Gap Analysis Flashcards

Security+

1
Q

What is gap analysis?

A

A process to compare the current state with the desired state to identify the “gap.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does gap analysis require?

A

Extensive research, which may involve data gathering and technical research.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How long can a gap analysis take?

A

It can take weeks or months, depending on the complexity of the study and number of participants.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a key step when choosing a framework?

A

Work towards a known baseline, either from internal goals or formal standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are two examples of frameworks to consider in gap analysis?

A

NIST SP 800-171 and ISO/IEC 27001.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is NIST SP 800-171 focused on?

A

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What should you evaluate regarding people in a gap analysis?

A

Employees’ formal experience, current training, and knowledge of security policies and procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What should be examined regarding processes?

A

Existing IT systems and current security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the purpose of comparing existing systems in a gap analysis?

A

To identify weaknesses and the most effective processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What should the final analysis include?

A

Detailed baseline objectives and a clear view of the current state.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is needed to create a gap analysis report?

A

A formal description of the current state and recommendations for meeting baseline objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are common resources required to bridge the gap identified in the analysis?

A

Time, money, and change control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why is a detailed analysis important in gap analysis?

A

It helps to break broad security categories into smaller segments for better understanding and evaluation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the first step in conducting a gap analysis?

A

Establishing a clear understanding of where you currently are versus where you want to be.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly