TechKnowSurge
InteractiveSecurityFree

Gap Analysis Activity

Assign five AcmeCorp security gaps to the correct NIST CSF function to build a remediation roadmap.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Gap analysis is how security professionals translate assessment findings into an actionable remediation roadmap. This activity presents five real-world-style findings from a fictional organization and asks you to categorize each one under the correct NIST CSF function — Identify, Protect, Detect, Respond, or Recover. Getting the categorization right is the first step toward prioritizing remediation work and communicating risk to leadership.

What you'll learn

Key terms

Gap Analysis
A process of comparing an organization's current security or compliance posture against required standards to identify deficiencies that must be remediated.
NIST Cybersecurity Framework
NIST CSF
A voluntary framework developed by NIST that provides organizations with a policy framework of computer security guidance for identifying, protecting, detecting, responding to, and recovering from cyberattacks. Originally created for critical infrastructure, CSF 2.0 expanded to address organizations of all sizes and sectors and added a Govern function.
Security Assessment and Authorization
SA&A
Security Assessment and Authorization is a formal process for evaluating security controls and granting official approval for a system to operate, forming the basis of NIST Risk Management Framework authorization activities.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.

Topics

Interactive Build

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →