A gap analysis measures an organization's current security or compliance posture against a required standard, identifying exactly what must be addressed to close the difference. It is commonly used to prepare for costly formal audits, such as a SOC 2 Type 2, by resolving weaknesses before the official assessment begins.
Gap Analysis
At times we may want to perform a gap analysis. All a gap analysis really is, is it says this is where we're at and this is where we want to be, and what is that gap? What is it that we need to do to get to where we need to be? By definition, a gap analysis is just measuring our current state against our desired state, where we need to be.
I'm going to use this ruler right here as an example. Let's say we need to be at this level right here — this is the level, the standard, that's set for us — and we are right here currently. So this is the gap right here. A gap analysis determines what this gap is and what we need to do to bring this up to the level that we need to be at.
Gap analysis is just a generic term that we could apply and do ourselves, but more often than not we're doing it in relationship to maybe some sort of compliance. Maybe it's a SOC 2 Type 2. One reason why we do this is because a SOC 2 Type 2 is very expensive, and so if we were to just throw a bunch of money at doing a SOC 2 Type 2 and then fail, and they say, well, you're not performing at the level you need to, then that is problematic. So what we can do ahead of time is do a gap analysis to determine what we need to do to fix things and get up to speed.
The first time that I hired a vendor to do a SOC 2 Type 2 audit for the company I worked for, I initially had them do a gap analysis. I paid them to come in, and it's still fairly expensive, because essentially they're doing a good portion of the work that they would do for a full SOC audit, but they're doing a gap analysis. So they come in and they identify where in our policies we need to beef up, that we need to make stronger, the areas that we are weak. Same thing with our processes and procedures, and we need to have proof showing that we're doing certain things.
So this gap analysis really saved a lot of money in the long run. Even though this was very expensive in itself, it allowed us to do a SOC 2 Type 2 and be very successful with the first one that we rolled out, because we already knew what was wrong and we fixed those issues.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →