Security / ISO 27001 readiness

ISO 27001 gap assessment and readiness.

A tender clause or a board decision means ISO 27001:2022. The gap assessment says how far away you are.

Sorami runs a clause-by-clause gap assessment against ISO 27001:2022 and produces three things: a findings report, a draft Statement of Applicability and an evidence plan. Certification itself is issued by a JAS-ANZ accredited certification body, which Sorami is not. Readiness is the work that shortens that audit.

Included

What the work covers

  • Clause 4 to 10 gap assessment against ISO 27001:2022.
  • Annex A control review with the evidence each one needs.
  • Statement of Applicability draft with justified exclusions.
  • Risk assessment method your team can repeat.
  • Internal audit plan and certification body liaison.
Excluded

What we do not do

  • The certification audit. That is an accredited certification body.
  • Running the ISMS after certification.
  • Writing policies nobody will follow.
The clauses this work touches

Named, so you can check us.

ISO/IEC 27001:2022. Annex A is a reference set of 93 controls you may exclude with justification. Clauses 4 to 10 are the management system and cannot be excluded, which is where most readiness projects are actually behind.

Management system, mandatory
ReferenceWhat it requiresWhat readiness produces
Clause 4.3Determining the scope of the ISMSA scope statement that matches the product, not the whole company.
Clause 6.1.2Information security risk assessmentA method with criteria and thresholds, run rather than documented.
Clause 6.1.3 dStatement of ApplicabilityAll 93 Annex A controls, each with applicability, justification and what implements it.
Clause 9.2Internal auditAn audit programme with competent auditors and retained results.
Clause 9.3Management reviewMinuted reviews with the required inputs, at planned intervals.
Clause 10.2Nonconformity and corrective actionA corrective action record that closes the loop.
Annex A controls most often gapped
ReferenceWhat it requiresWhat readiness produces
A.5.15Access controlRules that match what production actually enforces.
A.5.23Information security for use of cloud servicesNew in the 2022 revision. Usually the largest gap for a cloud team.
A.5.24Information security incident management planning and preparationA plan that has been exercised, not only written.
A.8.2Privileged access rightsTime-bound privilege with a revalidation record.
A.8.5Secure authenticationMulti-factor authentication on every administrative path.
A.8.8Management of technical vulnerabilitiesA scan cadence, an owner and a due date per finding.
A.8.9Configuration managementNew in 2022. Baselines, and drift you can detect.
A.8.15LoggingLogs the people being logged cannot alter.
A.8.16Monitoring activitiesAlerts that reach someone accountable.
A.8.28Secure codingNew in 2022. Review and dependency handling in the pipeline.

Source. ISO/IEC 27001:2022. Identifiers verified against the primary source, not quoted from a summary.

A certification body reads the Statement of Applicability first, because it is the map between your risk assessment and everything they are about to test. Sorami prepares that document. The certificate is issued by an accredited certification body, not by us.

Failure modes

What usually goes wrong.

  • A scope statement that excludes the system the customer cares about.
  • Risk assessment done once for the certificate, then never again.
  • Policies describing a company that does not exist.
  • Evidence gathered by hand in the fortnight before the audit.
Questions before you book

Practical answers.

Is Sorami ISO 27001 certified?

No. Sorami is not ISO 27001 certified and is not a certification body. We prepare your organisation for an accredited body to audit.

Gap assessment or full readiness?

The gap assessment is two to three weeks and tells you the distance. Readiness closes it and takes three to six months for most teams starting without an ISMS.

ISO 27001 or SOC 2?

ISO 27001 for tenders, government and international buyers. SOC 2 for US enterprise buyers. The control sets overlap heavily, so do the work once.

Which version?

ISO 27001:2022, including the restructured Annex A control set.

Requesters often name the wrong standard. If the wording actually points at an American customer or a software buyer, SOC 2 readiness is the closer fit, and privacy obligations sit with GDPR and Privacy Act readiness. Annex A control A.8.8 usually needs a test behind it, which is penetration testing, and running the controls afterwards is what the vCISO retainer covers.

Let’s scope it

Ready to scope iso 27001 readiness?

Send the requester wording and your deadline. We will confirm scope and fee before any work starts.

Request a quote

Last reviewed: