Section 2.15 Gap Analysis Flashcards
1
Q
Gap Analysis
A
Process of evaluating the differences between an organisations current peformance and its desired peformance
2
Q
Why is conducting Gap Analysis important?
A
Strengthen the overall security posture of an organisation
3
Q
how to conduct one (4 brief steps)
Gap Analysis steps
A
- Define the scope
- Gather data on the current state
- Analyse the data to identify areas of weakness
- Develop a plan of to bridge the gap
4
Q
2 Basic types of Gap Analysis
A
1.Technical Gap Analysis - Assesing the technical infrastructure
- Business Gap Analysis: Assessing business processes
5
Q
Plan of Action and Milestones (POA&M)
A
Outlines the specific measures to address each vulnerability with timelines and resources