ISO 27001 Readiness Assessment
Performed a comprehensive ISO/IEC 27001 readiness assessment for a simulated organization to evaluate its current information security posture, identify control gaps, and develop a structured roadmap toward certification.
Rather than jumping directly into technical controls, I wanted to understand how organizations prepare for an information security management system. This project focused on evaluating governance, policies, operational procedures, and technical safeguards against ISO/IEC 27001 requirements.
I created a fictional company with realistic business processes, interviewed "stakeholders" using prepared questionnaires, reviewed documentation, and compared existing practices against Annex A controls.
- Assess organizational readiness for ISO 27001 certification.
- Review documentation supporting the ISMS.
- Identify missing or partially implemented controls.
- Prioritize remediation activities.
- Produce management-ready audit documentation.
- ISO/IEC 27001:2022
- Microsoft Excel
- Microsoft Word
- Risk Assessment Matrix
- Statement of Applicability (SoA)
Performed document reviews, mapped existing controls to ISO requirements, assessed implementation maturity, documented evidence, assigned risk ratings, and produced an executive summary with prioritized recommendations.
- ISO 27001 Gap Assessment Report
- Statement of Applicability (SoA)
- Control Maturity Matrix
- Executive Readiness Dashboard
- Remediation Roadmap
This project strengthened my understanding of ISMS implementation, audit evidence collection, control evaluation, and communicating technical findings in language suitable for management.