Skip to content

Gap-Analysis (SoA)

Gap analysis and the Statement of Applicability show where your organization stands against ISO 27001 or BSI IT-Grundschutz, and what is still missing before certification.

This page starts with how to operate the module in the fuentis Suite. The methodical background on gap analysis, SoA and IT-Grundschutz follows below under Methodical background.


Navigation: ISMS → Gap Analysis

The key point first: the overview starts out empty. You will see neither catalogs nor results as long as no gap analysis exists and no catalog is selected. Looking for content here is futile: an analysis has to be created first.

There are two ways to do that.

The recommended route. When creating a scope, tick the box Set up gap analysis for this scope based on the selected framework and main catalog in step 2 (ISMS framework and main catalog).

This creates the gap analysis automatically with the matching catalog, here ISO/IEC 27001/27002:2022.

Navigation: ISMS → Scope Definition → + Create scope

Setting up the gap analysis while creating the scope

Way 2: Directly in the Gap Analysis module

Section titled “Way 2: Directly in the Gap Analysis module”

Via the + Create gap analysis button at the top right. Use this route when the scope already exists. The form asks for:

  • Type of gap analysis (field at the top right): ISO or BSI. This choice drives which catalogs are offered below it.
  • Catalog: the analysis’s main catalog. You can assign further ones. Only assigned catalogs feed controls into the analysis.
  • Name and description.

Then Save.

Every standard catalog ships twice, once in German and once in English. You can spot the English one by the word Catalog in its name. The content is the same either way.

What differs is the language the controls come out in. Titles and descriptions follow the catalog, in the analysis and later in the report. The interface language does not help here, because it follows your user account: a German interface can happily show you English control names. So check the catalog before you save.

Even with an analysis in place the overview stays empty at first. The Please select catalog dropdown at the top left is where you pick the catalog. Only then do the gap analyses appear as cards.

Each card shows name, description, the underlying catalog, progress in percent and the associated scope.

Gap analysis overview with catalog selection

Practice tip: If progress reads 0 %, the analysis exists but no control has been assessed yet. That is the normal starting state.


Clicking a card opens the analysis. It has two tabs: SOA and Gap Analysis. Both work on the same catalog but show different views.

Step 1: Decide applicability per control (SOA tab)

Section titled “Step 1: Decide applicability per control (SOA tab)”

The SOA tab lists every control in the catalog — for ISO 27001 all 93 from Annex A. Per row you decide via the pencil icon on the right:

  • Applied: Yes or No
  • Reason for selection: e.g. Risk assessment
  • Justification: free text on why the decision was made

You can also tick several rows on the left and assess them together via Assign on the right. Saved rows turn green.

Reason for selection is a dropdown, not free text. It includes, among others:

ReasonWhen it fits
Legal requirementThe normal case for ISO 27001. Anyone aiming for certification has to consider Annex A.
Contractual requirementThe control comes out of a customer or supplier contract.
Business requirementAn internal rule, typical for your own catalogs.
Risk assessmentThe control answers a specific assessed risk.

The justification below it is free text. For controls you apply, a short standard sentence such as “ISO 27001 compliance” is enough. The field earns its keep on the exclusions: why a control does not apply is the question an auditor asks. An exclusion without a defensible reason stands out.

The controls marked Yes are your statement of applicability. Those marked No are the candidates for the gap review.

SOA tab with assessed controls

Step 2: Work the gaps in the Gap Analysis tab

Section titled “Step 2: Work the gaps in the Gap Analysis tab”

The Gap Analysis tab shows the controls that need action. The columns match the SOA tab, plus Status.

As long as a gap has not been assessed, the status reads Undefined. That is exactly the backlog: every row marked Undefined is waiting for a decision.

Gap Analysis tab with open items

Step 3: Check where the control has to be implemented

Section titled “Step 3: Check where the control has to be implemented”

Clicking a control’s name opens its detail view, which lists the target object groups it is already assigned to. That list is the real work plan: it shows how many places the control has to be implemented in before its status can move to Implemented.

An empty list means the control has been declared applicable but modeled nowhere. There is nothing to implement yet. The assignment is made in Modeling or out of a risk assessment.

The gap grows with the number of assignments. A control assigned to ten target object groups has to be implemented ten times and evidenced ten times. Some requirements you cover once, centrally, with a policy. Others you have to demonstrate process by process. How finely you cut your target object groups is decided during structural analysis. You live with the consequences here.

Via the pencil icon you set the implementation status per control:

  • Fully implemented
  • Partially implemented (with schedule)
  • Planned (with milestone plan)
  • Not applicable (with justification)

The route through Modeling does the same thing: open the target object group, open the control there, Edit, set the status to Implemented, Save. Both routes write to the same object.

The progress bar on the overview card follows as controls get assessed.

The two document icons above the table on the right export the analysis for management reviews and audits.

Exporting the gap analysis

Create report turns the analysis into a PDF that carries the evaluation out of the tool. The report only says something once applicability and assignments are in place. Before that it is mostly empty rows.

Practice tip: Use the export functions for regular management reviews. The visual presentation makes communicating ISMS progress easier.


The percentage on the overview card counts the controls you have applied within the scope, not all 93 from ISO 27001 Annex A.

An example: exactly one control is applied, 5.18 Access rights, and its status is Implemented. The gap analysis reads 100 %. Apply two more controls and the same state drops to 33 %, without anything having got worse.

Hence the order of work:

  1. Settle applicability first. Go through every control in the catalog and decide which ones apply.
  2. Then track implementation.

Do it the other way round and you are reporting a number that collapses every time another control is applied.

Note: In the fuentis flex version, gap analyses can be created directly in scoping.


A gap analysis in the ISMS context is a structured method for identifying the difference between an organization’s current security level and the requirements of a specific standard (ISO 27001, BSI IT-Grundschutz, or industry-specific requirements).

1. Capture Current State

  • Documentation of existing security measures
  • Assessment of the effectiveness of implemented controls
  • Identification of informal security practices

Note: This is accomplished in the Security Check/Modeling module.

2. Define Target Requirements

  • Systematic comparison with standard specifications
  • Consideration of legal and contractual requirements
  • Integration of industry-specific best practices

3. Identify Gaps

  • Categorization by criticality
  • Risk assessment of missing measures
  • Prioritization by implementation effort

gap-2

Note: This is handled in the Risk Analysis module.

4. Develop Action Plan

  • Concrete action recommendations
  • Resource planning and budgeting
  • Timeline toward certification readiness

Note: This is visible in the Risk Monitoring module (Risk Treatment Plan)

The gap analysis follows a structured process:

Phase 1: Preparation

  • Define scope and system boundaries
  • Assemble project team
  • Collect relevant documentation

Phase 2: Data Collection

  • Interviews with process owners
  • Review existing policies and procedures
  • Technical review of IT infrastructure

Phase 3: Assessment

  • Comparison with standard catalog
  • Maturity assessment of controls
  • Documentation of deviations

Phase 4: Reporting the Results

  • Creation of gap analysis report
  • Visualization of results
  • Derivation of action catalog

Practice Tip: Conduct the gap analysis iteratively. An initial rough analysis quickly provides an overview, while subsequent detailed analyses deepen specific areas.

gap-3

The Statement of Applicability is a central document in the ISO 27001 ISMS that lists all 93 controls from Annex A of the standard and documents for each individual measure:

  • Applicability: Is the control relevant for the organization?
  • Justification: Why was this decision made?
  • Implementation Status: What is the current implementation level?
  • References: Reference to supporting documents and evidence

1. Evidence of Risk Treatment The SoA documents how identified risks are addressed through specific controls. It creates the connection between risk analysis and measure implementation.

2. Certification Basis Auditors use the SoA as an audit basis. It defines the scope of certification and serves as a checklist during the audit.

3. Communication Tool The SoA makes security decisions transparent and comprehensible for management, auditors, and stakeholders.

4. Compliance Evidence It demonstrates the systematic engagement with all relevant security aspects and justifies conscious decisions.

Step 1: Control Assessment Each of the 93 controls from ISO 27001 Annex A is individually assessed:

  • Check relevance for the business model
  • Establish risk relationship
  • Conduct cost-benefit analysis

Step 2: Document Justification

  • When applied: How is the control implemented?
  • When not applied: Why is it not relevant?
  • Describe compensatory measures

gap-4

Step 3: Define Status

  • Fully implemented
  • Partially implemented (with schedule)
  • Planned (with milestone plan)
  • Not applicable (with justification)

Step 4: Continuous Updates

  • Regular reviews (at least annually)
  • Adjustments when scope changes
  • Integration of new risks and threats

Practice Tip: Use version control for your SoA. Document changes transparently to make the development of your ISMS clear.

Central Administration

  • All controls in a clear matrix
  • Filter and search functions
  • Versioning and change history

Collaboration

  • Assignment of responsibilities
  • Comment function for coordination
  • Workflow for approval processes

Export and Reporting

  • PDF export for management presentations
  • Audit-compliant documentation

While ISO 27001 follows a risk-based approach, BSI IT-Grundschutz works with building blocks and predefined protection requirements:

Basic Protection

  • Standardized measures for normal protection requirements
  • Quick implementation through building block catalog
  • Suitable for typical IT infrastructures

Standard Protection

  • Extended measures for higher protection requirements
  • Additional organizational controls
  • More detailed documentation requirements

Many organizations use a hybrid approach:

  1. IT-Grundschutz for IT infrastructure
  2. ISO 27001 for organization-wide processes
  3. Industry standards for specific requirements

Best Practices for Successful Gap Analyses

Section titled “Best Practices for Successful Gap Analyses”
  • Early involvement of senior management
  • Clear communication of benefits
  • Document resource commitments
  • Plan buffer times for unexpected findings
  • Prefer iterative approach
  • Identify and implement quick wins
  • Involve functional departments early
  • Reduce resistance through transparency
  • Communicate successes
  • Record decisions transparently
  • Systematically collect evidence
  • Build audit trail
  • Establish gap analysis as recurring process
  • Document lessons learned
  • Define KPIs for progress measurement

Problem: Informal security measures are overlooked Solution: Structured interviews with operational teams, shadow IT analysis

Problem: Attempt to close all gaps simultaneously Solution: Risk-based prioritization, develop phase model

Problem: Controls are perceived as bureaucracy Solution: Communicate benefits, streamline processes, automation

Problem: Budget and personnel for implementation are missing Solution: Create business case, external support, cloud solutions

  • Gap analysis identifies risks through missing controls
  • SoA documents risk treatment
  • Interaction in prioritization
  • Controls are integrated into processes
  • Process owners defined for controls
  • KPIs derived from gap analysis
  • SoA as audit basis
  • Gap analysis results as audit focus areas
  • Continuous monitoring of implementation
  • Gap analysis status as agenda item
  • SoA changes for approval
  • Resource decisions based on gaps
  1. Specify Action Plan

    • Define detailed work packages
    • Assign responsibilities
    • Set milestones
  2. Develop Policies

    • Create security policy
    • Derive specific policies
    • Formulate work instructions
  3. Technical Implementation

    • Implement security tools
    • Harden infrastructure
    • Set up monitoring
  4. Create Awareness

    • Develop training program
    • Establish security champions
    • Foster security culture
  5. Certification Preparation

    • Conduct pre-audit
    • Complete documentation
    • Select certification body