ISO 27001 risk assessment: risks that name an asset, a threat and a consequence
The risk assessment is where an ISMS is won or lost. Vague risk statements produce controls nobody can test and a certificate that means little.
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
A GDPR gap analysis is a structured comparison between what the regulation requires and what the organisation actually does, ending in a list of gaps with owners, priorities and dates. It is the sensible first exercise for a company that has never assessed itself, and the recurring one for a company that wants its programme to stay true.
Whether it produces anything useful depends on one methodological choice: whether each answer is evidenced or asserted. An analysis built from a questionnaire filled in by the people responsible reliably reports a healthier position than the same organisation would show under examination.
For every row, ask what would prove it. "We handle access requests within a month" is an assertion; the log of the last four requests with dates received and dates answered is evidence. "Retention is applied" is an assertion; a query showing the oldest record in a category is evidence.
Where evidence does not exist, the honest finding is not that the control is absent but that it cannot be demonstrated — and under an accountability-based regulation those amount to nearly the same thing.
Score gaps by regulatory exposure and by how visible they would be in an incident, not by how hard they are to fix. A missing processing record is more serious than an unpolished policy, even though the policy is quicker to produce — and a programme that starts with the quick items usually stalls before reaching the hard ones.
A gap analysis is a working table with a long tail: many rows, several assessors, and a comparison against last year that only means something if both versions survive. Ettex Sheets keeps the assessment with its history and links each row to the evidence examined, so the movement between cycles is visible and a closed finding can be shown to have been re-tested. The findings then feed the same GDPR compliance work the analysis was meant to direct.
For a small company, one to three weeks including interviews and evidence review. The bottleneck is usually getting hold of processor agreements and system access lists rather than the analysis itself.
Someone independent of the processes being examined — an internal privacy or risk function, or an external adviser. A self-assessment by the team that operates the controls is a starting point, not an assessment.
A gap analysis assesses the organisation against the regulation as a whole. A DPIA assesses one specific processing activity that is likely to be high risk, before it starts.
If the audit tested evidence and covered the same ground, no. If it was a questionnaire, the gap analysis is the version that tests what the questionnaire asserted.
The risk assessment is where an ISMS is won or lost. Vague risk statements produce controls nobody can test and a certificate that means little.
A risk control matrix maps what could go wrong to what stops it. Most matrices fail because the rows describe processes rather than risks.
A reconciled account is one where the balance is supported by evidence of what makes it up. Most accounts that look reconciled are merely explained.