TechKnowSurge
CompTIA Security+ 5.5 ISC2 CISSP 6.1 NIST CSF ID.IM-01 NIST 800-53 CA-2 CompTIA Security+ 5.3 ISC2 CISSP 6.5 NIST 800-53 CA-7
VideoSecurityFree

Gap Analysis

Gap analysis and compliance monitoring are essential practices for identifying where an organization falls short of required security standards before undergoing formal third-party audits. SOC 2 attestations, performed by CPA firms, provide external validation of a company's compliance posture but come with significant cost.

Complete this video to capture a CTF flag worth 1 point.

About this video

Most organizations operate with some gap between their actual security practices and the compliance standards they are required to meet. Without a dedicated security function continuously auditing every process and control, deficiencies can go undetected. Compliance monitoring addresses this by taking defined standards, implementing them operationally, and continuously verifying adherence — often producing reports that can be shared with clients as evidence of a compliant security posture. When clients demand independent verification, a SOC 2 attestation becomes necessary. Performed by a licensed CPA firm with specialized expertise, a SOC 2 Type 1 assessment evaluates whether an organization has the appropriate standards and controls in place for its size and type. A SOC 2 Type 2 assessment goes further, examining whether those controls are being consistently and effectively followed over time. The resulting report identifies areas of compliance and any deficiencies, and organizations that pass receive a SOC 2 compliant designation they can present to clients and partners. Because even a basic SOC 2 audit can cost tens of thousands of dollars, failing one represents a significant waste of resources. A gap analysis conducted prior to the formal audit allows an organization to identify control weaknesses and take corrective action before the high-stakes assessment begins. While internal teams perform informal gap assessments as part of routine operations, bringing in an external third party — ideally the same firm that will conduct the eventual SOC 2 attestation — provides a more objective and audit-ready evaluation at a fraction of the cost of the full engagement.

What you'll learn

What's covered

Compliance Monitoring & Gap Analysis

Aligned to

CompTIA Security+
5.5 Explain types and purposes of audits and assessments.
5.3 Explain the processes associated with third-party risk assessment and management.
ISC2 CISSP
6.1 Design and validate assessment, test, and audit strategies
6.5 Conduct or facilitate security audits
NIST CSF
ID.IM-01 Improvements are identified from evaluations.
NIST 800-53
CA-2 Control Assessments
CA-7 Continuous Monitoring

Key terms

Gap Analysis
A process of comparing an organization's current security or compliance posture against required standards to identify deficiencies that must be remediated.
Compliance Monitoring
The ongoing process of measuring and verifying that an organization's practices align with required standards and regulations.
System and Organization Controls 2
SOC 2
An auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates the security, availability, processing integrity, confidentiality, and privacy controls of service organizations. SOC 2 reports are widely used by cloud service providers to demonstrate the effectiveness of their security controls to customers.
Attestation
The process of providing evidence or formal certification that a set of standards is being followed, either through self-reported documentation or third-party verification.
SOC 2 Type 1
An attestation that evaluates whether an organization has the appropriate controls designed and in place at a specific point in time.
SOC 2 Type 2
An attestation that evaluates not only whether controls are in place but also whether an organization is consistently following through with those controls over a defined period.
Third-Party Auditor
An independent external organization, such as a CPA firm, engaged to objectively assess and verify an organization's compliance with established standards.

Topics

Gap Analysis Compliance Monitoring Soc 2 Third Party Auditing Cybersecurity Compliance Risk Management

Transcript

There are certain things that we need to comply with, a set of standards that we need to meet, and what the company is doing hopefully goes beyond those standards. But that's not usually the case. There are usually things within a company that go unnoticed. Unless you have a huge security department that makes sure that you're covering everything that you need to do, you probably have a little bit of a gap. But how big is that gap? How much standards do we have, and how much lower are we operating at? What we may need to do is a gap analysis to determine what that gap is and how we can fill in that gap.

Compliance monitoring and attestation

When it comes to compliance monitoring, what we're doing is we're taking the compliance standards, whatever we've determined we need to follow, and we're taking action on that, and then we're monitoring to make sure we're doing all of that.

Let's generate a little scenario here. Let's say we work for a company and we are doing compliance monitoring to make sure that we're in compliance, and we have generated reports off that and we're turning those over to customers. But we have a few clients that require us to take the next step and get a third-party auditor to come in and make sure that we are doing exactly what we're saying we're going to do. So they're going to perform an attestation. Specifically, they want a SOC 2 attestation.

That's going to be done by a CPA firm, so that's a specific type of firm. It's a financial firm that's going to come in, and usually they do financial documents, but they have a team of people that do just SOC 2 attestations. SOC 2 Type 1 is going to just look at the standards and make sure that you have the right standards for the size and type of company that you are. But the other thing that they're going to do, if you're doing a Type 2, is they're going to take a look and see if you're following through with those: are you taking the proper actions? So this is going to be an attestation that's going to happen by this financial firm.

At the end of the attestation, what the CPA firm is going to do is generate a report, and the report is going to show us whether we're complying with everything, whether it is to the level that we need to have as far as the standards are concerned, or if we're deficient in any certain area. Then we can take this report and they'll label us as being SOC 2 compliant, and then we can turn this report over to our customers that are asking for it.

Why a gap analysis comes first

The reason why I bring this up is because this is a very expensive process. Even the more basic ones are tens of thousands of dollars to come and do a more simple SOC attestation. Since it can be so expensive, what we probably want to do ahead of time is a gap analysis. This is going to be where we're going to analyze to see where we're deficient. In the end, what we might find is that we don't have the proper standards, or we're not implementing the proper standards. Now what we can do is take corrective action to fix this before we go through a really expensive SOC audit only to fail that SOC audit. Now we can be successful in that audit and not waste our money.

Now, in my experience, you don't really want to do the gap analysis internally. I mean, you're really already doing that internally as part of your processes. So really what you want to do is hire a third party to come in and do the gap analysis. And what I've actually done is hired whoever is going to do the SOC attestation; I hire them to do the gap analysis as well. So in this scenario right here, it would still cost quite a bit of money to do the gap analysis, but not nearly as much as it would cost to do the full SOC.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →