// ISO 27001 READINESS · HANS STUDY · ONTARIO, CANADA

ISO 27001 and NIST CSF readiness

A customer security questionnaire or a contract clause has made an information security management system a requirement, and nobody on staff has run one before. This gap assessment maps what exists today against ISO/IEC 27001 or the NIST Cybersecurity Framework and sets out what's missing.

What it covers

A control-by-control gap assessment against ISO/IEC 27001 Annex A or the NIST CSF functions, whichever the organization is targeting, covering policy, access control, asset management, risk treatment, supplier security, incident response, and the evidence an auditor or assessor would expect to see for each one.

What you receive

  • A control-by-control gap report against the chosen framework
  • A remediation plan sequenced by what an auditor checks first
  • A statement of applicability draft, where ISO 27001 is the target

Price

Starting at $6,500.

CAD, plus HST.

Remote delivery via the DHD, a remote access device. Terms apply.

Where this sits next to the rest of the practice

A gap assessment is a point-in-time deliverable. Running the program that comes after it, risk register, ongoing policy maintenance, and audit cycles, is fractional CISO work.

Book a scoping call

A short call confirms the framework, the staff count, and whether the starting price fits.