Gap Analysis Flashcards
What is Gap Analysis?
Process of evaluating the differences between an organization’s current performance and its desired performance
○ Conducting a gap analysis can be a valuable tool for organizations looking to improve their operations, processes, performance, or overall security posture
What are the steps involved in a gap analysis?
Define the scope of the analysis
■ Gather data on the current state of the organization
■ Analyze the data to identify any areas where the organization’s current
performance falls short of its desired performance
■ Develop a plan to bridge the gap
What are the types of Gap analysis?
■ Technical Gap Analysis
● Involves evaluating an organization’s current technical infrastructure
● identifying any areas where it falls short of the technical capabilities
required to fully utilize their security solutions
■ Business Gap Analysis
● Involves evaluating an organization’s current business processes
● Identifying any areas where they fall short of the capabilities required to
fully utilize cloud-based solutions
What is a Plan of Action and Milestones (POA&M) document used for
● Outlines the specific measures to address each vulnerability
● Allocate resources
● Set up timelines for each remediation task that is needed