Skip to content
CyberSmithSECURE
Under Attack

Assurance & Risk

Gap Assessment

The standard, regulation or framework is chosen first, because it determines what a gap is. The assessment then runs from scope through requirement mapping to a prioritised view of what is missing.

Methodology

  1. 01

    Scope

    Establish what the assessment covers.

  2. 02

    Requirement Mapping

    Map the selected standard, regulation or framework to that scope.

  3. 03

    Evidence Collection

    Collect the evidence the mapped requirements call for.

  4. 04

    Control Assessment

    Assess the controls against those requirements.

  5. 05

    Gap ID

    Identify the gaps the assessment surfaces.

  6. 06

    Risk Prioritisation

    Prioritise those gaps by risk rather than by count.

Approach to testing

  • Requirement — what does the applicable standard, regulation or framework require?
  • Control — what control has the organisation established?
  • Implementation — how is the control actually implemented?
  • Evidence — what evidence demonstrates that the control operates?
  • Risk — what happens if the control is ineffective or absent?
  • Action — what needs to be changed?
  • Validation — has the corrective action actually addressed the issue?

Types of assessment

Black-Box

Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.

Grey-Box

Selected organisational documentation, process information and evidence are provided for structured assessment.

White-Box

Full documentation, evidence, stakeholder and process access is provided for detailed control validation.

Hybrid

Combines independent assessment techniques with detailed evidence and stakeholder validation.

Frameworks and standards

The selected framework or regulation
Chosen per engagement; it defines what counts as a gap.
CyberSmithSECURE Gap Assessment Toolkit
The toolkit the assessment is run from.

Tools used

Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.

CyberSmithSECURE Gap Assessment Toolkit

Requirement mapping, evidence collection and control assessment.

GRC Assessment Toolkit

Gap assessment, evidence assessment, maturity assessment and remediation tracking.

PlyoGRC

Where appropriate, the toolkits are supported through PlyoGRC for control, evidence, risk and compliance management.

Checklist approach

The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.

Scope and mapping

  • Scope definition
  • Requirement mapping against the selected framework

Assessment

  • Evidence collection
  • Control assessment

Outcome

  • Gap identification
  • Risk prioritisation

How CSS tests

A unified swarm of agents, for blind spot detection

AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.

  • Framework Mapping Agent — maps requirements and controls across applicable frameworks.

  • Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.

  • Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.

  • Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.

  • Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.

  • Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.

AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.

Why this differs

What CSS does that most vendors do not

Every one of these is checkable. Ask any vendor for the same and compare the answers.

Beyond the checklist

Structured checklists and framework mappings establish coverage, but the assessment continues through implementation, evidence, risk, action and validation.

Prioritised by risk, not by count

The output orders gaps by what they mean rather than listing them.

Operating control, not documentation only

Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?

Human-in-the-loop AI assistance

AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.

What you receive

A working management system, not a folder of documents

The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.

Executive layer

Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary

GRC layer

Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker

Assurance layer

Internal audit, findings, CAPA, management review, certification-readiness assessment

Operational layer

Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable

Governance cadence established

Monthly
Risk / action review, evidence status, control exceptions, material incidents
Quarterly
Risk trend, supplier / control reviews, KPI/KRI, management action tracking
Annual
Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan

For this engagement specifically

  • Control owners
  • IT teams
  • Security teams
  • Compliance teams
  • Process owners
  • Auditors
  • Key risks
  • Significant gaps
  • Business impact
  • Priority actions
  • Ownership
  • Target timelines

Case studies

What this finds in practice

Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.

An EdTech platform with security practices already in place, seeking a structured view of its ISO 27001 position and of what certification readiness would require.

Finding
Controls were operating, but had never been mapped against ISO 27001:2022 clauses and Annex A in one place — so documentation gaps and evidence gaps blurred into implementation gaps. Documentation was spread across multiple locations, control ownership was interpreted differently across teams, and there were more findings than could be sequenced against the resources available.
Recommendation
Review the ISMS scope and context alongside the existing policies, procedures and records; assess the clauses and controls against current organisational practice; hold stakeholder discussions to confirm which controls were operating and where evidence existed; and score maturity by control domain, sequencing remediation by risk, ownership and effort.
Outcome
Every gap classified by type — documentation, evidence, ownership or implementation — so remediation effort matched the actual shortfall rather than the finding count. Delivered as a gap assessment report, a clause and control assessment, a risk and gap register, a maturity and readiness view and a remediation roadmap.

Next

Scope this assessment

Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.