1/213
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is EGIT?
Enterprise Governance of Information & Technology (EGIT) is a process used to monitor and control IT activities within an organization.
(EGIT ensures that IT supports business goals, risks are managed, and IT resources are used responsibly to deliver value.)
What are the three main objectives of EGIT?
1. Ensure alignment of IT activities with business objectives
2. Ensure IT risks are appropriately addressed
3. Ensure IT delivers value to business processes
What is the main objective of IT governance?
To ensure optimum use of technology resources.
(This means using IT systems, infrastructure, and investments efficiently to support business operations and growth.)
Who has the final responsibility for IT governance?
The Board of Directors.
(The Board of Directors has the highest level of accountability for the organization’s overall direction, risk management, and stakeholder protection. If a major data breach occurs due to poor governance, regulators and stakeholders hold the board accountable for inadequate oversight.)
How can an organization determine whether IT is adding value?
By evaluating the alignment of IT strategy with organizational strategy.
(When IT initiatives support business goals and improve efficiency, productivity, or revenue, IT is delivering value.)
What is the prime purpose of corporate governance?
To provide strategic business direction for the entire organization.
(Corporate governance ensures the organization operates responsibly, achieves objectives, and protects stakeholder interests.)
What is the relationship between corporate governance and IT governance?
IT governance is a subset of corporate governance.
(IT governance supports overall corporate governance by ensuring technology supports strategy, manages risks, and delivers value.)
How can the effectiveness of IT governance implementation be best determined?
By ensuring involvement of stakeholders and senior management verifying that IT is delivering value to the business.
(Effective IT governance is reflected when key stakeholders (such as business leaders, IT management, and risk teams) actively participate in decision-making and oversight. Additionally, IT initiatives should support business objectives, improve efficiency, manage risks, and provide measurable value. If IT investments align with business goals and produce tangible benefits, governance is functioning effectively.)
What is the most important method to ensure alignment between IT and business objectives?
Review the compatibility of the IT plan with the business plan.
(This review confirms that IT initiatives support organizational goals, priorities, and growth strategies. It helps ensure that technology investments, projects, and resources are focused on delivering business value rather than operating in isolation.
Strategic alignment can best be improved by?
Involvement of top management in aligning business and technology requirements.
(Top management participation ensures that technology decisions support strategic objectives and receive proper resources and support.)
What is a major risk of lack of top management support in IT strategic planning?
Lack of alignment between technology and business objectives.
(Without leadership support, IT initiatives may become disconnected from business needs, leading to wasted resources and reduced value.)
What is IT Portfolio Management?
The process of managing an organization's IT projects and resources to ensure alignment with business objectives and optimal return on investment.
What is a Policy?
A policy is a high-level statement that provides management’s intent and direction regarding acceptable and unacceptable behavior.
(It defines the organization’s expectations and serves as a foundation for rules, procedures, and security controls. For example, an Information Security Policy may state that all critical database must have defense in depth.)
What are Guidelines and Procedures?
Guidelines and procedures provide detailed instructions (dos and don’ts) to support and implement policies.
(While policies state what must be done, guidelines and procedures explain how to do it. Procedures provide step-by-step instructions to perform tasks correctly and consistently, whereas guidelines offer recommended practices to help employees make appropriate decisions.)
Example: An Information Security Policy may state that all critical databases must be protected using defense in depth. To support this policy:
· Procedures may define steps to configure access controls, enable encryption, and apply security patches.
· Guidelines may recommend monitoring database activity logs and implementing intrusion detection alerts.
What is a Standard?
A standard is a mandatory requirement that must be followed to comply with a framework or certification (e.g., ISO 27001).
(This distinction helps organizations understand governance direction, implementation methods, and compliance requirements.)
Who should approve the Information Security Policy?
The Board of Directors.
(Board approval ensures the policy has authority, aligns with governance expectations, and reflects organizational priorities.)
What is the first reference point for an IS auditor during an audit?
Approved policies.
(Approved policies are the primary reference for an IS auditor because they define management’s expectations, control requirements, and acceptable practices. Auditors use these policies as a benchmark to evaluate whether processes, controls, and employee actions comply with organizational requirements.)
What is the most important factor while developing an information security policy?
Consideration of business requirements.
(Security policies must support business operations rather than hinder productivity.)
What should drive the development of an information security policy?
Business objectives - not just IT department goals.
(Policies must support organizational goals and risk management needs.)
What is the most important action after dismissal of an employee?
Immediately disable access rights.
(This prevents unauthorized access and protects organizational data after termination.)
What is the major concern if HR policy lacks a termination process?
Security risks due to continued access after termination.
(Former employees may retain access, creating risk of data theft or misuse.)
What is the risk if employees are unaware of the information security policy?
Unintentional disclosure of sensitive information.
(If employees do not understand security policies, they may unknowingly share confidential data, use weak security practices, or mishandle sensitive information. This lack of awareness can lead to data breaches, compliance violations, and reputational damage.)
How can policy compliance best be ensured?
Through existing IT mechanisms and enforcement controls.
(Policy compliance is most effective when enforced through automated IT controls rather than relying solely on user behavior. Technical mechanisms such as system configurations, access controls, password enforcement, monitoring tools, and data loss prevention systems ensure that policies are consistently followed and violations are prevented or detected.)
What is a major risk of unstructured data and system ownership policies?
Unauthorized access due to unclear ownership.
(When data and systems do not have clearly defined owners, accountability for access control, classification, protection, and monitoring becomes weak. This can result in excessive permissions, delayed removal of access, and sensitive information being exposed to unauthorized users.)
What ensures policies comply with legal requirements?
Periodic review by a subject matter expert (SME).
(Laws, regulations, and compliance requirements change over time. Regular reviews by legal, compliance, or regulatory subject matter experts help ensure that organizational policies remain aligned with current legal obligations and industry standards. This reduces the risk of non-compliance, penalties, and legal exposure.)
Which of the following is a first step for the auditor having observed that IT policies are not approved by management?
To include this as a non compliance in an audit report
What is a Top-Down approach to policy development?
A Top-Down approach develops policies from a senior management perspective, aligned with business objectives.
(This approach begins at the highest level of the organization, where senior management defines policies based on strategic goals, regulatory obligations, and enterprise-wide risks. It ensures that policies support business direction, risk appetite, governance expectations, and compliance requirements. Because leadership sets the tone, this approach promotes accountability, uniform standards, and alignment between IT and organizational objectives.)
What is a Bottom-Up approach to policy development?
A Bottom-Up approach develops policies from the process owner and operational level perspective, based on process-level requirements.
(This approach starts at the operational level, where process owners and technical teams identify risks, control gaps, and practical challenges in day-to-day activities. Policies are shaped by real operational needs, workflow realities, and risk assessment findings. This ensures that policies are practical, implementable, and effective in addressing operational vulnerabilities.)
Which risks are addressed in Top-Down approach?
Major risks affecting business objectives
(Top management focuses on enterprise risks such as regulatory noncompliance, reputational damage, financial loss, cybersecurity threats, and business continuity disruptions. Addressing these risks ensures that policy decisions protect organizational strategy and stakeholder interests.)
Which risks are addressed in Bottom-Up approach?
Process-level risks, identified through risk assessments.
(This includes risks such as weak access controls, procedural errors, system misconfigurations, data handling weaknesses, and operational inefficiencies. Identifying these risks ensures that day-to-day controls function effectively and support overall security objectives.)
What is one advantage of the Top-Down approach?
Ensures consistency across the organization.
(Because policies originate from senior leadership, they create uniform standards, consistent control expectations, and standardized practices across departments. This reduces confusion, ensures compliance, and strengthens governance.)
What is one advantage of the Bottom-Up approach?
Policies are based on risk assessment results and operational realities.
(This ensures policies reflect actual risks, operational challenges, and practical implementation considerations. As a result, controls are more realistic, accepted by staff, and effective in daily operations.)
Which approach is best for developing policies? Bottom-Up or Top-Down?
Both approaches should be used together. They are complementary and should be applied simultaneously.
(Using both approaches ensures policies align with business strategy while remaining practical and effective at the operational level. Top-down provides direction and governance, while bottom-up ensures real-world applicability and risk coverage.)
What is the role of The Board of Directors?
The Board of Directors has ultimate responsibility for IT governance and strategic direction.
(Ultimate responsibility lies with the Board because governance decisions affect enterprise risk, compliance, financial performance, and stakeholder trust. The Board ensures IT investments and strategies align with organizational objectives.)
What is the role of the IT Strategic Committee?
To advise the Board on IT strategy and new IT initiatives. They give direction while steering committee drives.
• Ensure alignment of IT with business objectives
• Identify IT risks and exposure
• Advise on IT contributions to business
• Direct management on IT strategic matters
(This committee ensures technology investments support business value, identifies strategic risks, and guides leadership on leveraging IT for competitive advantage. It evaluates emerging technologies, long-term IT direction, innovation opportunities, and major IT investments. Its advisory role helps ensure IT strategy supports business growth and competitive advantage.)
What is the role of the IT Steering Committee?
To implement, monitor, and control IT projects. The committee ensures projects are completed on time, within budget, and aligned with business requirements. They drive the car while Strategy Committee gives directions.
• Approve project plans and budgets
• Set priorities and milestones
• Assign resources
• Monitor project cost and schedules
• Ensure alignment with business requirements
• Ensure efficient use of IT resources
• Escalate major issues to senior management/Board
(The IT Steering Committee acts as a governance body overseeing IT project execution, prioritization, and resource allocation. It ensures projects deliver value and remain aligned with business needs.)
What is the role of the User Management / Project Sponsor?
User Management / Project Sponsors assume ownership of project and resulting systems. They provide functional requirements and they review and approve deliverables.
(Ownership of a system or project typically rests with user management or the project sponsor because they are responsible for defining business requirements, approving funding, ensuring the system meets business needs, and accepting associated risks. IT may develop and maintain the system, but ownership remains with the business side. Example: For a payroll system, the HR department head may act as the system owner, ensuring it meets operational and compliance requirements.)
What is the role of System Development management?
To provide technical support.
Who assumes overall responsibility for system development projects?
The IT Steering Committee.
(The committee oversees project progress, ensures alignment with strategic priorities, and monitors risks, budgets, and timelines to support successful system implementation.)
Who assumes ownership of a system or project?
User Management / Project Sponsor.
(Ownership of a system or project typically rests with user management or the project sponsor because they are responsible for defining business requirements, approving funding, ensuring the system meets business needs, and accepting associated risks. IT may develop and maintain the system, but ownership remains with the business side. Example: For a payroll system, the HR department head may act as the system owner, ensuring it meets operational and compliance requirements.)
Who is responsible for defining system requirements?
The Project Sponsor (User Management).
(Business users define requirements because they understand operational needs, workflows, and expected outcomes.)
Who is accountable for maintaining appropriate security measures over information assets?
The Resource Owner (Data/Process/System Owner).
(The resource owner is responsible for classifying information, defining access rights, ensuring protection controls, and safeguarding the confidentiality, integrity, and availability of assets.)
Who are the members of the IT Strategy Committee?
Board members and specialized non-board members.
(This may include senior executives, technology experts, and external advisors who bring strategic, industry, and governance perspectives to IT decision-making.)
Who are the members of the IT Steering Committee?
Executives such as CEO and other key organizational functionaries.
(Members typically include senior business and IT leaders responsible for prioritizing projects, allocating resources, and ensuring successful execution.)
Who is responsible for monitoring project cost and schedule?
The IT Steering Committee.
(Monitoring costs and timelines ensures projects remain within approved budgets and schedules, preventing overruns and operational disruptions.)
What is the flow between the IT strategy committee, board of directors and the IT steering committee?
The IT Strategy Committee advises the board on IT strategy. Then, the Board of Directors makes the decision on the basis of the advice of the IT Strategy Committee and they instruct the IT Steering Committee for Implementation. Then the IT Steering Committee is responsible for the implementation and monitoring.
Who ensures efficient use of IT resources?
The IT Steering Committee.
(The committee allocates and monitors resources to ensure optimal utilization and maximum return on IT investments.)
If the Board does not approve all recommendations from the IT Strategy Committee, is it a control weakness?
No. The Strategy Committee only advises; the Board makes the final decision.
(The committee provides guidance, but the Board retains ultimate decision-making authority based on strategic priorities and risk considerations.)
Who monitors and approves major IT projects?
The IT Steering Committee.
(The committee reviews project progress, approves key milestones, and ensures initiatives remain aligned with organizational priorities.)
A request for proposal (RFP) to purchase a new system will most likely be approved by?
The project steering committee
The ultimate responsibility for requirement specifications rests with?
The project sponsor/user management
The most suitable person to be appointed as chair of the steering committee is:
A. A member of the board
B. An executive level officer
C. The CTO
D. The CIO
B. An executive level officer
What is Enterprise Architecture (EA)?
Enterprise Architecture defines the structure and operations of an organization and how all the operations are connected and work together.
(It provides a blueprint of business processes, information systems, technology infrastructure, and their relationships. EA helps organizations understand how components interact and ensures technology supports business operations effectively. Example: A bank’s EA may show how customer onboarding processes connect with mobile banking applications, core banking systems, identity verification services, and data centers. This blueprint ensures all systems work together smoothly and support secure, efficient customer services.)
What is the main focus of Enterprise Architecture?
To ensure that technology initiatives are compatible with the overall IT framework. To help the organization adopt the most suitable and successful technologies.
(EA ensures that new systems, applications, and technologies integrate smoothly with existing infrastructure, preventing fragmentation, redundancy, and incompatibility issues. It guides technology selection and implementation to ensure solutions align with business needs, support scalability, and provide long-term value.)
What must EA include to be considered complete?
Both current state and future state representation. If the future state is not included, EA is incomplete.
(The current state shows how systems operate today, while the future state defines the target architecture. Together, they enable strategic planning and a roadmap for transformation.)
What is the Zachman Framework?
One of the first Enterprise Architecture frameworks, created by John Zachman, providing a structured way to define and view an enterprise.
(The Zachman Framework organizes architecture artifacts into perspectives and dimensions, helping stakeholders understand the enterprise from multiple viewpoints such as data, function, network, and people.)
If an organization maintains two separate EAs (one current and one future under development), what should the auditor do?
Report it as an audit observation, since EA should provide a unified enterprise-wide view.
(Maintaining separate architectures can create confusion and misalignment. EA should present an integrated roadmap connecting the current environment to the future state.)
What is the main advantage of an Enterprise Architecture initiative?
It allows the company to invest in the most suitable technologies.
(EA ensures technology investments are aligned with business priorities, reduce duplication, and support long-term strategic growth.)
What is a major concern if IT is not involved in system selection procedures?
Application technologies may not be compatible with the organization’s architecture.
(Without IT involvement, selected solutions may not integrate properly, increasing costs, security risks, and operational inefficiencies.)
When a vendor develops proprietary application software, what is the most important contract clause?
Inclusion of source code escrow arrangement. To ensure availability of source code if the vendor becomes unavailable in the future. It protects the organization’s investment and ensures business continuity by allowing maintenance or migration if vendor support is lost.
(This clause ensures the organization can access the source code if the vendor ceases operations, fails to provide support, or breaches contractual obligations.)
What is the most valuable factor in environments with rapid technology transition?
Having sound processes in place.
(Strong processes ensure consistent control, risk management, and governance even when technologies change rapidly.)
Before making major infrastructure investments, what is the most critical factor to consider?
Risk analysis. Alignment is a part of risk analysis.
(Risk analysis helps evaluate financial, operational, security, and strategic risks to ensure informed investment decisions.)
What is the most important advantage of open system architecture?
It facilitates integration and compatibility with other systems, including proprietary components. Open systems architecture is a system design approach which aims to produce systems that are interoperable and connectable across vendors.
Which risk is not directly addressed by risk transfer?
Compliance risk. Risk of non adherence to legal rules and regulations. Transferring risk usually covers financial risk. The purpose of an insurance policy is to transfer the financial risk; however, a compliance risk continues to exist. (Risk transfer mechanisms like insurance may cover financial losses but cannot transfer legal or regulatory responsibility for compliance.)
What are the four main risk response options?
Remember using MAAT:
• M – Mitigation (Risk Reduction)
• A – Acceptance
• A – Avoidance
• T – Transfer (Risk Sharing)
What is Risk Mitigation and what is its objective?
Reducing risk to an acceptable level by lowering the probability or impact through controls. The objective is to ensure the risk is reduced within acceptable limits.
(Risk mitigation does not eliminate risk entirely but reduces its likelihood or impact by implementing safeguards such as technical controls, policies, or procedures.)
What is Risk Acceptance and when is it used?
Accepting the risk without taking any action. This approach is used when the risk is low or mitigation costs outweigh the potential loss.)
Example: An organization continues using a legacy internal tool that occasionally causes minor delays because replacing it would be expensive
What is Risk Avoidance and when is it used?
Eliminating the risk by stopping the activity or process causing it. It is used when potential losses outweigh expected benefits. It is usually the last choice when no other response is adequate.
Example:
A company decides not to launch an online payment feature because it lacks the security infrastructure to protect financial data, and the potential fraud and compliance risks outweigh the expected revenue
What is Risk Transfer and when is it used?
Shifting risk to another party through insurance or contractual agreement. It is used for low probability but high impact risks (e.g., natural disasters).
(This transfers financial consequences to a third party while the organization retains operational responsibility.)
Outsourcing a process to an expert organization is an example of?
Risk mitigation.
(Outsourcing reduces operational and security risks by relying on specialized expertise, better controls, and established processes.)
Why it is NOT risk transfer:
Risk transfer means shifting the financial impact or liability of a risk to another party (e.g., insurance). In outsourcing, the organization still retains accountability and ultimate responsibility for the process, compliance, and data protection. While the service provider performs the task, the organization must monitor performance, ensure controls, and manage vendor risk.
Example: Outsourcing payroll processing reduces errors and improves compliance (risk mitigation), but the organization remains responsible if employee data is mishandled.)
Best response for natural disasters?
Risk transfer (insurance).
(Insurance provides financial protection against catastrophic losses.)
What is the most risky approach among all risk responses? / Which risk response most likely increases liability?
Risk acceptance.
(This approach leaves the risk untreated and may result in losses if the risk event occurs. Accepting risk without proper evaluation may expose the organization to legal, financial, or regulatory consequences.))
When a risk practitioner recommends implementing controls, which of the four response is being used?
Risk mitigation.
(Implementing controls such as encryption, access controls, or monitoring systems reduces the likelihood or impact of risks.)
If cost of control exceeds cost of risk event, what is the best response?
Risk acceptance.
(Organizations accept the risk when mitigation is not cost-effective.)
What is the purpose of a business case in risk response?
To evaluate cost-benefit analysis of mitigation activities.
((A business case justifies investment in controls by comparing mitigation costs with potential risk impacts. Example: An organization considers implementing a 1000 USD security monitoring system to prevent potential cyberattacks that could cause losses of 2 million USD. The business case helps justify the investment by showing that the cost of mitigation is far lower than the potential impact.).)
What should be reviewed to ensure control deficiencies are remediated?
The risk mitigation plan.
(This plan tracks corrective actions, timelines, and responsibilities to ensure risks are properly addressed.)
What is risk analysis?
Risk analysis is the process of ranking various risks so that high-risk areas can be prioritized for treatment.
(Risk analysis helps organizations identify which risks require immediate attention by evaluating their likelihood and impact. This enables efficient allocation of resources and ensures critical risks are addressed first.)
What is Quantitative Risk Analysis?
Risk is measured using numerical values, such as:
• Dollar amount
• Percentage
• Statistical probability
(This method assigns measurable values to risks, enabling precise evaluation of potential losses and supporting financial decision-making. Example: Estimated loss from system downtime = ₹5,00,000)
What is Qualitative Risk Analysis?
Risk is assessed using descriptive categories such as High, Medium, Low. It is not expressed numerically.
(This method evaluates risks based on expert judgment and experience when numerical data is unavailable.)
What is Semi-Quantitative Risk Analysis?
A combination of qualitative and quantitative methods. Example: High = 5, Medium = 3, Low = 1. It is used when full quantitative analysis is not possible. It is also used to reduce subjectivity in qualitative analysis
(It provides a structured approach when data is limited but prioritization is still required.
(This method assigns numeric weights to qualitative ratings, reducing subjectivity while avoiding the complexity of full quantitative analysis.)
What is the biggest advantage of quantitative analysis?
Supports cost-benefit analysis because risk is expressed in monetary terms. A risk practitioner would always prefer quantitative approach.
(Monetary values allow management to compare mitigation costs with potential losses and make financially sound decisions.)
What is the biggest challenge in quantitative analysis?
Obtaining accurate frequency/probability data.
(Reliable historical data is often unavailable, making precise probability estimation difficult.)
When is qualitative analysis preferred?
When reliable numerical data is not available.
(It is useful in situations where historical data is limited or risks are difficult to quantify.)
Best way to get comprehensive qualitative results?
Develop scenarios with threats and impact.
(Scenario analysis helps visualize potential risk events and their consequences, improving risk understanding. Example: Scenario: “Employee clicks phishing email → credentials stolen → financial fraud.)
What is the primary factor in choosing between qualitative and quantitative methods?
Availability and reliability of data. The choice depends on whether accurate numerical data exists to support precise analysis.
Example: Use qualitative analysis when assessing new technology risks with no past data.
Which method is used to arrive at financial impact of a specific risk scenario?
Quantitative risk analysis.
(It calculates expected monetary loss for decision-making.)
Most difficult data to derive in quantitative analysis?
Accurate frequency / probability of occurrence. Without reliable historical data, estimating probability becomes challenging.
Example: Predicting frequency of cyber terrorism incidents.
What is Enterprise Risk Management (ERM)?
Enterprise Risk Management (ERM) covers the entire range of risks that affect an organization. These include:
IT risk
Operational risk
Investment risk
Market risk
Reputational risk
Legal risk
Compliance risk
In short, ERM includes all risks applicable to the enterprise. ERM is the practices, methods, and processes used by organizations to manage and monitor risks across the organization. It is a structured process for managing risks that may negatively impact business objectives.
Who is responsible for establishing the level of acceptable risk?
Senior business management.
They decide how much risk the organization is willing to accept.
(Risk tolerance must align with business goals and regulatory expectations. Example: Management may accept minor website downtime but not data breaches.)
Risk management results are used as input for what?
They are used for decision-making regarding security policies.
(Risk results guide security priorities and policy development. Example: High phishing risk leads to email filtering controls and awareness training.)
What is the first step in implementing a risk management program?
Identify assets, then determine threats and vulnerabilities affecting them.
(This sequence ensures risk assessment focuses on protecting critical resources. Example: Asset: payment gateway → Threat: fraud → Vulnerability: lack of monitoring.)
After identifying vulnerabilities in an e-business program, what should be done next?
Identify risks arising from vulnerabilities, likelihood of occurrence, and potential impact.
What is the best recommendation for a small IT organization without a dedicated risk management function?
Establish regular IT risk management meetings to define risks, assess risks, and develop contingency plans.
(Regular reviews help monitor risks even without formal risk teams. Example: Monthly meetings to review security incidents and mitigation actions.)
Which insurance covers losses caused by employee fraud?
Fidelity coverage.
(This insurance protects against financial losses due to employee dishonesty. Example: Coverage for funds stolen by an internal accountant.)
Why is it important for an IS auditor to confirm that all relevant risks are identified and categorized?
Without identifying risks, strategy cannot be effective.
(Identifying and categorizing risks ensures effective protection, prioritization, and informed management decisions. Complete risk identification ensures effective mitigation planning. Example: Ignoring vendor risk indicates incomplete risk coverage.)
Why should IT risks be presented from a business perspective to senior management?
Presenting IT risks in business terms helps senior management understand their real impact and prioritize decisions effectively. Executives focus on business outcomes such as financial loss, operational disruption, legal exposure, and reputational damage rather than technical details. Management responds better to business impact than technical terminology.
What is CMM?
Capability Maturity Model (CMM) is a framework used to determine the maturity level of an organization’s risk management processes. It measures how well processes are:
• Defined
• Managed
• Controlled
• Predictable
• Optimized
(CMM evaluates how structured, consistent, and effective organizational processes are. Example: A company with documented and monitored risk procedures has higher maturity than one using informal practices.)
How does maturity progress in CMM?
Each level improves upon the previous one.
EX:
1. Incomplete – Process does not achieve its intended purpose.
2. Performed – Process achieves its purpose.
3. Managed – Process is planned, monitored, and controlled.
4. Established – Process is defined, documented, standardized.
5. Predictable – Process operates within defined limits.
6. Optimized – Continuous improvement is in place.
Note: CISA exam does NOT usually test exact level names directly.
What are the main objectives of CMM?
To identify the gap between the current maturity level and the desired maturity level.
Continuous improvement.
Maturity models encourage ongoing enhancement rather than one-time fixes.
(This gap analysis helps organizations understand improvement needs.)
Why is identifying the gap important in CMM?
Because it helps the organization:
• Determine improvement areas
• Plan remediation actions
• Achieve continuous improvement
(Understanding gaps allows structured improvement planning.)