Skip to content

Gap-Analysis (SoA)

Gap analysis and the Statement of Applicability (SoA) (baseline) form the strategic foundation for the successful establishment of an Information Security Management System (ISMS). These systematic tools enable organizations to objectively assess the current security status and develop a clear roadmap to achieve the desired certification.

Why are these instruments indispensable? In the complex landscape of information security, they create transparency about existing protective measures and precisely identify where action is needed. This not only saves time and resources but also minimizes the risk of compliance violations and security gaps.

A gap analysis in the ISMS context is a structured method for identifying the difference between an organization’s current security level and the requirements of a specific standard (ISO 27001, BSI IT-Grundschutz, or industry-specific requirements).

1. Capture Current State

  • Documentation of existing security measures
  • Assessment of the effectiveness of implemented controls
  • Identification of informal security practices

Note: This is accomplished in the Security Check/Modeling module.

gap-1

2. Define Target Requirements

  • Systematic comparison with standard specifications
  • Consideration of legal and contractual requirements
  • Integration of industry-specific best practices

3. Identify Gaps

  • Categorization by criticality
  • Risk assessment of missing measures
  • Prioritization by implementation effort

gap-2

Note: This is handled in the Risk Analysis module.

4. Develop Action Plan

  • Concrete action recommendations
  • Resource planning and budgeting
  • Temporal roadmap to certification readiness

Note: This is visible in the Risk Monitoring module (Risk Treatment Plan)

The gap analysis follows a structured process:

Phase 1: Preparation

  • Define scope and system boundaries
  • Assemble project team
  • Collect relevant documentation

Phase 2: Data Collection

  • Interviews with process owners
  • Review existing policies and procedures
  • Technical review of IT infrastructure

Phase 3: Assessment

  • Comparison with standard catalog
  • Maturity assessment of controls
  • Documentation of deviations

Phase 4: Results Preparation

  • Creation of gap analysis report
  • Visualization of results
  • Derivation of action catalog

Practice Tip: Conduct the gap analysis iteratively. An initial rough analysis quickly provides an overview, while subsequent detailed analyses deepen specific areas.

gap-3

Statement of Applicability (SoA): The Heart of ISO 27001

Section titled “Statement of Applicability (SoA): The Heart of ISO 27001”

The Statement of Applicability is a central document in the ISO 27001 ISMS that lists all 93 controls from Annex A of the standard and documents for each individual measure:

  • Applicability: Is the control relevant for the organization?
  • Justification: Why was this decision made?
  • Implementation Status: What is the current implementation level?
  • References: Reference to supporting documents and evidence

1. Evidence of Risk Treatment The SoA documents how identified risks are addressed through specific controls. It creates the connection between risk analysis and measure implementation.

2. Certification Basis Auditors use the SoA as an audit basis. It defines the scope of certification and serves as a checklist during the audit.

3. Communication Tool The SoA makes security decisions transparent and comprehensible for management, auditors, and stakeholders.

4. Compliance Evidence It demonstrates the systematic engagement with all relevant security aspects and justifies conscious decisions.

Step 1: Control Assessment Each of the 93 controls from ISO 27001 Annex A is individually assessed:

  • Check relevance for the business model
  • Establish risk relationship
  • Conduct cost-benefit analysis

Step 2: Document Justification

  • When applied: How is the control implemented?
  • When not applied: Why is it not relevant?
  • Describe compensatory measures

gap-4

Step 3: Define Status

  • Fully implemented
  • Partially implemented (with schedule)
  • Planned (with milestone plan)
  • Not applicable (with justification)

Step 4: Continuous Updates

  • Regular reviews (at least annually)
  • Adjustments when scope changes
  • Integration of new risks and threats

Practice Tip: Use version control for your SoA. Document changes transparently to make the development of your ISMS clear.

While ISO 27001 follows a risk-based approach, BSI IT-Grundschutz works with building blocks and predefined protection requirements:

Basic Protection

  • Standardized measures for normal protection requirements
  • Quick implementation through building block catalog
  • Suitable for typical IT infrastructures

Standard Protection

  • Extended measures for higher protection requirements
  • Additional organizational controls
  • More detailed documentation requirements

Many organizations use a hybrid approach:

  1. IT-Grundschutz for IT infrastructure
  2. ISO 27001 for organization-wide processes
  3. Industry standards for specific requirements

Practical Implementation with the fuentis Suite

Section titled “Practical Implementation with the fuentis Suite”

The fuentis Suite automates essential steps of the gap analysis.

gap-7

gap-8

Note: In the fuentis flex version, gap analyses can be created directly in scoping.

gap-5

gap-6

Central Administration

  • All controls in a clear matrix
  • Filter and search functions
  • Versioning and change history

Collaboration

  • Assignment of responsibilities
  • Comment function for coordination
  • Workflow for approval processes

Export and Reporting

  • PDF export for management presentations
  • Audit-compliant documentation

Practice Tip: Use the export functions for regular management reviews. Visual preparation facilitates communication of ISMS progress.

gap-9

Best Practices for Successful Gap Analyses

Section titled “Best Practices for Successful Gap Analyses”
  • Early involvement of senior management
  • Clear communication of benefits
  • Document resource commitments
  • Plan buffer times for unexpected findings
  • Prefer iterative approach
  • Identify and implement quick wins
  • Involve functional departments early
  • Reduce resistance through transparency
  • Communicate successes
  • Record decisions transparently
  • Systematically collect evidence
  • Build audit trail
  • Establish gap analysis as recurring process
  • Document lessons learned
  • Define KPIs for progress measurement

Problem: Informal security measures are overlooked Solution: Structured interviews with operational teams, shadow IT analysis

Problem: Attempt to close all gaps simultaneously Solution: Risk-based prioritization, develop phase model

Problem: Controls are perceived as bureaucracy Solution: Communicate benefits, streamline processes, automation

Problem: Budget and personnel for implementation are missing Solution: Create business case, external support, cloud solutions

  • Gap analysis identifies risks through missing controls
  • SoA documents risk treatment
  • Interaction in prioritization
  • Controls are integrated into processes
  • Process owners defined for controls
  • KPIs derived from gap analysis
  • SoA as audit basis
  • Gap analysis results as audit focus areas
  • Continuous monitoring of implementation
  • Gap analysis status as agenda item
  • SoA changes for approval
  • Resource decisions based on gaps
  1. Specify Action Plan

    • Define detailed work packages
    • Assign responsibilities
    • Set milestones
  2. Develop Policies

    • Create security policy
    • Derive specific policies
    • Formulate work instructions
  3. Technical Implementation

    • Implement security tools
    • Harden infrastructure
    • Set up monitoring
  4. Create Awareness

    • Develop training program
    • Establish security champions
    • Foster security culture
  5. Certification Preparation

    • Conduct pre-audit
    • Complete documentation
    • Select certification body

Gap Analysis as Starting Point: The systematic inventory creates transparency about the current security status and defines the path to certification

SoA as Central Control Instrument: The Statement of Applicability documents conscious security decisions and serves as evidence of systematic risk treatment

Iterative Approach: Successful ISMS implementation occurs step by step with regular reviews and continuous improvement

Tool Support Essential: Digital solutions like the fuentis Suite significantly simplify administration, tracking, and reporting

Holistic Approach: Gap analysis and SoA are not isolated documents but integral components of the entire ISMS lifecycle