Webinar

How to conduct a Gap Analysis

Date/Time: 2026-11-26 14:00 - 15:00

Description

Join us for a Free webinar, hosted by an International ISO Auditor. This is a rare opportunity to understand where ISO Auditors are approaching the audits. External Auditors are not allowed to provide any advice during an audit or to provide consulting to audit clients. Thus, we are just auditing to make a judgement regarding the compliance against the requirements of the standards.

 

This webinar will address the practical process of conducting a practical Gap Assessment, based on the international Best practice as stipulated in ISO 21827, the Capability Maturity Model (CMM) and what auditors are looking for:

 

1. Start With the Right Assessment Question

1.1 The two questions

1.2 Why use both

1.3 Practical status categories

2. ISO/IEC 21827 Assessment Architecture

2.1 Two dimensions

2.2 Model structure

2.3 Core security-engineering process areas

3. Capability Levels and Assessment Criteria

3.1 The cumulative rating rule

4. Plan the Gap Analysis Before Collecting Evidence

4.1 Recommended assessment file

5. Conduct Fieldwork: Evidence Before Opinion

5.1 Evidence methodologies

5.2 Triangulation rule

5. Worked Example: Assess Security Risk

6.1 Finding statement

6.2 Recommended actions

7. From Findings to a Prioritised Roadmap

7.1 Minimum finding fields

7.2 Prioritisation model

8. Professional Gap Analysis Report Layout

8.1 Reporting cautions

9. Recommended Slide Deck Layout

10. Facilitator Guidance and Interaction

10.1 Opening script (approximately 60 seconds)

10.2 Participant prompts

10.3 Five closing takeaways

11. Source Materials and Development Notes

12. Contact us


Back to Webinars