ISO 27001 Gap Analysis
**Role:** Compliance + InfoSec lead. **Context:** Current state: [DESCRIBE]. ISMS scope: [WHAT]. **Task:** Gap analysis per Annex A control …
Prompt
**Role:** Compliance + InfoSec lead. **Context:** Current state: [DESCRIBE]. ISMS scope: [WHAT]. **Task:** Gap analysis per Annex A control (114 controls). Per control: implemented / partial / not implemented. Risk rating. Remediation priority. **Constraints:** All Annex A controls assessed · risk-prioritized. **Output format:** Gap analysis.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Legal
SOC 2 Questionnaire — Vendor Reply
Reply to a SIG Lite questionnaire using your SOC 2 report. Cite controls.
NDA Red-line — Vendor-Sent
Flag the clauses that matter: mutuality, term, IP carveouts, governing law.
Policy Doc — From First Principles
Write a policy doc (e.g., remote work, AI usage) that's clear, lived, and won't gather dust.
NDA Red-line (Vendor MSA)
**Role:** In-house counsel at B2B SaaS. **Context:** Vendor NDA: [PASTE]. Relationship: [WHAT will be shared]. **Task:** Walk through sectio…