): The Heart of ISO 27001
Section titled “Statement of Applicability (SoA): The Heart of ISO 27001”Concept and Significance
Section titled “Concept and Significance”The Statement of Applicability is a central document in the ISO 27001 ISMS that lists all 93 controls from Annex A of the standard and documents for each individual measure:
- Applicability: Is the control relevant for the organization?
- Justification: Why was this decision made?
- Implementation Status: What is the current implementation level?
- References: Reference to supporting documents and evidence
Functions of the SoA
Section titled “Functions of the SoA”1. Evidence of Risk Treatment The SoA documents how identified risks are addressed through specific controls. It creates the connection between risk analysis and measure implementation.
2. Certification Basis Auditors use the SoA as an audit basis. It defines the scope of certification and serves as a checklist during the audit.
3. Communication Tool The SoA makes security decisions transparent and comprehensible for management, auditors, and stakeholders.
4. Compliance Evidence It demonstrates the systematic engagement with all relevant security aspects and justifies conscious decisions.
Creation and Maintenance of the SoA
Section titled “Creation and Maintenance of the SoA”Step 1: Control Assessment Each of the 93 controls from ISO 27001 Annex A is individually assessed:
- Check relevance for the business model
- Establish risk relationship
- Conduct cost-benefit analysis
Step 2: Document Justification
- When applied: How is the control implemented?
- When not applied: Why is it not relevant?
- Describe compensatory measures

Step 3: Define Status
- Fully implemented
- Partially implemented (with schedule)
- Planned (with milestone plan)
- Not applicable (with justification)
Step 4: Continuous Updates
- Regular reviews (at least annually)
- Adjustments when scope changes
- Integration of new risks and threats
Practice Tip: Use version control for your SoA. Document changes transparently to make the development of your ISMS clear.
Integration of BSI IT-Grundschutz
Section titled “Integration of BSI IT-Grundschutz”Specifics of IT-Grundschutz
Section titled “Specifics of IT-Grundschutz”While ISO 27001 follows a risk-based approach, BSI IT-Grundschutz works with building blocks and predefined protection requirements:
Basic Protection
- Standardized measures for normal protection requirements
- Quick implementation through building block catalog
- Suitable for typical IT infrastructures
Standard Protection
- Extended measures for higher protection requirements
- Additional organizational controls
- More detailed documentation requirements
Combined Approach
Section titled “Combined Approach”Many organizations use a hybrid approach:
- IT-Grundschutz for IT infrastructure
- ISO 27001 for organization-wide processes
- Industry standards for specific requirements
Practical Implementation with the fuentis Suite
Section titled “Practical Implementation with the fuentis Suite”Digital Gap Analysis
Section titled “Digital Gap Analysis”The fuentis Suite automates essential steps of the gap analysis.


Note: In the fuentis flex version, gap analyses can be created directly in scoping.


SoA Management
Section titled “SoA Management”Central Administration
- All controls in a clear matrix
- Filter and search functions
- Versioning and change history
Collaboration
- Assignment of responsibilities
- Comment function for coordination
- Workflow for approval processes
Export and Reporting
- PDF export for management presentations
- Audit-compliant documentation
Practice Tip: Use the export functions for regular management reviews. Visual preparation facilitates communication of ISMS progress.

Best Practices for Successful Gap Analyses
Section titled “Best Practices for Successful Gap Analyses”1. Secure Top Management Support
Section titled “1. Secure Top Management Support”- Early involvement of senior management
- Clear communication of benefits
- Document resource commitments
2. Realistic Planning
Section titled “2. Realistic Planning”- Plan buffer times for unexpected findings
- Prefer iterative approach
- Identify and implement quick wins
3. Include Stakeholders
Section titled “3. Include Stakeholders”- Involve functional departments early
- Reduce resistance through transparency
- Communicate successes
4. Documentation from the Start
Section titled “4. Documentation from the Start”- Record decisions transparently
- Systematically collect evidence
- Build audit trail
5. Continuous Improvement
Section titled “5. Continuous Improvement”- Establish gap analysis as recurring process
- Document lessons learned
- Define KPIs for progress measurement
Common Challenges and Solution Approaches
Section titled “Common Challenges and Solution Approaches”Challenge 1: Incomplete Inventory
Section titled “Challenge 1: Incomplete Inventory”Problem: Informal security measures are overlooked Solution: Structured interviews with operational teams, shadow IT analysis
Challenge 2: Overambitious Goals
Section titled “Challenge 2: Overambitious Goals”Problem: Attempt to close all gaps simultaneously Solution: Risk-based prioritization, develop phase model
Challenge 3: Lack of Acceptance
Section titled “Challenge 3: Lack of Acceptance”Problem: Controls are perceived as bureaucracy Solution: Communicate benefits, streamline processes, automation
Challenge 4: Resource Shortage
Section titled “Challenge 4: Resource Shortage”Problem: Budget and personnel for implementation are missing Solution: Create business case, external support, cloud solutions
Connection to Other ISMS Components
Section titled “Connection to Other ISMS Components”Risk Analysis
Section titled “Risk Analysis”- Gap analysis identifies risks through missing controls
- SoA documents risk treatment
- Interaction in prioritization
Process Landscape
Section titled “Process Landscape”- Controls are integrated into processes
- Process owners defined for controls
- KPIs derived from gap analysis
Internal Audit
Section titled “Internal Audit”- SoA as audit basis
- Gap analysis results as audit focus areas
- Continuous monitoring of implementation
Management Review
Section titled “Management Review”- Gap analysis status as agenda item
- SoA changes for approval
- Resource decisions based on gaps
Further Steps After Gap Analysis
Section titled “Further Steps After Gap Analysis”-
Specify Action Plan
- Define detailed work packages
- Assign responsibilities
- Set milestones
-
Develop Policies
- Create security policy
- Derive specific policies
- Formulate work instructions
-
Technical Implementation
- Implement security tools
- Harden infrastructure
- Set up monitoring
-
Create Awareness
- Develop training program
- Establish security champions
- Foster security culture
-
Certification Preparation
- Conduct pre-audit
- Complete documentation
- Select certification body
Key Messages at a Glance
Section titled “Key Messages at a Glance”✓ Gap Analysis as Starting Point: The systematic inventory creates transparency about the current security status and defines the path to certification
✓ SoA as Central Control Instrument: The Statement of Applicability documents conscious security decisions and serves as evidence of systematic risk treatment
✓ Iterative Approach: Successful ISMS implementation occurs step by step with regular reviews and continuous improvement
✓ Tool Support Essential: Digital solutions like the fuentis Suite significantly simplify administration, tracking, and reporting
✓ Holistic Approach: Gap analysis and SoA are not isolated documents but integral components of the entire ISMS lifecycle