Gap Analysis 1.2 Flashcards

(5 cards)

1
Q

What is a gap Analysis?

A

Where you compare where you want to be with where you are. Requires doing extensive research.

Can take weeks or months. Extensive study with numerous participants. Emails, data gathering, and technical research.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Choosing the framework

A

Work towards a baseline. May be an internal set of goals. Some orgs should use formal standards.

Determine the end goal. ex- NIST special publication 800-171 revision 2, protecting controlled unclassified information in nonfederal systems and organizations. ISO/IEC 27001, Information security management systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Evaluate people and processes

A

Get a baseline of employees. Formal experience, current training, knowledge of security policies and procedures.

Examine the current processes. Research existing IT systems. Evaluate existing security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Compare and contrast (See example on Vid)

A

Evaluate existing systems.

Identify weaknesses along with the most effective processes.

A detailed analysis that examines broad security categories and breaks those into smaller segments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The analysis and report (see video)

A

The final comparison shows detailed baseline objectives. A clear view of the current state.

Need a path to get from the current security to the goal. This will almost certainly include time, money, and lots of change control.

Time to create the gap analysis report. A formal description of the current state and recommendations for meeting the baseline.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly