ISO 27001 information security gap analysis — know where you stand
160 structured questions covering every ISO 27001:2022 requirement — core ISMS clauses plus all 93 Annex A controls. Yes/Partial/No answers, instant gap identification, and a prioritised remediation roadmap for your information security management system.

11 sections, 160 questions
Every ISO 27001 core ISMS requirement and all 93 Annex A controls are broken into discrete questions. No ambiguity, no guesswork.
| Clause | Title | Questions |
|---|---|---|
| 4 | Context of the Organisation | 8 |
| 5 | Leadership | 14 |
| 6 | Planning | 14 |
| 7 | Support | 10 |
| 8 | Operation | 6 |
| 9 | Performance Evaluation | 10 |
| 10 | Improvement | 5 |
| A.5 | Organisational Controls | 37 |
| A.6 | People Controls | 8 |
| A.7 | Physical Controls | 14 |
| A.8 | Technological Controls | 34 |
| Total | 160 | |
Yes / Partial / No scoring
Information security controls are often partially implemented. The three-level scoring captures this nuance so you know exactly where to focus.
Yes
Fully in place. Score: 100%.
Partial
Partially in place. Score: 50%. A gap is flagged with targeted guidance.
No
Not in place. Score: 0%. A gap is identified with a specific recommendation.
Information Security Notice
This tool does not replace information security obligations under Australian privacy legislation (including the Privacy Act 1988 and Notifiable Data Breaches scheme) or other applicable regulations. Organisations remain legally responsible for protecting personal information and meeting all applicable security requirements regardless of the results of this assessment.
How it works
Create your organisation
Sign up, name your organisation, and select ISO 27001 as your standard.
Answer Yes, Partial, or No for each requirement
Work through each clause at your own pace. Each question has three response options to capture partial implementation. Your progress is saved automatically.
Review your information security gap report
Based on your responses, receive a prioritised list of ISMS gaps with specific recommendations, evidence requirements, and effort estimates.
Earn your certificate
Score 80% or above overall readiness and receive a Readiness Assessment Certificate to share with stakeholders.
Frequently asked questions
Ready to assess your ISO readiness?
Start your self-guided assessment today. No consultants, no surprises.
Get started