ISO 27001 & PCI DSS

ISO 27001 and PCI DSS gap analysis: gaps, evidence and remediation

Unix Consulting helps clarify compliance gaps, prepare technical evidence and organize expected remediation.

Connect the framework to real evidence

A useful gap analysis does not only check requirements. It connects ISO 27001 or PCI DSS controls to configurations, logs, procedures, access, backups, providers and evidence that actually exist.

Reviewed points

  • Scope, critical assets, sensitive flows, cardholder data or confidential data.
  • Security policies, governance, responsibilities, risk management and documentary evidence.
  • Technical controls: MFA, segmentation, hardening, vulnerabilities, backups, logs and monitoring.
  • Access management, privileged accounts, providers, changes, incidents and periodic reviews.
  • Gaps between requirements, real practices, available evidence and remediation actions.

Deliverables

  • ISO 27001 or PCI DSS gap matrix with existing evidence, missing evidence and priority.
  • Technical and documentary remediation plan understandable by IT, CISOs, DPOs, leadership or auditors.
  • Quick wins, residual risks and arbitration points requiring leadership decisions.
  • Useful preparation before audit, customer request, internal review or certification path.

Does a gap analysis replace a certification audit?

No. It prepares the ground by identifying gaps, missing evidence and fixes to prioritize before a formal review.

Do ISO 27001 and PCI DSS require the same evidence?

No. Topics such as access, logging and vulnerability management overlap, but scope, requirements and expected evidence differ.

Can we start with weak documentation?

Yes. That is often the starting point: separate what already exists, what must be documented and what requires technical remediation.