Case Study: ISO 27001 Gap Assessment and Certification Roadmap
Client: A mid-tier Australian retail service provider
The client needed a roadmap to ISO 27001 certification. Fortian's gap assessment, conducted by a qualified ISO 27001 Lead Auditor against ISO/IEC 27001:2022, delivered a clear, prioritised path to first-time certification, which the client achieved after completing the remediation activities.
The Challenge
The client had made a strategic commitment to achieving ISO 27001 certification for the first time. What it needed was a clear roadmap to get there:
- Some security controls already established across the business, though not yet drawn together into a formal Information Security Management System (ISMS)
- Existing controls that had grown to meet operational need rather than being mapped systematically to the ISO 27001 clauses and Annex A control set
- A requirement to understand which gaps stood between the client and certification, and in what order to close them
- A requirement to give the executive a credible view of the effort, cost and timeline involved before committing to certification
Our Approach
Fortian assessed the client against ISO/IEC 27001:2022 using a qualified ISO 27001 Lead Auditor, covering both the management system clauses and the Annex A control set, and translated the findings into a remediation roadmap the client could act on. Gaps were prioritised and sequenced so the client knew what to tackle first and how each activity built toward the next. The engagement covered:
- Scope Refinement – Worked with the client to refine its certification scope, tightening the boundaries of the ISMS before assessment began
- Management System Assessment – Assessed the client against the mandatory ISO 27001 management system clauses, covering context, leadership, planning, support, operation, performance evaluation and improvement
- Annex A Control Assessment – Assessed current controls against the 93 Annex A controls across the four themes of organisational, people, physical and technological, recognising the controls already in place and identifying where further work was needed
- Gap Prioritisation – Ranked identified gaps by their significance to certification and by the effort required to close them, so remediation could be sequenced sensibly
- Remediation Roadmap – Produced a prioritised, sequenced roadmap to certification readiness, setting out the work required, its order, and the dependencies between activities
- Stakeholder Engagement – Engaged the executive sponsor and security, technology and risk stakeholders throughout, so findings reflected operational reality and the roadmap aligned with organisational priorities
Delivery Approach
Fortian ran the engagement as a structured assessment:
- Refined the client's certification scope at the outset, to focus the assessment and keep the ISMS certifiable without being unmanageable
- Conducted the assessment using a qualified ISO 27001 Lead Auditor, so findings reflected how a certification body would evaluate the client
- Assessed the management system clauses and Annex A controls against evidence and through stakeholder interviews, rather than self-assessment questionnaires alone
- Prioritised gaps by significance and effort, so the roadmap reflected a practical order of work
- Presented findings and the roadmap to the executive sponsor, giving leadership a clear basis for the decision to proceed
The Outcome
The engagement gave the client a clear, defensible path to certification, which it went on to achieve through its own remediation effort:
- A complete view of current state against ISO/IEC 27001:2022, across both the management system clauses and Annex A controls
- A prioritised remediation roadmap the client could execute against, sequenced so each activity built toward the next
- Realistic visibility of the effort, sequencing and dependencies involved, enabling an informed decision to commit to certification
- Executive alignment on the path forward, built through direct engagement during the assessment
- ISO/IEC 27001:2022 certification achieved after the remediation activities were completed
Why Fortian
Fortian's depth in information security governance and its familiarity with how ISO 27001 is assessed in practice, backed by a qualified ISO 27001 Lead Auditor, gave the client a clear, prioritised path from its existing controls to certification.
A gap assessment is only as useful as the judgement behind it. Knowing which gaps a certification auditor will treat as material, how to scope an ISMS so it is certifiable without being unmanageable, and how to sequence remediation so early effort builds toward later work is what turned the assessment from a list of gaps into a roadmap the client could act on with confidence.