Gap analysis
Study of where we are versus where we should be.
Baseline in gap analysis
Choosing proper baseline based on known standards (NIST, ISO) \
NIST 800
ISO 27001
Gap analysis process
Do the comparison, identify weaknesses, do a detail analysis,
Formal gap analysis report
Final document, gap analysis, recommendation how to achieve good state