1/3
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Gap analysis
Where you are compared with where you want to be.
Choosing the framework
• Work towards a known baseline
- This may be an internal set of goals
- Some organizations should use formal standards
• Determine the end goal
- NIST Special Publication 800-171 Revision 2,
- Protecting Controlled Unclassified Information in
- Nonfederal Systems and Organizations
• ISO/IEC 27001
- Information security management systems
Evaluate people and processes
Get a baseline of employees' formal experience, current training, and knowledge of security policies.
The analysis and report
The final comparison
-Detailed baseline objectives
-A clear view of the current state
-Need a path to get from the current security to the goal
-This will almost certainly include time, money, and lots of change control
-Time to create the gap analysis report
-A formal description of the current state
-Recommendations for meeting the baseline
