1.2 Flashcards
1
Q
gap analysis
A
a comprehensive appraisal that helps organizations determine the
difference between the current state of their information security to specific industry requirements guidance and best practices
2
Q
why must you conduct gap
analysis?
A
To know where you are and where you need to go as a secure organization
3
Q
common security gaps:
A
- Weak and/or shared credentials
- Lack of tested patch management
- Violation of the least privilege principle
- Having no/unenforced acceptable use policies
- Poor physical security
- Configuration and deployment errors due to lack of change and configuration management
- Poor visibility and lack of proper auditing
4
Q
A