gap-assessment

Automate ISO 27001 gap assessments across Clauses 4–10 and generate RAG-based reports.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill gap-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gap-assessment
Source: https://github.com/gombing/ISO27001Agent/tree/main/gap-assessment
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill gap-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Gap assessment for ISO 27001 helps teams identify gaps in Clauses 4–10, delivering a consistent RAG-based findings report with prioritized actions.

Core Features & Use Cases

  • Systematically evaluates mandatory clauses (4–10) and captures evidence, owners, and risk ratings.
  • Produces a dated gap report suitable for handoff to risk assessment and SoA preparation.
  • Supports engagement-context loading and provides clear remediation prioritization for audit readiness.

Quick Start

Initiate the gap assessment after the interview to generate a clause-by-clause gap report.

Frequently Asked Questions about gap-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct an ISO 27001 gap assessment for Clauses 4-10?

An ISO 27001 gap assessment evaluates Clauses 4-10 by capturing evidence, owners, and risk ratings to identify compliance gaps. This structured evaluation generates a prioritized remediation plan for audit readiness.

What is a RAG-based gap analysis report for ISO 27001 compliance?

A RAG-based gap analysis report uses Red, Amber, and Green ratings to prioritize ISO 27001 compliance findings. It highlights mandatory clause failures and provides clear, actionable remediation steps for audit readiness.

When do I need to perform a gap assessment during ISO 27001 implementation?

Perform a gap assessment after the initial client interview and before risk assessment or SoA preparation. Identifying missing documentation across Clauses 4-10 ensures compliance gaps are addressed before formalizing your Statement of Applicability.

Can I use gap assessment findings to prepare my ISO 27001 Statement of Applicability?

Yes, gap assessment findings directly feed into SoA preparation. Identifying missing controls and documentation across mandatory clauses provides the necessary context to build a compliant ISO 27001 Statement of Applicability.

Does ISO 27001 gap analysis require prior client interviews and engagement context?

Yes, ISO 27001 gap analysis requires prior client interviews to load engagement context. The assessment evaluates mandatory clauses based on this context, producing a dated gap document ready for client sign-off.

What limitations exist when automating ISO 27001 compliance documentation reviews?

Automating ISO 27001 compliance reviews focuses strictly on evaluating Clauses 4-10 and requires completed client interviews. It generates a dated engagement-gap document for sign-off but does not replace the subsequent manual risk assessment process.