Gap Analysis
Summary
PDF p.15Gap analysis identifies deviations between an organization's current security systems and the requirements or recommendations of a cybersecurity framework. It helps in achieving compliance and improving security by highlighting missing or poorly configured controls and providing remediation recommendations.
In plain words
Supplementary — not from your PDFA gap analysis compares where your security is today with where a framework says it should be. The gaps are the missing or weak controls, and the report tells you what to fix.
Detailed explanation
PDF p.15-
Security Functions and Outcomes
-
Identify Function
- Example Outcome: Inventory of company assets.
- Achievement: Implementing security controls.
-
Identify Function
-
Security Controls
- Challenges: Numerous categories and types make selection difficult.
-
Cybersecurity Framework
- Purpose: Guides selection and configuration of controls.
- Benefits: Prevents building security programs in isolation; ensures important security concepts are covered.
-
Framework Usage
- Capabilities: Allows objective assessment of current cybersecurity capabilities.
- Target Level: Identifies target capability level and prioritizes investments.
- Compliance: Provides structure for risk management and regulatory compliance.
-
Gap Analysis Process
- Purpose: Identifies deviations from framework requirements.
- Timing: Performed when adopting a framework or meeting new compliance requirements; repeated periodically.
- Report: Provides overall score, list of missing/poorly configured controls, and remediation recommendations.
- Involvement: May involve third-party consultants for complex frameworks and compliance requirements.
Important terms
taken from the text above- Example Outcome
- Inventory of company assets.
- Achievement
- Implementing security controls.
- Capabilities
- Allows objective assessment of current cybersecurity capabilities.
- Target Level
- Identifies target capability level and prioritizes investments.
- Timing
- Performed when adopting a framework or meeting new compliance requirements; repeated periodically.
- Report
- Provides overall score, list of missing/poorly configured controls, and remediation recommendations.
- Involvement
- May involve third-party consultants for complex frameworks and compliance requirements.
Examples & real-world scenarios
Supplementary — not from your PDF- Comparing current controls against the NIST framework and finding there is no asset inventory.
- A retailer preparing for a payment-card standard finds that stored card data isn't encrypted.
Scenario
A company adopts a new security framework. Consultants score each required control, list the missing ones (for example, no regular access reviews), and recommend fixes. Management uses the report to decide where to spend next year's security budget. A year later they repeat the analysis to measure progress.
Common mistakes
Supplementary — not from your PDF- Treating a gap analysis as a vulnerability scan. It compares you against framework requirements, not a list of software flaws.
- Doing it only once. It is repeated periodically and whenever new compliance requirements appear.
Practical skills
Supplementary — not from your PDF- Read a framework requirement and decide whether an existing control meets it, partly meets it, or is missing.
What I should remember
Key Points PDF p.15-
Security Functions and Outcomes
- Identify Function: Inventory of assets.
- Security Controls: Implement to achieve outcomes.
-
Security Controls
- Selection Challenges: Numerous categories and types.
-
Cybersecurity Framework
- Guidance: Selection and configuration of controls.
- Benefits: Comprehensive security program development.
-
Framework Usage
- Capabilities Assessment: Objective statement of current capabilities.
- Target Level: Identify and prioritize investments.
- Compliance: Structure for risk management and compliance.
-
Gap Analysis Process
- Purpose: Identify deviations from framework.
- Timing: Initial adoption, new compliance, periodic review.
- Report: Score, missing controls, remediation.
- Consultants: May involve third-party specialists.