RPG Excellence
Sign inBook
NEW STANDARDISO 9001:2026 is now publishedSee what changed and prepare your quality management system.
Read full update
← Back to RPG InsightsRPG Insights • Issue 013

ISO/IEC 27001 Readiness: Connecting Gap Analysis and the Statement of Applicability

Two connected workspaces answer different assurance questions: whether the ISMS meets the standard's requirements and how the organisation has selected, implemented and evidenced its information-security controls.

ISO/IEC 27001 is more than a control checklist

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining and continually improving an information security management system. It connects information risk with organisational context, leadership, planning, support, operation, performance evaluation and improvement.

A review limited to technical controls can miss whether the wider system is governed, resourced, understood and evaluated. Equally, a clause-by- clause gap analysis does not by itself explain which controls the organisation has selected or why.

The readiness principleAssess the management system and control the applicability decisions—without confusing one record for the other.

Two workspaces, two purposes

Gap Analysis

Evaluate the management system against ISO/IEC 27001 requirements.

  • What is implemented?
  • What objective evidence supports the assessment?
  • Where are the findings, gaps and actions?
  • What does management need to prioritise?
Statement of Applicability

Control the organisation’s decisions about information-security controls.

  • Which controls are applicable?
  • Why is each control included or excluded?
  • What is its implementation position?
  • Who owns it and what evidence supports it?

An evidence-led gap analysis

A useful gap analysis should do more than mark a requirement compliant or non-compliant. The assessor should record the current position, objective evidence, the significance of any gap and the action needed to improve readiness.

RPG Excellence connects requirement-level assessment with evidence, formal findings, accountable actions and management reporting. This makes it possible to distinguish documented intention from implemented practice and to see where management decisions or resources are required.

A Statement of Applicability should be organisation-specific

The Statement of Applicability should reflect the organisation's information-security risks, obligations and chosen treatment. It should not be a generic control list copied from another organisation or completed only to satisfy an external audit request.

A control marked as implemented should be supported by evidence. An exclusion needs a defensible rationale. A planned improvement should remain visible as an action rather than being presented as a completed control.

01Applicability decision
02Inclusion or exclusion rationale
03Implementation status
04Control owner
05Objective evidence
06Residual-risk consideration
07Actions and target dates
08Review and approval record

Connect risk, control and management attention

The strongest value appears when gap-analysis findings, applicability decisions, evidence and action ownership can be viewed together. This helps management understand not only whether a document exists, but whether the ISMS is operating and whether selected controls are justified and effective.

A controlled workspace also preserves the audit trail. Reviewers can see the decision, rationale, evidence, owner, implementation status and subsequent change rather than relying on an overwritten spreadsheet.

Use the tools for readiness—not as a certification claim

RPG Excellence supports structured self- assessment, evidence gathering, action planning and management readiness. It does not issue accredited ISO certification, guarantee conformity or replace competent information- security, legal or certification advice.

Used with appropriate competence, the Gap Analysis and Statement of Applicability can provide a more disciplined starting point for implementation, internal review and certification preparation.

Explore ISO/IEC 27001 readiness

Start an evidence-led ISO/IEC 27001 Gap Analysis or use the standalone Statement of Applicability workspace to manage control decisions, ownership and evidence.

Explore ISO/IEC 27001View access options

References: ISO/IEC 27001:2022 and the UK National Cyber Security Centre's guidance on managing security risk. ISO standards are copyrighted; users should obtain authorised copies where required.

ISO/IEC 27001 Readiness: Connecting Gap Analysis and the Statement of Applicability | RPG Insights | RPG Excellence