A browser-based gap analysis tool that maps an organisation's security posture against all 93 ISO/IEC 27001:2022 Annex A controls — no backend, no dependencies, deployable as a single HTML file.
Live Demo: https://<your-username>.github.io/iso27001-grc-tool
| Dashboard | Controls Register | Gap Analysis |
|---|---|---|
| Coverage stats, domain breakdown, top risk controls | All 93 controls with search, filter, detail panel | Risk-prioritised gap list with remediation hints |
- Full Annex A coverage — all 93 controls across Organizational (5.x), People (6.x), Physical (7.x), and Technological (8.x) domains
- Structured gap analysis — Implemented / Partially Implemented / Missing / Not Applicable
- Risk rating — Critical / High / Medium / Low, computed from domain defaults + questionnaire context
- Company background questionnaire — 10-question intake form that drives rule-based control mapping
- Detail panel — per-control objective, evidence requirements, remediation actions, and owner
- Three export formats — JSON, Markdown report, CSV spreadsheet
- Demo dataset — fictional Australian SaaS company (NovaBridge Pty Ltd) with 10 pre-loaded known issues
- Zero dependencies — pure HTML/CSS/JS, works offline, deployable on GitHub Pages
iso27001-grc-tool/
├── index.html # Main assessment dashboard (Gap Analysis Tool)
├── questionnaire.html # Company background questionnaire (intake form)
├── iso27001_annex_a_controls.json # Knowledge base: all 93 Annex A controls
├── company_questionnaire.json # Questionnaire schema + control mapping rules
├── novabridge_demo_dataset.json # Demo dataset: fictional SaaS company
└── README.md
The 10-question intake form collects company context across six dimensions:
| Question | Dimension | GRC Purpose |
|---|---|---|
| Q01 | Organisation size | Governance complexity |
| Q02 | Industry sector | Regulatory obligations (APRA CPS 234, Privacy Act, ISM) |
| Q03 | PII handling | Data breach impact severity |
| Q04 | Infrastructure | Attack surface (cloud vs on-premise) |
| Q05 | Remote work / BYOD | Perimeter definition |
| Q06 | Software development | Supply chain / SDLC risk |
| Q07 | Third-party suppliers | Indirect exposure |
| Q08 | Security operations | Current detection capability |
| Q09 | Identity & access | Current IAM maturity |
| Q10 | Governance documents | Baseline governance maturity |
Each answer triggers one of three rule types:
mandatory— control is a regulatory requirement for this sector (e.g. APRA CPS 234 → 8.15, 8.16)elevate_risk— control's default risk tier is increased (e.g. sensitive PII → 8.11 escalates to Critical)increase_applicability— control confirmed as in-scope (e.g. public cloud → 5.23 applicable)
Answers accumulate — multiple rules from different questions apply to the same control, producing a context-weighted final risk rating.
Every control produces four GRC-relevant outputs:
{
"control_id": "8.11",
"status": "Missing",
"risk_level": "Critical",
"gaps": ["Production PII (TFN, bank details) present in staging without masking"],
"remediation_hints": [
"Mask PII in test/dev environments",
"Implement tokenisation for payment or health data",
"Document masking procedures aligned to Privacy Act obligations"
]
}The tool ships with a pre-loaded fictional dataset representing a realistic Australian SaaS assessment scenario.
Company profile: 85-person cloud HR & payroll platform, Melbourne. Processes TFNs, salary records, and superannuation details for ~45,000 employees across 1,200 client organisations. AWS-hosted, hybrid workforce, ISO 27001 certification in progress.
Assessment results:
| Status | Count |
|---|---|
| Implemented | 6 |
| Partially Implemented | 7 |
| Missing | 80 |
| Total | 93 |
| Risk Level | Count |
|---|---|
| Critical | 4 |
| High | 34 |
| Medium | 42 |
| Low | 13 |
10 pre-loaded known issues including:
KI-002— Production TFN/bank data in staging without masking → Critical (8.11, 8.31, 5.34)KI-005— No SIEM; CloudTrail logs unmonitored → High (8.15, 8.16, 5.25)KI-009— No SAST/DAST in CI/CD pipeline → High (8.28, 8.29, 8.8)
| Status | Definition |
|---|---|
| Implemented | Control fully in place with verifiable evidence |
| Partially Implemented | Control exists but gaps remain in scope, documentation, or testing |
| Missing | No evidence of control implementation |
| Not Applicable | Control is not relevant to this organisation's context |
Base risk = domain default
(Technological: High, Organizational: Medium, People: Medium, Physical: Low)
+ Questionnaire elevation rules (mandatory / elevate_risk)
+ Known issue severity overlay
= Final risk level (Critical / High / Medium / Low)
| Framework | Applicable Controls |
|---|---|
| Privacy Act 1988 — APP 1–13 | 5.34, 8.11, 8.12, 5.12, 8.3 |
| Notifiable Data Breaches (NDB) Scheme | 5.5, 5.24, 5.26 |
| APRA CPS 234 | 8.15, 8.16, 5.35, 8.2, 8.5 |
| Essential Eight (ACSC) | 8.5 (MFA), 8.8 (patching), 8.2 (admin privileges), 8.7 (malware), 8.13 (backups) |
| Security of Critical Infrastructure Act 2018 | 5.5, 5.7, 5.29, 5.30 |
# Clone or fork this repo
git clone https://github.com/<your-username>/iso27001-grc-tool.git
cd iso27001-grc-tool
# No build step needed — static files only
# Enable GitHub Pages: Settings → Pages → Branch: main / root
# Your tool will be live at:
# https://<your-username>.github.io/iso27001-grc-toolTo run the questionnaire against your own organisation:
- Open
questionnaire.htmlin a browser - Answer all 10 questions
- Click Generate ISO 27001 Assessment → export JSON
- (Coming in v2) Import responses into
index.htmlto override the demo dataset
- Questionnaire → assessment integration (import responses into main tool)
- Statement of Applicability (SoA) draft generation
- Remediation tracking (mark gaps as in-progress / resolved)
- Multi-framework mapping (ISO 27001 ↔ NIST CSF ↔ Essential Eight)
- AI-assisted remediation suggestions (Claude API integration)
- Evidence upload and re-scoring
The iso27001_annex_a_controls.json knowledge base covers all 93 Annex A controls with:
- Control objective
- Evidence examples (what an auditor looks for)
- Risk if missing (business impact)
- Remediation hints (actionable steps)
- Typical owner (CISO, IT, Legal, HR, Facilities)
- Essential Eight mapping
- NIST CSF mapping
Built as a GRC portfolio project demonstrating:
- ISO 27001:2022 Annex A domain knowledge (all 93 controls)
- Gap analysis methodology and control status reasoning
- Risk rating logic (context-weighted, not static)
- Australian regulatory context (Privacy Act, NDB, APRA CPS 234, Essential Eight)
- Structured output design suitable for audit reporting
Author: Jack Chen Target roles: GRC Analyst · Security Consultant · Technology Risk Analyst · AppSec Analyst Location: Melbourne, VIC, Australia
All company data in this tool is fictional and created for demonstration purposes only.