The Elsmar Cove Wiki More Free Files The Elsmar Cove Forums Discussion Thread Index Post Attachments Listing Failure Modes Services and Solutions to Problems Elsmar cove Forums Main Page Elsmar Cove Home Page
Google
  Web Elsmar.com
*Please be aware that SOME RECENT forum threads may not yet be indexed by Google.

View Full Version : ISO 27001 Gap Assessment content vs. Risk Assessment


romelroche
22nd July 2009, 11:41 AM
Hi,

I'm kinda new to the ISO 27001 standard and was wondering if I could get some views on what a gap assessment should cover. I been told by a number of people that it is performed to evaluate the readiness of the organization against all clauses (4 to 8).

However some mention that the controls (A.5 to A.15) are also to be checked against. Isn't an RA performed to check this ?

Any clarifications would help. Thanks

harry
23rd July 2009, 09:00 AM
Perhaps a view of a gap analysis worksheet on ISO 27001 and found in this post (http://elsmar.com/Forums/showpost.php?p=239843&postcount=1) may be helpful.

romelroche
27th July 2009, 04:07 AM
Thanks Harry!!!!