Gap Analysis Flashcards
Process of evaluating the differences between an organization’s current performance and its desired performance
Gap Analysis
Conducting a gap analysis can be a valuable tool for organizations looking to improve their operations, processes, performance, or overall security posture
TRUE
■ Define the scope of the analysis
■ Gather data on the current state of the organization
■ Analyze the data to identify any areas where the organization’s current performance falls short of its desired performance
■ Develop a plan to bridge the gap
Steps for conducting a gap analysis
Technical Gap Analysis, Business Gap Analysis
2 Basic Types of Gap Analysis
Involves evaluating an organization’s current technical infrastructure
Identifying any areas where it falls short of the technical capabilities
required to fully utilize their security solutions
Technical Gap Analysis
Involves evaluating an organization’s current business processes
Identifying any areas where they fall short of the capabilities required to
fully utilize cloud-based solutions
Business Gap Analysis
Outlines the specific measures to address each vulnerability
Allocate resources
Set up timelines for each remediation task that is needed
Plan of Action and Milestones (POA&M)