TechKnowSurge
CompTIA Security+ 5.2 ISC2 CISSP 1.9 NIST CSF ID.IM-01 NIST NICE S0861 CompTIA Security+ 5.5 ISC2 CISSP 6.5 NIST NICE S0940 NIST 800-53 CA-2
VideoSecurityFree

Gap Analysis

A gap analysis measures an organization's current security or compliance posture against a required standard, identifying exactly what must be addressed to close the difference. It is commonly used to prepare for costly formal audits, such as a SOC 2 Type 2, by resolving weaknesses before the official assessment begins.

Complete this video to capture a CTF flag worth 1 point.

About this video

A gap analysis is a structured evaluation that compares an organization's current state to a defined target or required standard, then identifies what must be done to bridge that difference. It is a broadly applicable technique, but in IT and cybersecurity it most commonly surfaces in the context of compliance frameworks and regulatory requirements, where the distance between current practices and required controls has direct operational and financial consequences. One of the most practical applications is using a gap analysis to prepare for a SOC 2 Type 2 audit. Because a full SOC 2 Type 2 engagement is a significant financial investment, entering that process with unresolved gaps in policies, procedures, or supporting evidence can result in a failed audit and wasted resources. Commissioning a gap analysis beforehand — even though it carries its own cost, as the vendor performs much of the same investigative work — allows an organization to identify weak areas, strengthen documentation, and implement corrective measures before the formal audit begins. This approach converts a reactive, high-stakes process into a deliberate, staged one. Organizations that use a gap analysis effectively enter formal compliance assessments already aware of their deficiencies and having addressed them, which dramatically improves the probability of a successful first-pass outcome. The upfront investment in the gap analysis is typically recovered many times over by avoiding a failed audit, repeat engagements, or the remediation costs that follow an unsuccessful assessment.

What you'll learn

What's covered

Gap Analysis

Aligned to

CompTIA Security+
5.2 Explain elements of the risk management process.
5.5 Explain types and purposes of audits and assessments.
ISC2 CISSP
1.9 Understand and apply risk management concepts
6.5 Conduct or facilitate security audits
NIST CSF
ID.IM-01 Improvements are identified from evaluations.
NIST NICE
S0861 Skill in performing gap analysis
S0940 Skill in performing risk-based gap analysis
NIST 800-53
CA-2 Control Assessments

Key terms

Gap Analysis
A process of comparing an organization's current security or compliance posture against required standards to identify deficiencies that must be remediated.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
SOC 2 Type 2
An attestation that evaluates not only whether controls are in place but also whether an organization is consistently following through with those controls over a defined period.

Topics

Gap Analysis Compliance Frameworks Soc 2 Audit Preparation Security Posture Cybersecurity Governance

Transcript

At times we may want to perform a gap analysis. All a gap analysis really is, is it says this is where we're at and this is where we want to be, and what is that gap? What is it that we need to do to get to where we need to be? By definition, a gap analysis is just measuring our current state against our desired state, where we need to be.

I'm going to use this ruler right here as an example. Let's say we need to be at this level right here — this is the level, the standard, that's set for us — and we are right here currently. So this is the gap right here. A gap analysis determines what this gap is and what we need to do to bring this up to the level that we need to be at.

Gap analysis and compliance

Gap analysis is just a generic term that we could apply and do ourselves, but more often than not we're doing it in relationship to maybe some sort of compliance. Maybe it's a SOC 2 Type 2. One reason why we do this is because a SOC 2 Type 2 is very expensive, and so if we were to just throw a bunch of money at doing a SOC 2 Type 2 and then fail, and they say, well, you're not performing at the level you need to, then that is problematic. So what we can do ahead of time is do a gap analysis to determine what we need to do to fix things and get up to speed.

The first time that I hired a vendor to do a SOC 2 Type 2 audit for the company I worked for, I initially had them do a gap analysis. I paid them to come in, and it's still fairly expensive, because essentially they're doing a good portion of the work that they would do for a full SOC audit, but they're doing a gap analysis. So they come in and they identify where in our policies we need to beef up, that we need to make stronger, the areas that we are weak. Same thing with our processes and procedures, and we need to have proof showing that we're doing certain things.

So this gap analysis really saved a lot of money in the long run. Even though this was very expensive in itself, it allowed us to do a SOC 2 Type 2 and be very successful with the first one that we rolled out, because we already knew what was wrong and we fixed those issues.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →