Gap Analysis
Process of evaluation the differences between an orgs current performance and it’s desired performance
Steps of gap analysis
Technical Gap
Involves evaluating current orgs technical infrastructure and identifying an areas where it falls short of technical capabilities required to utilize security solution
Business Gap
Evaluating current business processes and identifying where they fall short of the capabilities needed to utilize cloud-based solutions
Plan of action and milestones (POA&M)
Outlines the specific measures to address each vulnerability, allocate resources, and set up timelines for each remediation task