Compliance · ISO 27001
Information Security Management
Maturity score: 87% · 102 of 117 controls implemented · audit in 14 days
Maturity score
87%
ISO 27001
Implemented102
In progress11
Missing4
Total117
External audit
14 days
May 10, 2026 · TÜV Rheinland
✓
Documentation complete
✓
Risk register up to date
⏳
Confirm 2 controls
⏳
Employee training Q2
Risk matrix
42 risksVery rare
Rare
Possible
Prob.
Catastrophic
1
0
0
0
Hard
2
3
2
1
Medium
4
7
5
2
Low
8
5
2
0
3 critical
17 Medium
22 Low
🤖
AI pre-audit
Audit probability: 94% passed
All mandatory controls (A.5-A.18 per ISO 27001:2022) fulfilled. 2 weaknesses: A.6.3 employee training Q2 pending, A.8.10 data deletion procedure documentation outdated.
ISO 27001:2022 controls
Annex A · 4 topic areas · 93 controls
🏢
A.5 Organizational Controls
37 / 37 ✓
👥
A.6 People Controls
7 / 8 · 1 pending
⚠ A.6.3 employee training Q2 missing
🔐
A.7 Physical Controls
14 / 14 ✓
💻
A.8 Technological Controls
31 / 34 · 3 in progress
⏳ A.8.10 deletion procedure · A.8.16 monitoring · A.8.23 web filtering
Top risks
🔴
Critical
Cloud provider outage
A.5.30 · Likelihood: Possible · Impact: Catastrophic
Owner: Frank
Mitigation active
🔴
Critical
DSGVO violation
A.5.34 · Likelihood: Rare · Impact: Severe
Owner: Daniela
AVV-compliant
🟡
Medium
Phishing attack
A.6.3 · Probability: Prob. · Impact: Medium
Owner: Maja
Training Q2
🟡
Medium
Insider threat
A.5.10 · Probability: Rare · Impact: Severe
Audit roadmap 2026
planned · in progress · completed
✓
Q1 26
Internal audit
✓
Q1 26
Pen-Test
●
Q2 26
External audit (TÜV)
○
Q3 26
DSGVO review
○
Q3 26
Internal audit
○
Q4 26
ISO re-cert
Completed
2 audits Q1
0 Major Findings
In preparation
TÜV audit
May 10 · 14d
Planned
3 audits
Q3-Q4 2026
Score history
12 months
▲ +15 points since Q2/25