GDPR gap analysis: finding what is missing before someone else does
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
The risk assessment is where an ISMS is won or lost. Vague risk statements produce controls nobody can test and a certificate that means little.
An ISO 27001 risk assessment identifies what could compromise the confidentiality, integrity or availability of information in scope, evaluates how likely and how damaging each is, and decides what to do about it. Everything downstream — the controls selected, the statement of applicability, the treatment plan — is derived from it, which is why a weak assessment produces a weak management system regardless of how much documentation follows.
The standard does not prescribe a method. It requires that the method be defined, repeatable and produce consistent results — meaning two people assessing the same risk should land in roughly the same place, and next year’s assessment should be comparable to this one.
A usable risk names three things: the asset or process at stake, the threat or event, and the consequence. "Customer data" is not a risk. "Customer records are exposed because a departing employee retains access to the CRM, leading to a notifiable breach" is one — and it implies its control and its evidence without further discussion.
Five-by-five matrices invite false precision. What matters is that everything above the acceptance line has a treatment with an owner and a date, and that everything below it was seen and accepted by someone with the authority to accept it. A risk marked 12 rather than 9 changes nothing if both sit above the line.
Risk acceptance is routinely done implicitly: the risk sits in the register untreated, and nobody signs anything. Auditors ask who accepted it. Similarly, the assessment is often performed once and then referenced for three years, while the business changes underneath it.
Supplier risk is the other consistent gap. Information held by a processor is still in scope, and its risks belong in the same assessment rather than in a separate vendor spreadsheet nobody reads.
A risk assessment is a table with a long life: dozens of rows, several assessors, an annual comparison, and an auditor asking what it said last cycle. Ettex Sheets keeps the assessment and its scoring with version history, so the movement between cycles — new risks, retired ones, changed scores — is visible rather than reconstructed, and each row can point at the evidence for the control it relies on.
At planned intervals — annually is the norm — and whenever significant changes occur: new systems, new premises, new categories of data, mergers, or after a significant incident.
No. It requires a defined, repeatable method with documented criteria for acceptance, and results that are consistent and comparable over time.
Inherent risk is the exposure before existing controls; residual risk is what remains after them. Recording both shows what your controls are actually contributing.
Someone with the authority to accept it or fund its treatment — usually a business owner, not the security manager. A register where all risks are owned by security is a register nobody can act on.
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
A risk control matrix maps what could go wrong to what stops it. Most matrices fail because the rows describe processes rather than risks.
A reconciled account is one where the balance is supported by evidence of what makes it up. Most accounts that look reconciled are merely explained.