2 Fundamentals of Security: Gap Analysis Flashcards
Process of evaluating the differences between an organization’s current performance and its desired performance
Gap Analysis
Conducting a gap analysis can be a valuable tool for organizations looking to improve
their operations, processes, performance, or overall security posture True or False
True
Steps in Gap Analysis
Define Scope of analysis
Gather Data on the current state of the organiztion
Analyze the data to identify any areas where the organizations current performacne falls short of its desired performance
develop a plan to bridge the gap
Two types of gap analysis are?
Technical
Business
Involves evaluating an organization’s current technical infrastructure
identifying any areas where it falls short of the technical capabilities
required to fully utilize their security solutions
Technical
Involves evaluating an organization’s current business processes
● Identifying any areas where they fall short of the capabilities required to
fully utilize cloud-based solutions
business gap analysis
● Outlines the specific measures to address each vulnerability
● Allocate resources
● Set up timelines for each remediation task that is needed
POA&M Plan of Action and Milestones