Cyberstudy
PDF p.15 In progress

Gap Analysis

Open PDF at p.15 14 flashcards

Summary

PDF p.15

Gap analysis identifies deviations between an organization's current security systems and the requirements or recommendations of a cybersecurity framework. It helps in achieving compliance and improving security by highlighting missing or poorly configured controls and providing remediation recommendations.

In plain words

Supplementary — not from your PDF

A gap analysis compares where your security is today with where a framework says it should be. The gaps are the missing or weak controls, and the report tells you what to fix.

Detailed explanation

PDF p.15
  • Security Functions and Outcomes
    • Identify Function
      • Example Outcome: Inventory of company assets.
      • Achievement: Implementing security controls.
  • Security Controls
    • Challenges: Numerous categories and types make selection difficult.
  • Cybersecurity Framework
    • Purpose: Guides selection and configuration of controls.
    • Benefits: Prevents building security programs in isolation; ensures important security concepts are covered.
  • Framework Usage
    • Capabilities: Allows objective assessment of current cybersecurity capabilities.
    • Target Level: Identifies target capability level and prioritizes investments.
    • Compliance: Provides structure for risk management and regulatory compliance.
  • Gap Analysis Process
    • Purpose: Identifies deviations from framework requirements.
    • Timing: Performed when adopting a framework or meeting new compliance requirements; repeated periodically.
    • Report: Provides overall score, list of missing/poorly configured controls, and remediation recommendations.
    • Involvement: May involve third-party consultants for complex frameworks and compliance requirements.

Important terms

taken from the text above
Example Outcome
Inventory of company assets.
Achievement
Implementing security controls.
Capabilities
Allows objective assessment of current cybersecurity capabilities.
Target Level
Identifies target capability level and prioritizes investments.
Timing
Performed when adopting a framework or meeting new compliance requirements; repeated periodically.
Report
Provides overall score, list of missing/poorly configured controls, and remediation recommendations.
Involvement
May involve third-party consultants for complex frameworks and compliance requirements.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Comparing current controls against the NIST framework and finding there is no asset inventory.
  • A retailer preparing for a payment-card standard finds that stored card data isn't encrypted.

Scenario

A company adopts a new security framework. Consultants score each required control, list the missing ones (for example, no regular access reviews), and recommend fixes. Management uses the report to decide where to spend next year's security budget. A year later they repeat the analysis to measure progress.

Common mistakes

Supplementary — not from your PDF
  • Treating a gap analysis as a vulnerability scan. It compares you against framework requirements, not a list of software flaws.
  • Doing it only once. It is repeated periodically and whenever new compliance requirements appear.

Practical skills

Supplementary — not from your PDF
  • Read a framework requirement and decide whether an existing control meets it, partly meets it, or is missing.

What I should remember

Key Points PDF p.15
  • Security Functions and Outcomes
    • Identify Function: Inventory of assets.
    • Security Controls: Implement to achieve outcomes.
  • Security Controls
    • Selection Challenges: Numerous categories and types.
  • Cybersecurity Framework
    • Guidance: Selection and configuration of controls.
    • Benefits: Comprehensive security program development.
  • Framework Usage
    • Capabilities Assessment: Objective statement of current capabilities.
    • Target Level: Identify and prioritize investments.
    • Compliance: Structure for risk management and compliance.
  • Gap Analysis Process
    • Purpose: Identify deviations from framework.
    • Timing: Initial adoption, new compliance, periodic review.
    • Report: Score, missing controls, remediation.
    • Consultants: May involve third-party specialists.