DRAFT — REQUIRES REVIEW BY EXTERNAL ISO 27001 CONSULTANT AND SIGN-OFF BY BRITIAI CTO BEFORE USE IN BID OR AUDIT.
ISO/IEC 27001:2022 — Gap Analysis and Remediation Backlog
Document ID: ISO03 Version: 0.1 (Draft) Date: 15 June 2026 Owner: BritiAI CISO (interim: CTO) Target Stage 2 readiness date: 31 March 2027
1. Purpose and method
This gap analysis compares BritiAI’s current information security posture (as at 15 June 2026) against the requirements of ISO/IEC 27001:2022 Clauses 4–10 and Annex A. Findings were derived from a desktop review of existing controls, interviews with the CTO and engineering leads, sampling of repository and cloud configuration, and review of supplier contracts with Votee Limited and Beever.
Each gap is rated by severity (Critical / High / Medium / Low), assigned an effort estimate (S ≤ 2 weeks, M ≤ 8 weeks, L ≤ 6 months), an owner, and a target closure date relative to the Stage 2 audit window (Q1 2027).
2. Clause-level findings (Clauses 4–10)
Clause 4 — Context of the organisation
- Gap 4.1: Interested parties register exists in draft only and does not yet enumerate NHS-specific stakeholders (NHS England, NHS SBS, ICO, NCSC). Severity: Medium. Effort: S. Owner: CTO. Target: 31 Jul 2026.
- Gap 4.2: ISMS scope statement (ISO01) requires formal approval and inclusion in the document control register. Severity: High. Effort: S. Owner: CTO. Target: 31 Jul 2026.
Clause 5 — Leadership
- Gap 5.1: Information Security Policy not yet ratified by the Board; no recorded management commitment in minutes. Severity: High. Effort: S. Owner: CTO/Board. Target: 31 Aug 2026.
- Gap 5.2: CISO role currently held on an interim basis by the CTO; segregation of duties is reduced. Severity: Medium. Effort: M. Owner: CTO. Target: appoint or contract a fractional CISO by 31 Oct 2026.
Clause 6 — Planning
- Gap 6.1: Information security risk assessment methodology documented but not yet applied consistently; risk register (ISO04) is a first-pass population. Severity: High. Effort: M. Owner: CISO. Target: 30 Sep 2026.
- Gap 6.2: Risk treatment plan not yet linked to SoA control statuses. Severity: High. Effort: M. Owner: CISO. Target: 30 Sep 2026.
- Gap 6.3: Information security objectives not quantified at function level (no SMART objectives, no measurable KPIs). Severity: Medium. Effort: S. Owner: CTO. Target: 31 Aug 2026.
Clause 7 — Support
- Gap 7.1: Competence matrix for security-relevant roles is informal. Severity: Medium. Effort: M. Owner: Head of People. Target: 30 Nov 2026.
- Gap 7.2: Awareness training exists but completion is not centrally tracked. Severity: Medium. Effort: S. Owner: HoP. Target: 30 Sep 2026.
- Gap 7.3: Documented information control (versioning, approval, retention, access) is inconsistent across SharePoint/Drive locations. Severity: High. Effort: M. Owner: HoO. Target: 31 Oct 2026.
Clause 8 — Operation
- Gap 8.1: Change management is operationally sound for code (PR review) but not for cloud infrastructure outside IaC. Severity: High. Effort: M. Owner: HoE. Target: 30 Nov 2026.
- Gap 8.2: Supplier risk assessment (Votee, Beever, cloud, SaaS) is partial; no annual review cycle in place. Severity: Critical. Effort: M. Owner: HoO. Target: 31 Oct 2026.
Clause 9 — Performance evaluation
- Gap 9.1: No internal audit programme defined; first internal audit must be completed before Stage 2. Severity: Critical. Effort: M. Owner: CTO. Target: 31 Jan 2027.
- Gap 9.2: Management Review not yet scheduled. Required quarterly cadence to be established. Severity: High. Effort: S. Owner: CTO. Target: first MR by 30 Sep 2026.
- Gap 9.3: KPI dashboard for ISMS not yet built. Severity: Medium. Effort: M. Owner: CISO. Target: 31 Dec 2026.
Clause 10 — Improvement
- Gap 10.1: Nonconformity and corrective action procedure exists in draft but has no recorded use. Severity: Medium. Effort: S. Owner: CISO. Target: 31 Oct 2026.
3. Annex A high-priority gaps
Findings below are the highest-impact controls to close before Stage 2. Lower-impact items are tracked in the SoA (ISO02).
A.5 Organisational
- A.5.7 Threat intelligence (Planned): No subscription to threat intelligence feeds (NCSC CiSP, commercial). Effort: S. Target: 30 Sep 2026.
- A.5.19–A.5.23 Supplier security: Inter-company agreements with Votee/Beever need ISO-aligned security schedules and DPAs with NHS-specific flow-down. Critical. Effort: L. Target: 31 Dec 2026.
- A.5.23 Cloud services security: Cloud security baseline documented but not yet enforced through policy-as-code/SCPs across all accounts. High. Effort: M. Target: 30 Nov 2026.
- A.5.24–A.5.28 Incident management: Runbooks exist for the top 5 scenarios; lifecycle documentation (triage, evidence, lessons learned) incomplete. High. Effort: M. Target: 31 Oct 2026.
- A.5.29–A.5.30 ICT readiness for business continuity: No tested DR plan. High. Effort: L. Target: 31 Jan 2027 (with one tested failover).
- A.5.35 Independent review: Internal audit programme is the gating dependency for Stage 2. Critical. Effort: M. Target: 31 Jan 2027.
A.6 People
- A.6.1 Screening: BPSS-equivalent screening required for NHS-facing personnel; current process is right-to-work + reference only. High. Effort: M. Target: 30 Nov 2026.
- A.6.3 Awareness training: Roll out role-specific modules for engineers (secure coding) and operators (incident response). Medium. Effort: M. Target: 31 Oct 2026.
A.7 Physical
- A.7.4 Physical security monitoring and A.7.14 Secure disposal: Both Planned. Office is small but disposal certs are essential. Medium. Effort: S. Target: 30 Sep 2026.
A.8 Technological — highest-priority cluster
- A.8.8 Vulnerability management: Scanning is in place but patch SLAs are not enforced and exceptions are not tracked. Critical. Effort: M. Target: 31 Oct 2026.
- A.8.10 Information deletion and A.8.11 Data masking: Required for any NHS data pipeline; currently unaddressed. Critical. Effort: L. Target: 31 Jan 2027.
- A.8.12 DLP: No DLP policies in M365/Google tenant; egress controls partial. High. Effort: M. Target: 30 Nov 2026.
- A.8.15–A.8.16 Logging and monitoring: Centralised SIEM ingest exists, but alerting coverage and on-call rota are incomplete. High. Effort: M. Target: 30 Nov 2026.
- A.8.22 Network segregation: Tenant isolation between NHS workloads and other workloads needs to be evidenced architecturally and via runtime tests. Critical. Effort: M. Target: 31 Dec 2026.
- A.8.24 Cryptography: Customer-managed keys (CMK) and key rotation policy needed. High. Effort: M. Target: 31 Dec 2026.
- A.8.25–A.8.29 Secure development: SDLC documented; threat modelling and secure-coding training not yet rolled out. High. Effort: M. Target: 30 Nov 2026.
- A.8.33 Test information: Production data prohibited in non-prod; need synthetic data generator and audit. Critical (NHS). Effort: M. Target: 31 Dec 2026.
4. Prioritised remediation backlog (summary table)
| Priority | Workstream | Severity | Effort | Owner | Target |
|---|---|---|---|---|---|
| 1 | Internal audit programme + first audit | Critical | M | CTO | 31 Jan 2027 |
| 2 | Supplier security overhaul (Votee/Beever DPAs + flow-down) | Critical | L | HoO/Legal | 31 Dec 2026 |
| 3 | Vulnerability management with enforced SLAs | Critical | M | CISO | 31 Oct 2026 |
| 4 | NHS data segregation: A.8.22 + A.8.33 + A.8.11 | Critical | L | HoE/DPO | 31 Dec 2026 |
| 5 | Incident management lifecycle (A.5.24–A.5.28) | High | M | CISO | 31 Oct 2026 |
| 6 | ICT business continuity with tested DR (A.5.29–A.5.30) | High | L | HoE | 31 Jan 2027 |
| 7 | Logging/monitoring (A.8.15–A.8.16) + 24/7 alerting | High | M | CISO | 30 Nov 2026 |
| 8 | Information Security Policy + Board ratification | High | S | CTO | 31 Aug 2026 |
| 9 | Risk treatment plan linked to SoA | High | M | CISO | 30 Sep 2026 |
| 10 | DLP + data deletion (A.8.10, A.8.12) | High | M | CISO/DPO | 30 Nov 2026 |
| 11 | Cryptography uplift (CMK, rotation) | High | M | HoE | 31 Dec 2026 |
| 12 | Secure SDLC + threat modelling rollout | High | M | HoE | 30 Nov 2026 |
| 13 | BPSS-equivalent screening for NHS-facing staff | High | M | HoP | 30 Nov 2026 |
| 14 | Document control consolidation | High | M | HoO | 31 Oct 2026 |
| 15 | Management review cadence | High | S | CTO | 30 Sep 2026 |
| 16 | Fractional CISO appointment | Medium | M | CTO | 31 Oct 2026 |
| 17 | Awareness training tracking | Medium | S | HoP | 30 Sep 2026 |
| 18 | Threat intelligence subscription | Medium | S | CISO | 30 Sep 2026 |
| 19 | Physical disposal certification | Medium | S | HoO | 30 Sep 2026 |
| 20 | KPI dashboard for ISMS | Medium | M | CISO | 31 Dec 2026 |
5. Effort and resourcing summary
- S items (≤2 weeks): 7
- M items (≤8 weeks): 11
- L items (≤6 months): 2
Recommended resourcing: engage a fractional CISO (1–2 days/week) and an external ISO 27001 consultant for an 8-week intensive remediation sprint (Sep–Oct 2026) and a 4-week pre-audit sprint (Feb 2027).
6. Stage 2 readiness criteria
BritiAI will be deemed ready for Stage 2 when:
- All Annex A controls are at least Partial with evidence; all Critical-priority items are Implemented.
- Internal audit has been completed end-to-end and findings closed or accepted.
- At least one Management Review has been minuted.
- A risk treatment plan exists with named owners and review dates.
- Supplier flow-down (Votee/Beever) is contractually executed.
- A DR test has been performed and lessons captured.
Target Stage 2 readiness: 31 March 2027.
End of document.
