Gap Analysis
Where you are compared with where you want to be. The “gap” between the two
Choosing the framework
Work towards a known baseline. Determine the end goal.
Evaluate people and processes
-Get a baseline of employees
1. Formal experience
2. Current training
3. Knowledge of security procedures and policies
-Examine the current processes
1. Research existing IT systems
2. Evaluate existing security policies
Compare and contrast
-The Comparison
Evaluate existing systems
-Identify weakness
Along with the most effective processes
-A Detailed Analysis of
Examine broad security categories. Break those into smaller segments
The Analysis and Report
-The final comparison
Detailed baseline objectives, and a clear view of the current state
-Need a path to get from the current security to the goal
This will most certainly include time, money, and lots of change control
-Time to create the gap analysis report
A formal description of the current state, recommendations for meeting the baseline