Gap Analysis in IT Security--Lesson 1.2

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/14

flashcard set

Earn XP

Description and Tags

CompTIA Security + Flashcards

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

15 Terms

1
New cards

What is the purpose of a gap analysis in IT security?

To compare current security posture with desired future state and identify weaknesses.

2
New cards

What is a baseline in gap analysis?

A standard or goal used to measure current security status, often based on NIST 800-171 or ISO/IEC 27001.

3
New cards

What are the three main areas evaluated in a gap analysis?

People, processes, and technology.

4
New cards

What personnel factors are assessed in gap analysis?

Training, experience, and familiarity with security policies.

5
New cards

How are processes and systems evaluated?

By reviewing policies, infrastructure, and identifying vulnerabilities.

6
New cards

Why is breaking down broad security categories important?

It allows for detailed evaluation and targeted remediation.

7
New cards

What does a gap analysis report include?

Current status vs. baseline, remediation steps, resources, and timelines.

8
New cards

What do green, yellow, and red indicators in a gap report mean?

Green = compliant, Yellow = moderate gaps, Red = significant deficiencies.

9
New cards

Why is a gap analysis considered iterative and complex?

It involves detailed data collection, multiple stakeholders, and extended timelines.

10
New cards

What is the benefit of using established baselines like NIST or ISO?

They provide expert-developed frameworks aligned with best practices and regulations.

11
New cards

Why are human factors critical in gap analysis?

Even strong technical controls fail without proper user knowledge and policy adherence.

12
New cards

What does task-level analysis enable?

Pinpointing specific weaknesses for effective remediation.

13
New cards

How does multi-location operation affect gap analysis?

It adds complexity but helps prioritize remediation using visual tools.

14
New cards

What does closing gaps typically require?

Strategic planning, investment, training, and change management.

15
New cards

Why is documentation important in gap analysis?

It drives accountability and supports continuous improvement.