ISO/IEC 27001 is more than a control checklist
ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining and continually improving an information security management system. It connects information risk with organisational context, leadership, planning, support, operation, performance evaluation and improvement.
A review limited to technical controls can miss whether the wider system is governed, resourced, understood and evaluated. Equally, a clause-by- clause gap analysis does not by itself explain which controls the organisation has selected or why.
Two workspaces, two purposes
Evaluate the management system against ISO/IEC 27001 requirements.
- What is implemented?
- What objective evidence supports the assessment?
- Where are the findings, gaps and actions?
- What does management need to prioritise?
Control the organisation’s decisions about information-security controls.
- Which controls are applicable?
- Why is each control included or excluded?
- What is its implementation position?
- Who owns it and what evidence supports it?
An evidence-led gap analysis
A useful gap analysis should do more than mark a requirement compliant or non-compliant. The assessor should record the current position, objective evidence, the significance of any gap and the action needed to improve readiness.
RPG Excellence connects requirement-level assessment with evidence, formal findings, accountable actions and management reporting. This makes it possible to distinguish documented intention from implemented practice and to see where management decisions or resources are required.
A Statement of Applicability should be organisation-specific
The Statement of Applicability should reflect the organisation's information-security risks, obligations and chosen treatment. It should not be a generic control list copied from another organisation or completed only to satisfy an external audit request.
A control marked as implemented should be supported by evidence. An exclusion needs a defensible rationale. A planned improvement should remain visible as an action rather than being presented as a completed control.
Connect risk, control and management attention
The strongest value appears when gap-analysis findings, applicability decisions, evidence and action ownership can be viewed together. This helps management understand not only whether a document exists, but whether the ISMS is operating and whether selected controls are justified and effective.
A controlled workspace also preserves the audit trail. Reviewers can see the decision, rationale, evidence, owner, implementation status and subsequent change rather than relying on an overwritten spreadsheet.
Use the tools for readiness—not as a certification claim
RPG Excellence supports structured self- assessment, evidence gathering, action planning and management readiness. It does not issue accredited ISO certification, guarantee conformity or replace competent information- security, legal or certification advice.
Used with appropriate competence, the Gap Analysis and Statement of Applicability can provide a more disciplined starting point for implementation, internal review and certification preparation.
Explore ISO/IEC 27001 readiness
Start an evidence-led ISO/IEC 27001 Gap Analysis or use the standalone Statement of Applicability workspace to manage control decisions, ownership and evidence.
References: ISO/IEC 27001:2022 and the UK National Cyber Security Centre's guidance on managing security risk. ISO standards are copyrighted; users should obtain authorised copies where required.
