02 · Selected Work

ISO 27001 Readiness Assessment

ISO 27001 GRC Gap Assessment

Performed a comprehensive ISO/IEC 27001 readiness assessment for a simulated organization to evaluate its current information security posture, identify control gaps, and develop a structured roadmap toward certification.

Role
IT/IS Auditor
Environment
Simulated Enterprise
Framework Mapping
ISO/IEC 27001:2022
Overview

Rather than jumping directly into technical controls, I wanted to understand how organizations prepare for an information security management system. This project focused on evaluating governance, policies, operational procedures, and technical safeguards against ISO/IEC 27001 requirements.

I created a fictional company with realistic business processes, interviewed "stakeholders" using prepared questionnaires, reviewed documentation, and compared existing practices against Annex A controls.

Objectives
Tools & Stack
Process

Performed document reviews, mapped existing controls to ISO requirements, assessed implementation maturity, documented evidence, assigned risk ratings, and produced an executive summary with prioritized recommendations.

Findings & Deliverables
Outcome & Reflection

This project strengthened my understanding of ISMS implementation, audit evidence collection, control evaluation, and communicating technical findings in language suitable for management.

Selected Work